Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libqb CRITICAL 9.8
CVE-2023-39976

log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered.

Fix: 2.0.8+
Fix from $2,300 2023-08-08
Hawk HIGH 8.8
CVE-2021-3020

An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (built from tools/hawk_invoke.c), …

Fix: after 2.3.0-15
Fix from $1,950 2022-08-26
Cluster Glue MEDIUM 5.5
CVE-2010-2496

stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwor…

Fix: 1.0.6 / 1.1.3+
Fix from $1,600 2021-10-18
Hawk CRITICAL 9.8
CVE-2020-35458EPSS 5%

An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in …

Patch available
Fix from $2,300 2021-01-12
Fence Agents MEDIUM 5.9
CVE-2014-0104

In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-mid…

Fix: 4.0.17+
Fix from $1,600 2020-01-02
Pacemaker MEDIUM 5.5
CVE-2011-5271

Pacemaker before 1.1.6 configure script creates temporary files insecurely

Fix: 1.1.6+
Fix from $1,600 2019-11-12
Libqb HIGH 7.1
CVE-2019-12779

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /t…

Fix: 1.0.5+
Fix from $1,950 2019-06-07
Pcs MEDIUM 6.1
CVE-2017-2661

ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creat…

Fix: 0.9.157+
Fix from $1,600 2018-03-12