Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Jan 26, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously ac...Show more |
3Fedoraproject M2crypto ProjectRedhat4Enterprise Linux FedoraM2crypto+1 moreNov 21, 2024 Jan 12, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat fro...Show more |
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and o...Show more |
2Fedoraproject Redhat3Ceph Ceph StorageFedoraNov 21, 2024 Jan 8, 2021 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible. |
1Redhat 1Jboss Core Services Httpd Nov 21, 2024 Jan 7, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate whether CN and hostname are matching stopp...Show more |
5Debian FedoraprojectOracle+2 more11Codeready Linux Builder Codeready Linux Builder For Ibm Z SystemsCodeready Linux Builder For Power Little Endian+8 moreNov 21, 2024 Jan 5, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is...Show more |
4Broadcom GnuNetapp+1 more8Binutils Brocade Fabric Operating SystemCloud Backup+5 moreNov 21, 2024 Jan 4, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dere...Show more |
2Ovirt Redhat2Ovirt Engine VirtualizationNov 21, 2024 Dec 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in ovirt-engine 4.4.3 and earlier allowing an authenticated user to read other users' personal information, including name, email and public SSH key. |
4Fedoraproject GrafanaRedhat+1 more6Enterprise Linux FedoraGrafana+3 moreNov 21, 2024 Dec 21, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system av...Show more |
2Fedoraproject Redhat5Ceph Ceph StorageFedora+2 moreNov 21, 2024 Dec 18, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx us...Show more |
A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful authentication, redirects to a Keycloak endpoint that accepts multiple invocations with the use of the same "state" paramet...Show more |
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Ser...Show more |
2Linux Redhat3Enterprise Linux Linux KernelOpenshift Container PlatformNov 21, 2024 Dec 15, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors (pseries platform) a...Show more |
2Redhat X.org2Enterprise Linux X ServerNov 21, 2024 Dec 15, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and i...Show more |
4Debian LinuxNetapp+1 more7Cloud Backup Debian LinuxEnterprise Linux+4 moreNov 21, 2024 Dec 11, 2020 N/A· v4 5.7 MEDIUM· v3 5.4 MEDIUM· v2 A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of...Show more |
3Linux NetappRedhat6Cloud Backup Enterprise LinuxEnterprise Mrg+3 moreNov 21, 2024 Dec 11, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl commands to midi devices could trigger a use-after-free issue. A write to this spec...Show more |
1Redhat 1Language Support For Java Aug 28, 2025 Dec 10, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability |
A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final. When an application uses the OpenTracing API's java-interceptors, there is a possibility of a memor...Show more |
3Netapp OpenldapRedhat4Cloud Backup Enterprise LinuxOpenldap+1 moreNov 21, 2024 Dec 8, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially craf...Show more |
2Ceph Redhat2Ceph Ansible Ceph StorageNov 21, 2024 Dec 8, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The hig...Show more |