Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 3Jboss Enterprise Application Platform Openshift Application RuntimesSingle Sign OnNov 21, 2024 Oct 16, 2020 N/A· v4 6.5 MEDIUM· v3 6.3 MEDIUM· v2 A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. This flaw allows an at...Show more |
5Canonical DebianOpensuse+2 more10Debian Linux Enterprise LinuxEnterprise Linux Aus+7 moreNov 21, 2024 Oct 7, 2020 N/A· v4 6.6 MEDIUM· v3 6.5 MEDIUM· v2 Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws....Show more |
2Qemu Redhat3Enterprise Linux Openstack PlatformQemuNov 21, 2024 Oct 6, 2020 N/A· v4 3.2 LOW· v3 2.1 LOW· v2 hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call. |
2Netapp Redhat10Data Grid Jboss Data GridJboss Enterprise Application Platform+7 moreNov 21, 2024 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vuln...Show more |
6Debian LinuxNetapp+3 more6Debian Linux Enterprise LinuxH410c Firmware+3 moreNov 21, 2024 Oct 6, 2020 N/A· v4 7.2 HIGH· v3 7.5 HIGH· v2 A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the sys...Show more |
5Canonical DebianLinux+2 more5Debian Linux Enterprise LinuxLeap+2 moreNov 21, 2024 Oct 6, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial o...Show more |
A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access co...Show more |
A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. Files would remain in the bucket exposing the data. This issue affects dire...Show more |
A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written directly to the root bucket, making possible to have collisions when run...Show more |
3Debian EncodeRedhat3Ceph Storage Debian LinuxDjango Rest FrameworkNov 21, 2024 Sep 30, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This...Show more |
2Opensuse Redhat3Backports Sle LeapPagureNov 21, 2024 Sep 25, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Pagure before 5.6 allows XSS via the templates/blame.html blame view. |
3Fedoraproject Podman ProjectRedhat4Enterprise Linux FedoraOpenshift Container Platform+1 moreNov 21, 2024 Sep 23, 2020 N/A· v4 5.3 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short dura...Show more |
2Debian Redhat5Ansible Engine Ansible TowerCeph Storage+2 moreNov 21, 2024 Sep 23, 2020 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even whe...Show more |
2Netapp Redhat6Codeready Studio Descision ManagerJboss Fuse+3 moreNov 21, 2024 Sep 23, 2020 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat fr...Show more |
1Redhat 3Jboss Enterprise Application Platform Single Sign OnUndertowNov 21, 2024 Sep 23, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP...Show more |
2Quarkus Redhat2Quarkus ResteasyNov 21, 2024 Sep 18, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive information when the server got WebApplicationException from the R...Show more |
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-cra...Show more |
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their perm...Show more |
A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed process API has an exposed setting of the Thread Context Classloader (TCCL). This setting is exposed as a public method, which...Show more |
It was found in AMQ Online before 1.5.2 that injecting an invalid field to a user's AddressSpace configuration of the user namespace puts AMQ Online in an inconsistent state, where the AMQ Online components do not operat...Show more |