Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian OpenexrRedhat3Debian Linux Enterprise LinuxOpenexrNov 21, 2024 Jul 6, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The...Show more |
4Debian FedoraprojectLibslirp Project+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Jun 15, 2021 N/A· v4 3.8 LOW· v3 2.1 LOW· v2 An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size o...Show more |
4Debian FedoraprojectLibslirp Project+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Jun 15, 2021 N/A· v4 3.8 LOW· v3 2.1 LOW· v2 An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of...Show more |
4Debian FedoraprojectLibslirp Project+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Jun 15, 2021 N/A· v4 3.8 LOW· v3 2.1 LOW· v2 An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size o...Show more |
4Debian FedoraprojectLibslirp Project+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Jun 15, 2021 N/A· v4 3.8 LOW· v3 2.1 LOW· v2 An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size...Show more |
2Netapp Redhat2Oncommand Insight ResteasyNov 21, 2024 Jun 10, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL encoding when calling @javax.ws.rs.PathParam without any @Produces Med...Show more |
3Bluez DebianRedhat3Bluez Debian LinuxEnterprise LinuxNov 21, 2024 Jun 9, 2021 N/A· v4 5.7 MEDIUM· v3 2.7 LOW· v2 Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjacent access. |
A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a specific group can perform actions restricted only to system administr...Show more |
1Redhat 1Machine Config Operator Nov 21, 2024 Jun 7, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container consumes a large amount of memory. An attacker could use this flaw to deny access to schedule new pods...Show more |
2Nmstate Redhat2Kubernetes Nmstate Openshift VirtualizationNov 21, 2024 Jun 7, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileg...Show more |
1Redhat 2Openstack Selinux Openstack PlatformNov 21, 2024 Jun 7, 2021 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from privilege escalation. A non-root attacker in one or more Red Hat OpenStack...Show more |
A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability is to data confidentiality and integrity....Show more |
3Fedoraproject RedhatTpm2 Tools Project3Enterprise Linux FedoraTpm2 ToolsNov 21, 2024 Jun 4, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being...Show more |
2Libtpms Project Redhat2Enterprise Linux LibtpmsNov 21, 2024 Jun 3, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SIGBUS (bad memory access) and termination of swtpm. The highest threat f...Show more |
1Redhat 2Noobaa Operator Openshift Container PlatformNov 21, 2024 Jun 2, 2021 N/A· v4 7.1 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The inp...Show more |
4Debian FedoraprojectQemu+1 more5Debian Linux Enterprise LinuxFedora+2 moreNov 21, 2024 Jun 2, 2021 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null. |
An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacker with access to a running container which mounts /etc/kubernetes or has local access to the node, t...Show more |
A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads to hold up forever in the EJB server by writing a sequence of bytes corresponding to the expected me...Show more |
1Redhat 13scale Api Management Nov 21, 2024 Jun 2, 2021 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were not properly enforced. This flaw allows an authenticated user to bypass normal account restrictions...Show more |
An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already ex...Show more |