CVEs (326)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Artifex CanonicalDebian+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 21, 2024 Nov 23, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same. |
2Linux Redhat9Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+6 moreNov 21, 2024 Oct 22, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt and bind on an AF_PACKET socket. This issue exists because of the 15fe076edea787807a7cdc168df832544b...Show more |
3Canonical HaproxyRedhat5Enterprise Linux HaproxyOpenshift+2 moreNov 21, 2024 Sep 21, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service. |
2Elastic Redhat2Kibana Openshift Container PlatformNov 21, 2024 Sep 19, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of o...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Sep 11, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim. |
2Redhat Starcounter Jack2Json Patch Openshift Container PlatformNov 21, 2024 Sep 6, 2018 N/A· v4 7.7 HIGH· v3 4.0 MEDIUM· v2 An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Op...Show more |
4Artifex CanonicalDebian+1 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 Sep 5, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified...Show more |
3Ibm RedhatSalesforce3Api Connect Openshift Container PlatformTough CookieNov 21, 2024 Sep 5, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP heade...Show more |
2Nodejs Redhat2Node.js Openshift Container PlatformNov 21, 2024 Aug 21, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`), `Buffer#write()` can be abused to wri...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Aug 13, 2018 N/A· v4 5.0 MEDIUM· v3 4.0 MEDIUM· v2 The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook tokens. |
1Redhat 2Openshift Openshift Container PlatformNov 21, 2024 Aug 1, 2018 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Jul 27, 2018 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the t...Show more |
4Canonical DebianFreedesktop+1 more8Ansible Tower Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jul 25, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of...Show more |
3Canonical DebianRedhat9Ansible Engine Debian LinuxGluster Storage+6 moreNov 21, 2024 Jul 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2...Show more |
1Redhat 2Openshift Openshift Container PlatformNov 21, 2024 Jul 16, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that shoul...Show more |
5Canonical DebianGnome+2 more9Ansible Tower Debian LinuxEnterprise Linux Desktop+6 moreNov 21, 2024 Jul 5, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname. |
1Redhat 1Openshift Container Platform Nov 21, 2024 Jul 2, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the assemble script to run as the root user...Show more |
2Gnu Redhat5Binutils Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Jul 1, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file,...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Jun 15, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabled. Quotations around the values of ETCD_CLIENT_CERT_AUTH and ETCD_PEER...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Jun 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to be brought down. A malicious user can use this vulnerability to cause a...Show more |