Search

Found 673 results in 97ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2015-5233 medium 4.2 4.2 theforemanredhat 10y ago Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary h…
CVE-2016-0792 high 8.8 9.8 EXP jenkinsredhat 10y ago Jenkins allows Deserialization of Untrusted Data via an XML File
CVE-2016-0790 medium 5.3 5.3 jenkinsredhat 10y ago Exposure of Sensitive Information in Jenkins Core
CVE-2016-0789 medium 6.1 6.1 jenkinsredhat 10y ago Jenkins has CRLF Injection Vulnerability in the CLI
CVE-2016-1714 high 8.1 8.1 FIX slesdebian debian redhatqemu 10y ago The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_…
CVE-2016-0793 high 7.5 8.5 EXP redhat 10y ago WildFly has incomplete blacklist vulnerability
CVE-2016-0636 high 8.1 8.1 FIX rheldebian debian oracleredhat 10y ago Unspecified vulnerability in Oracle Java SE 7u97, 8u73, and 8u74 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to the Hotspot sub-componen…
CVE-2016-0742 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu f5appleredhat 10y ago The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
CVE-2015-7539 high 7.5 7.5 jenkinsredhat 11y ago Jenkins does not Verify Checksums for Plugin Files
CVE-2015-7538 high 8.8 8.8 jenkinsredhat 11y ago Jenkins Vulnerable to Cross-Site Request Forgery (CSRF) Attack
CVE-2015-7537 high 8.8 8.8 redhatjenkins 11y ago Jenkins Vulnerable to Cross-Site Request Forgery (CSRF) Attack
CVE-2015-5295 medium 5.4 5.4 FIX slesdebian debianfedora fedora openstackredhat 11y ago The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory cons…
CVE-2015-1779 high 8.6 8.6 FIX slesubuntu ubuntu rhel qemuredhat 11y ago The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.
CVE-2015-5302 medium 5.0 redhat 11y ago libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive information via unspecified vectors related to the (1)…
CVE-2015-5287 medium 7.9 EXP rhel redhat 11y ago The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable na…
CVE-2015-5245 medium 4.3 FIX debian debian redhat 11y ago CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks…
CVE-2015-5326 medium 4.3 jenkinsredhat 11y ago Jenkins allows Cross-Site Scripting (XSS)
CVE-2015-5325 high 7.5 redhatjenkins 11y ago Jenkins allows Bypass of Access Restrictions
CVE-2015-5324 medium 5.0 jenkinsredhat 11y ago Jenkins allows Unauthorized Viewing of Queue API Information
CVE-2015-5323 medium 6.5 redhatjenkins 11y ago Jenkins allows Administrators to Access API Tokens
CVE-2015-5322 medium 5.0 redhatjenkins 11y ago Jenkins has Local File Inclusion Vulnerability
CVE-2015-5321 medium 5.0 redhatjenkins 11y ago Jenkins has Information Disclosure via Sidepanel Widget
CVE-2015-5320 medium 5.0 redhatjenkins 11y ago Jenkins allows Exposure of Sensitive Information to an Unauthorized Actor
CVE-2015-5319 medium 5.0 redhatjenkins 11y ago Jenkins has XML External Entity (XXE) Vulnerability in Job Configuration via CLI
CVE-2015-5318 medium 6.8 jenkinsredhat 11y ago Jenkins Vulnerable to Cross-Site Request Forgery (CSRF) Attack
CVE-2015-5242 medium 6.0 redhat 11y ago OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a cra…
CVE-2015-8126 high 7.5 FIX slesdebian debianubuntu ubuntu libpngredhatoracle 11y ago Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x …
CVE-2015-5225 high 7.2 FIX slesfedora fedoradebian debian redhatqemu 11y ago Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) …
CVE-2015-5305 medium 6.4 FIX debian debian redhat 11y ago Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a crafted object type name, which is not properly handle…
CVE-2015-5220 medium 5.0 redhat 11y ago The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption)…
CVE-2015-5188 medium 6.8 redhat 11y ago Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) before 2.0.0.C…
CVE-2015-5178 medium 4.3 redhat 11y ago The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for …
CVE-2015-1814 high 7.5 jenkinsredhat 11y ago Jenkins allows for Privilege Escalation by Remote Authenticated Users
CVE-2015-1813 medium 4.3 jenkinsredhat 11y ago Jenkins allows Cross-Site Scripting (XSS)
CVE-2015-1812 medium 4.3 jenkinsredhat 11y ago Jenkins Cross-site Scripting vulnerability
CVE-2015-1810 medium 4.6 jenkinsredhat 11y ago Jenkins does not Restrict Reserved Names Allowing for Privilege Escalation
CVE-2015-1806 medium 6.5 jenkinsredhat 11y ago Jenkins allows for Privilege Escalation by Remote Authenticated Users
CVE-2015-5235 medium 4.3 FIX debian debiansuse susefedora fedora redhat 11y ago IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving …
CVE-2015-5234 medium 6.8 FIX debian debiansuse susefedora fedora redhat 11y ago IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass use…
CVE-2015-5274 medium 6.5 redhat 11y ago rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to the Broker.
CVE-2015-5250 medium 4.0 redhat 11y ago Denial of Service in OpenShift Origin in github.com/openshift/origin
CVE-2015-3214 medium 7.9 EXPFIX debian debian linux-kernel rhel qemuredhat 11y ago The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitra…
CVE-2015-5222 high 8.5 redhat 11y ago Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute arbitrary shell commands with root permissions on a…
CVE-2015-0298 medium 4.3 redhat 11y ago Cross-site scripting (XSS) vulnerability in the manager web interface in mod_cluster before 1.3.2.Alpha1 allows remote attackers to inject arbitrary web script or HTML via a crafted MCMP message.
CVE-2015-3908 medium 4.3 FIX debian debian redhat 11y ago Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle …
CVE-2015-5176 medium 5.8 redhat 11y ago The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to r…
CVE-2015-3267 medium 4.3 redhat 11y ago Cross-site scripting (XSS) vulnerability in the 404 error page in Red Hat JBoss Operations Network before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVE-2015-3246 high 8.2 EXPFIX debian debian redhat 11y ago libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (incon…
CVE-2015-1818 high 7.5 redhat 11y ago XML external entity (XXE) vulnerability in the dashbuilder import facility (DocumentBuilders in org.jboss.dashboard.export.ImportManagerImpl) in Red Hat JBoss BPM Suite before 6.1.2 allows remote att…
CVE-2015-3244 medium 4.9 redhat 11y ago The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6.2.0, when used in portlets with the default resource serving for GenericPortlet, does not properly restrict access to restricted reso…
CVE-2014-8175 medium 6.0 redhat 11y ago Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an account defined in the users.properties file.
CVE-2013-7398 medium 4.3 FIX debian debian async-http-client_projectredhat 11y ago Insufficient Verification of Data Authenticity in Async Http Client
CVE-2013-7397 medium 4.3 FIX debian debian redhatasync-http-client_project 11y ago Insufficient Verification of Data Authenticity in Async Http Client
CVE-2015-3209 high 7.5 FIX ubuntu ubuntudebian debian rhel qemujuniperredhat 11y ago Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_…
CVE-2014-8162 high 7.5 redhatsuse 11y ago XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbitrary files and possibly have other unspecified imp…
CVE-2015-3456 high 8.7 EXPFIX rheldebian debian qemuredhat 11y ago The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arb…
CVE-2015-0237 medium 6.8 redhat 11y ago Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between domains, which allows remote authenticated users t…
CVE-2014-8125 high 7.5 redhat 11y ago Improper Input Validation in Drools and jBPM
CVE-2015-1843 medium 4.3 FIX debian debian redhat 11y ago The Red Hat docker package before 1.5.0-28, when using the --add-registry option, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to condu…
CVE-2015-0283 high 7.8 FIX debian debian redhat 11y ago The slapi-nis plug-in before 0.54.2 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) v…
CVE-2015-0279 medium 6.8 redhat 11y ago JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.
CVE-2015-0250 medium 6.4 FIX slesdebian debianubuntu ubuntu apacheredhat 11y ago Improper Input Validation in Apache Batik
CVE-2015-0271 medium 4.0 FIX debian debian redhat 11y ago The log-viewing function in the Red Hat redhat-access-plugin before 6.0.3 for OpenStack Dashboard (horizon) allows remote attackers to read arbitrary files via a crafted path.
CVE-2014-3691 high 7.5 redhattheforeman 11y ago Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remote attackers to bypass intended authentication and …
CVE-2014-8115 medium 6.5 redhat 11y ago The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended access restrictions, and possibly have other unspeci…
CVE-2014-8114 medium 6.8 redhat 11y ago UberFire Framework Improperly Restricts Paths
CVE-2014-3682 high 7.5 redhat 11y ago XML external entity (XXE) vulnerability in the JBPMBpmn2ResourceImpl function in designer/bpmn2/resource/JBPMBpmn2ResourceImpl.java in jbpm-designer 6.0.x and 6.2.x allows remote attackers to read ar…
CVE-2014-8122 medium 4.3 redhat 12y ago Information disclosure in JBoss Weld
CVE-2014-7853 medium 4.0 redhat 12y ago The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to t…
CVE-2014-7849 medium 4.0 redhat 12y ago The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authentic…
CVE-2014-0151 medium 6.8 redhat 12y ago Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a RE…
CVE-2014-9623 medium 4.0 FIX debian debian redhatopenstack 12y ago OpenStack Glance Bypass the storage quota and Denial of service
CVE-2014-7814 medium 6.5 redhat 12y ago SQL injection vulnerability in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 allows remote authenticated users to execute arbitrary SQL commands via a crafted REST API request to an SQL filter.
CVE-2014-0171 medium 5.0 redhatodata4j_project 12y ago XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization before 6.0.0 patch 4, allows remote attackers to read arbitrary files via a…
CVE-2014-9493 medium 5.5 FIX debian debian redhatopenstack 12y ago The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: UR…
CVE-2014-8131 medium 4.0 FIX debian debian redhat 12y ago The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly handle locks when a domain is skipped due to ACL restrictions, which allows a remote authenticated us…
CVE-2014-7840 high 7.5 FIX rheldebian debian qemuredhat 12y ago The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via a crafted (1) offset or (2) length value in savev…
CVE-2013-4399 medium 4.3 FIX debian debian redhat 12y ago The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cau…
CVE-2014-7852 medium 4.3 redhat 12y ago Cross-site scripting (XSS) vulnerability in JBoss RichFaces, as used in JBoss Portal 6.1.1, allows remote attackers to inject arbitrary web script or HTML via crafted URL, which is not properly handl…
CVE-2014-9140 medium 5.0 FIX debian debian redhat 12y ago Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia a crafted PPP packet.
CVE-2014-3703 medium 5.0 redhat 12y ago OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration option when generating the nova.conf configuration…
CVE-2014-7816 medium 6.0 EXPFIX debian debian redhat 12y ago Improper Limitation of a Pathname to a Restricted Directory in JBoss Undertow
CVE-2014-7839 medium 6.4 FIX debian debian redhat 12y ago XML External Entity Reference in RESTEasy
CVE-2014-7821 medium 4.0 FIX debian debianfedora fedora openstackredhat 12y ago OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
CVE-2014-8769 medium 6.4 FIX debian debian redhat 12y ago tcpdump 3.8 through 4.6.2 might allow remote attackers to obtain sensitive information from memory or cause a denial of service (packet loss or segmentation fault) via a crafted Ad hoc On-Demand Dist…
CVE-2014-8768 medium 6.0 EXPFIX suse suseubuntu ubuntudebian debian redhat 12y ago Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a…
CVE-2014-8767 medium 5.0 FIX suse susedebian debian redhat 12y ago Integer underflow in the olsr_print function in tcpdump 3.9.6 through 4.6.2, when in verbose mode, allows remote attackers to cause a denial of service (crash) via a crafted length value in an OLSR f…
CVE-2014-0233 medium 6.5 redhat 12y ago Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to execute arbitrary commands via shell metacharacters in a directory name that is referenced by a cartr…
CVE-2014-7815 medium 5.0 FIX debian debiansuse suseubuntu ubuntu qemuredhat 12y ago The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.
CVE-2014-7823 medium 5.0 FIX debian debian redhat 12y ago The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML…
CVE-2014-3674 high 7.5 redhat 12y ago Red Hat OpenShift Enterprise before 2.2 does not properly restrict access to gears, which allows remote attackers to access the network resources of arbitrary gears via unspecified vectors.
CVE-2013-0336 medium 5.0 FIX debian debian redhat 12y ago The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows remote attackers to cause a denial of service (cr…
CVE-2014-3654 medium 4.3 suse suse redhatsuse 12y ago Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.5 and 5.6 allow remote attackers to inject arbitrary web script or HTML …
CVE-2014-8333 medium 4.0 FIX debian debian rhel redhatopenstack 12y ago The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.
CVE-2014-0136 medium 5.0 redhat 12y ago The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitrary text into log files via unspecified vectors.
CVE-2014-5075 medium 6.8 redhatigniterealtime 12y ago The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN)…
CVE-2014-7968 medium 5.0 redhat 12y ago VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open.
CVE-2014-3677 high 7.5 redhat 12y ago Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.
CVE-2014-3676 high 7.5 redhat 12y ago Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."
CVE-2014-3675 medium 5.0 redhat 12y ago Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.