Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject Libtpms ProjectRedhat3Enterprise Linux FedoraLibtpmsNov 21, 2024 Apr 19, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPri...Show more |
4Debian GstreamerGstreamer Project+1 more4Debian Linux Enterprise LinuxGstreamer+1 moreMar 17, 2026 Apr 19, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files. |
4Debian GstreamerGstreamer Project+1 more4Debian Linux Enterprise LinuxGstreamer+1 moreMar 17, 2026 Apr 19, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files. |
4Debian FedoraprojectLinuxfoundation+1 more4Ceph Ceph StorageDebian Linux+1 moreNov 21, 2024 Apr 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_...Show more |
4Debian Exiv2Fedoraproject+1 more4Debian Linux Enterprise LinuxExiv2+1 moreNov 21, 2024 Apr 8, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetadata() in jp2image.cpp can lead to a heap-based buffer overflow via a cra...Show more |
4Fedoraproject OracleRedhat+1 more4Communications Cloud Native Core Network Function Cloud Native Environment DnsmasqEnterprise Linux+1 moreDec 3, 2025 Apr 8, 2021 N/A· v4 4.0 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dnsmasq uses a fixed port while forwarding queries. An attacker on the network, able to find th...Show more |
2Redhat Theforeman2Foreman Azurerm SatelliteNov 21, 2024 Apr 8, 2021 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was identified which will expose Azure Resource Manager's secret key through JSON of the API output. The h...Show more |
5Debian FedoraprojectNetapp+2 more6Active Iq Unified Manager Debian LinuxEnterprise Linux+3 moreNov 21, 2024 Apr 5, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called wi...Show more |
2Fedoraproject Redhat3Ansible Ansible TowerFedoraNov 21, 2024 Apr 1, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the controller node when run in ve...Show more |
3Fedoraproject RedhatStorage Project4Enterprise Linux FedoraOpenshift Container Platform+1 moreNov 21, 2024 Apr 1, 2021 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archiv...Show more |
2Postgresql Redhat3Enterprise Linux PostgresqlSoftware CollectionsNov 21, 2024 Apr 1, 2021 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under so...Show more |
4Netapp OracleQuarkus+1 more4Communications Cloud Native Core Console Oncommand InsightQuarkus+1 moreNov 21, 2024 Mar 26, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or q...Show more |
4Fedoraproject RedhatRpm+1 more4Enterprise Linux FedoraRpm+1 moreNov 21, 2024 Mar 26, 2021 N/A· v4 7.0 HIGH· v3 5.1 MEDIUM· v2 A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified,...Show more |
4Broadcom GnuNetapp+1 more6Binutils Brocade Fabric Operating System FirmwareCloud Backup+3 moreDec 3, 2025 Mar 26, 2021 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxNov 21, 2024 Mar 26, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP d...Show more |
3Linux NetappRedhat18A700s Firmware Aff A400 FirmwareBrocade Fabric Operating System Firmware+15 moreNov 21, 2024 Mar 26, 2021 N/A· v4 4.5 MEDIUM· v3 4.4 MEDIUM· v2 A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to...Show more |
3Fedoraproject GnuRedhat3Enterprise Linux FedoraLibmicrohttpdNov 21, 2024 Mar 25, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd....Show more |
3Fedoraproject Libtpms ProjectRedhat3Enterprise Linux FedoraLibtpmsNov 21, 2024 Mar 25, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were...Show more |
3Fedoraproject Jasper ProjectRedhat3Enterprise Linux FedoraJasperNov 21, 2024 Mar 25, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jas...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Mar 24, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/pas...Show more |