VYPR

Vendor CVEs

Red Hat

All CVEs

6,364 total · sorted by risk
  • CVE-2015-5694MedNov 22, 2019
    risk 0.42cvss 6.5epss 0.02

    Designate does not enforce the DNS protocol limit concerning record set sizes

  • CVE-2015-1780MedNov 22, 2019
    risk 0.42cvss 6.5epss 0.01

    oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center

  • CVE-2012-6135HigNov 19, 2019
    risk 0.42cvss 7.5epss 0.02

    RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.

  • CVE-2018-12207MedNov 14, 2019
    risk 0.42cvss 6.5epss 0.01

    Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.

  • CVE-2012-1156HigNov 14, 2019
    risk 0.42cvss 7.5epss 0.02

    Moodle before 2.2.2 has users' private files included in course backups

  • CVE-2019-14860MedNov 8, 2019
    risk 0.42cvss 6.5epss 0.01

    It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized information.

  • CVE-2019-14824MedNov 8, 2019
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

  • CVE-2008-5083MedNov 8, 2019
    risk 0.42cvss 6.5epss 0.01

    In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.

  • CVE-2013-5123MedNov 5, 2019
    risk 0.42cvss 5.9epss 0.08

    The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

  • CVE-2013-6461MedNov 5, 2019
    risk 0.42cvss 6.5epss 0.02

    Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits

  • CVE-2013-6460MedNov 5, 2019
    risk 0.42cvss 6.5epss 0.02

    Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents

  • CVE-2019-0210HigOct 29, 2019
    risk 0.42cvss 7.5epss 0.07

    In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.

  • CVE-2019-17596HigOct 24, 2019
    risk 0.42cvss 7.5epss 0.05

    Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

  • CVE-2019-14832HigOct 15, 2019
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized information or to carry out further attacks.

  • CVE-2018-14882HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.

  • CVE-2018-14881HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.05

    The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTART).

  • CVE-2018-14880HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.05

    The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().

  • CVE-2018-14470HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2().

  • CVE-2018-14469HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.05

    The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().

  • CVE-2018-14468HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().

  • CVE-2018-14467HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP).

  • CVE-2018-14466HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert().

  • CVE-2018-14465HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().

  • CVE-2018-14464HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().

  • CVE-2018-14463HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.05

    The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.

  • CVE-2018-14462HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().

  • CVE-2018-14461HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().

  • CVE-2019-16276HigSep 30, 2019
    risk 0.42cvss 7.5epss 0.05

    Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.

  • CVE-2019-16884HigSep 25, 2019
    risk 0.42cvss 7.5epss 0.04

    runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.

  • CVE-2019-10198MedJul 31, 2019
    risk 0.42cvss 6.5epss 0.02

    An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through…

  • CVE-2019-10184HigJul 25, 2019
    risk 0.42cvss 7.5epss 0.03

    undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

  • CVE-2019-2834MedJul 23, 2019
    risk 0.42cvss 6.5epss 0.02

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise…

  • CVE-2019-2812MedJul 23, 2019
    risk 0.42cvss 6.5epss 0.02

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise…

  • CVE-2019-2795MedJul 23, 2019
    risk 0.42cvss 6.5epss 0.03

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL…

  • CVE-2019-9959MedJul 22, 2019
    risk 0.42cvss 6.5epss 0.02

    The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by…

  • CVE-2019-10193HigJul 11, 2019
    risk 0.42cvss 7.2epss 0.24

    A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could cause Redis to perform controlled increments of…

  • CVE-2019-10177MedJun 27, 2019
    risk 0.42cvss 6.5epss 0.01

    A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is not properly sanitized. An attacker with least privilege to edit compute is able to execute a XSS attack against other users, which…

  • CVE-2019-3875MedJun 12, 2019
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The…

  • CVE-2019-3873MedJun 12, 2019
    risk 0.42cvss 6.4epss 0.01

    It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.

  • CVE-2019-2695MedApr 23, 2019
    risk 0.42cvss 6.5epss 0.02

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise…

  • CVE-2019-2694MedApr 23, 2019
    risk 0.42cvss 6.5epss 0.02

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise…

  • CVE-2019-2693MedApr 23, 2019
    risk 0.42cvss 6.5epss 0.02

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise…

  • CVE-2016-10746HigApr 18, 2019
    risk 0.42cvss 7.5epss 0.02

    libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.

  • CVE-2019-3460MedApr 11, 2019
    risk 0.42cvss 6.5epss 0.02

    A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.

  • CVE-2019-3459MedApr 11, 2019
    risk 0.42cvss 6.5epss 0.02

    A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.

  • CVE-2019-0757MedApr 9, 2019
    risk 0.42cvss 6.5epss 0.03

    A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.

  • CVE-2019-10876MedApr 5, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute…

  • CVE-2019-5419HigMar 27, 2019
    risk 0.42cvss 7.5epss 0.09

    There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.

  • CVE-2019-3874MedMar 25, 2019
    risk 0.42cvss 6.5epss 0.02

    The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches are believed to be vulnerable.

  • CVE-2019-9903MedMar 21, 2019
    risk 0.42cvss 6.5epss 0.02

    PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.

Page 50 of 128