Search

Found 469 results in 184ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-3641 medium 4.9 4.9 slesdebian debian rhel oracleredhatmariadb 9y ago Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.56 and earlier, 5.6.36 and earlier and 5.7.18 and earlier. Easily…
CVE-2017-3636 medium 5.3 5.3 slesdebian debian rhel oracleredhatmariadb 9y ago Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.56 and earlier and 5.6.36 and earlier. Easily exploitable vul…
CVE-2017-10243 medium 6.5 6.5 FIX slesdebian debian rhel netapporacleredhat 9y ago Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAX-WS). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded:…
CVE-2017-10109 medium 5.3 5.3 FIX slesdebian debian rhel oracleredhatnetapp 9y ago Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Em…
CVE-2017-10108 medium 5.3 5.3 FIX slesdebian debian rhel oraclephoenixcontactredhat 9y ago Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Em…
CVE-2017-10105 medium 4.3 4.3 FIX slesdebian debian rhel oracleredhatnetapp 9y ago Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows …
CVE-2017-10053 medium 5.3 5.3 FIX slesdebian debian rhel oracleredhatnetapp 9y ago Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u1…
CVE-2016-3113 medium 6.1 6.1 redhat 9y ago Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML.
CVE-2016-0764 medium 6.2 6.2 FIX slesdebian debian rhel redhat 9y ago Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux…
CVE-2015-3142 medium 4.7 4.7 redhat 9y ago The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensi…
CVE-2015-1870 medium 5.5 5.5 redhat 9y ago The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information fr…
CVE-2016-3077 medium 6.5 6.5 redhat 9y ago The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for all VMs.
CVE-2014-8180 medium 5.5 5.5 mongodbredhat 9y ago MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by logging in with an empty password and delete information which can cause a Denial of Service.
CVE-2017-8379 medium 6.5 6.5 FIX slesdebian debian qemuredhat 9y ago Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generati…
CVE-2016-3702 medium 5.3 5.3 redhat 9y ago Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information.
CVE-2016-6519 medium 5.4 5.4 FIX slesdebian debian redhatopenstack 9y ago Openstack Manila Persistent XSS in Metadata field
CVE-2016-6347 medium 6.1 6.1 FIX debian debian redhat 9y ago Improper Neutralization of Input During Web Page Generation in RESTEasy
CVE-2016-6338 medium 6.8 6.8 redhat 9y ago ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restric…
CVE-2016-7060 medium 4.6 4.6 redhat 9y ago The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the d…
CVE-2016-2104 medium 6.1 6.1 redhat 9y ago Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the label parameter to admin/BunchDetail.do; (2) the p…
CVE-2016-6348 medium 6.1 6.1 FIX debian debian redhat 9y ago JacksonJsonpInterceptor susceptible to cross-site script inclusion (XSSI) attack
CVE-2017-5973 medium 5.5 5.5 FIX slesdebian debian rhel qemuredhat 9y ago The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors r…
CVE-2016-9921 medium 6.5 6.5 FIX slesdebian debian rhel qemuredhat 10y ago Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. …
CVE-2016-9911 medium 6.5 6.5 FIX slesdebian debian rhel qemuredhat 10y ago Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process coul…
CVE-2016-9907 medium 6.5 6.5 FIX slesdebian debian rhel qemuredhat 10y ago Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest …
CVE-2016-4443 medium 5.5 5.5 redhat 10y ago Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by reading the engine-setup log file.
CVE-2016-7466 medium 6.0 6.0 FIX slessuse suse rhel qemuredhat 10y ago Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consump…
CVE-2016-7422 medium 6.0 6.0 FIX slessuse suse rhel qemuredhat 10y ago The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) …
CVE-2016-6888 medium 4.4 4.4 FIX slesdebian debian rhel qemuredhat 10y ago Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the max…
CVE-2016-6835 medium 6.0 6.0 FIX slesdebian debian rhel qemuredhat 10y ago The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (buffer over-read) by leveraging fail…
CVE-2016-8910 medium 6.0 6.0 FIX sles rheldebian debian qemuredhat 10y ago The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveragin…
CVE-2016-8909 medium 6.0 6.0 FIX sles rheldebian debian qemuredhat 10y ago The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry wit…
CVE-2016-8669 medium 6.0 6.0 FIX sles rheldebian debian qemuredhat 10y ago The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) …
CVE-2016-8576 medium 6.0 6.0 FIX sles rheldebian debian qemuredhat 10y ago The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging f…
CVE-2016-1000007 medium 6.1 6.1 FIX debian debian redhat 10y ago Pagure 2.2.1 XSS in raw file endpoint
CVE-2016-7046 medium 5.9 5.9 FIX debian debian redhat 10y ago Undertow Uncaught Exception vulnerability
CVE-2016-5398 medium 5.4 5.4 redhat 10y ago Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permis…
CVE-2016-4993 medium 6.1 6.1 FIX rheldebian debian redhat 10y ago Improper Neutralization of CRLF Sequences in Wildfly Undertow
CVE-2016-7033 medium 6.1 6.1 redhat 10y ago Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inject arbitrary web script or HTML via unspecified ve…
CVE-2016-6345 medium 6.5 6.5 FIX debian debian redhat 10y ago Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
CVE-2016-6344 medium 5.3 5.3 redhat 10y ago Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attackers to obtain potentially sensitive information via…
CVE-2016-7103 medium 6.1 6.1 FIX slesdebian debianfedora fedora jqueryuioraclenetapp 10y ago jQuery-UI vulnerable to Cross-site Scripting in dialog closeText
CVE-2016-5392 medium 6.5 6.5 redhat 10y ago The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowledge of other project names to obtain sensitive pr…
CVE-2016-3097 medium 6.1 6.1 sles redhat 10y ago Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via a group name, related to viewing snapshot data.
CVE-2016-3080 medium 6.1 6.1 redhat 10y ago Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via the (1) RHNMD User or (2) Filesystem parameters,…
CVE-2016-5403 medium 5.5 5.5 FIX slesdebian debian rhel qemuredhat 10y ago The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without w…
CVE-2016-5009 medium 6.5 6.5 FIX slesdebian debian rhel redhat 10y ago The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
CVE-2016-4428 medium 5.4 5.4 FIX slesdebian debian rhel openstackredhat 10y ago OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability
CVE-2016-3703 medium 5.3 5.3 redhat 10y ago Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/proxy API for a specific pod, which allows remote …
CVE-2016-2149 medium 6.5 6.5 redhat 10y ago Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously deleted namespace when creating a new namespace.
CVE-2016-2142 medium 5.5 5.5 redhat 10y ago Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local users to obtain Active Directory credentials by re…
CVE-2014-8177 medium 6.5 6.5 rhel redhat 10y ago The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass the max_meta_count constraint via multiple crafted…
CVE-2016-4020 medium 6.5 6.5 FIX sles rhelubuntu ubuntu qemuredhat 10y ago The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory …
CVE-2014-3672 medium 6.5 6.5 FIX slesdebian debian redhat 10y ago The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denial of service (host disk consumption) by writing to stdout or stderr.
CVE-2016-0264 medium 5.6 5.6 sles rhelsuse suse ibmredhatsuse 10y ago Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP…
CVE-2016-3727 medium 4.3 4.3 jenkinsredhat 10y ago Jenkins Exposes Sensitive Information via API URL
CVE-2016-3725 medium 4.3 4.3 jenkinsredhat 10y ago Missing permissions check in Jenkins Core
CVE-2016-3724 medium 6.5 6.5 redhatjenkins 10y ago Jenkins Exposes Sensitive Information from Job Configuration
CVE-2016-3723 medium 4.3 4.3 jenkinsredhat 10y ago Exposure of Sensitive Information in Jenkins Core
CVE-2016-3722 medium 4.3 4.3 jenkinsredhat 10y ago Incorrect Authorization in Jenkins Core
CVE-2016-3721 medium 4.3 4.3 redhatjenkins 10y ago Jenkins allows Remote Users to Inject Build Parameters
CVE-2016-0695 medium 5.9 5.9 FIX sles rheldebian debian oracleredhat 10y ago Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related to Security.
CVE-2015-5247 medium 6.5 6.5 FIX debian debianubuntu ubuntu redhat 10y ago The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unl…
CVE-2011-4600 medium 5.9 5.9 FIX debian debianubuntu ubuntu redhat 10y ago The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow rem…
CVE-2016-3079 medium 6.1 6.1 sles redhat 10y ago Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems…
CVE-2016-2103 medium 6.1 6.1 sles redhat 10y ago Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the list_1680466951_oldfilterval parameter to systems/…
CVE-2015-0284 medium 5.4 5.4 redhat 10y ago Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the …
CVE-2015-7528 medium 5.3 5.3 FIX debian debian kubernetesredhat 10y ago Kubernetes before 1.2.0-alpha.5 allows remote attackers to read arbitrary pod logs via a container name.
CVE-2015-7502 medium 5.1 5.1 redhat 10y ago Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend PostgreSQL database, which might allow local users …
CVE-2015-5233 medium 4.2 4.2 theforemanredhat 10y ago Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary h…
CVE-2016-0790 medium 5.3 5.3 jenkinsredhat 10y ago Exposure of Sensitive Information in Jenkins Core
CVE-2016-0789 medium 6.1 6.1 jenkinsredhat 10y ago Jenkins has CRLF Injection Vulnerability in the CLI
CVE-2015-5295 medium 5.4 5.4 FIX slesdebian debianfedora fedora openstackredhat 11y ago The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory cons…
CVE-2015-5302 medium 5.0 redhat 11y ago libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive information via unspecified vectors related to the (1)…
CVE-2015-5287 medium 7.9 EXP rhel redhat 11y ago The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable na…
CVE-2015-5245 medium 4.3 FIX debian debian redhat 11y ago CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks…
CVE-2015-5326 medium 4.3 jenkinsredhat 11y ago Jenkins allows Cross-Site Scripting (XSS)
CVE-2015-5324 medium 5.0 jenkinsredhat 11y ago Jenkins allows Unauthorized Viewing of Queue API Information
CVE-2015-5323 medium 6.5 redhatjenkins 11y ago Jenkins allows Administrators to Access API Tokens
CVE-2015-5322 medium 5.0 redhatjenkins 11y ago Jenkins has Local File Inclusion Vulnerability
CVE-2015-5321 medium 5.0 redhatjenkins 11y ago Jenkins has Information Disclosure via Sidepanel Widget
CVE-2015-5320 medium 5.0 redhatjenkins 11y ago Jenkins allows Exposure of Sensitive Information to an Unauthorized Actor
CVE-2015-5319 medium 5.0 redhatjenkins 11y ago Jenkins has XML External Entity (XXE) Vulnerability in Job Configuration via CLI
CVE-2015-5318 medium 6.8 jenkinsredhat 11y ago Jenkins Vulnerable to Cross-Site Request Forgery (CSRF) Attack
CVE-2015-5242 medium 6.0 redhat 11y ago OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a cra…
CVE-2015-5305 medium 6.4 FIX debian debian redhat 11y ago Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a crafted object type name, which is not properly handle…
CVE-2015-5220 medium 5.0 redhat 11y ago The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption)…
CVE-2015-5188 medium 6.8 redhat 11y ago Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) before 2.0.0.C…
CVE-2015-5178 medium 4.3 redhat 11y ago The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for …
CVE-2015-1813 medium 4.3 jenkinsredhat 11y ago Jenkins allows Cross-Site Scripting (XSS)
CVE-2015-1812 medium 4.3 jenkinsredhat 11y ago Jenkins Cross-site Scripting vulnerability
CVE-2015-1810 medium 4.6 jenkinsredhat 11y ago Jenkins does not Restrict Reserved Names Allowing for Privilege Escalation
CVE-2015-1806 medium 6.5 jenkinsredhat 11y ago Jenkins allows for Privilege Escalation by Remote Authenticated Users
CVE-2015-5235 medium 4.3 FIX debian debiansuse susefedora fedora redhat 11y ago IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving …
CVE-2015-5234 medium 6.8 FIX debian debiansuse susefedora fedora redhat 11y ago IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass use…
CVE-2015-5274 medium 6.5 redhat 11y ago rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to the Broker.
CVE-2015-5250 medium 4.0 redhat 11y ago Denial of Service in OpenShift Origin in github.com/openshift/origin
CVE-2015-3214 medium 7.9 EXPFIX debian debian linux-kernel rhel qemuredhat 11y ago The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitra…
CVE-2015-0298 medium 4.3 redhat 11y ago Cross-site scripting (XSS) vulnerability in the manager web interface in mod_cluster before 1.3.2.Alpha1 allows remote attackers to inject arbitrary web script or HTML via a crafted MCMP message.
CVE-2015-3908 medium 4.3 FIX debian debian redhat 11y ago Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle …