← Back

Redhat

redhat

5,899 CVEs • 544 products

Products (544)

Click to collapse
Toggle
Satellite
satellite
Linux
linux
Openstack
openstack
Openshift
openshift
Keycloak
keycloak
Fedora Core
fedora_core
Libvirt
libvirt
Ansible Tower
ansible_tower
Cloudforms
cloudforms
Ansible
ansible
Ceph Storage
ceph_storage
Linux Desktop
linux_desktop
Linux Server
linux_server
Jboss Fuse
jboss_fuse
Undertow
undertow
Quay
quay
Storage
storage
Fuse
fuse
Data Grid
data_grid
Resteasy
resteasy
Wildfly
wildfly
Jboss A Mq
jboss_a-mq
Ceph
ceph

CVEs (5,899)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Certification
Nov 21, 2024
May 26, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to remove a "system" file, that is an xml file with host related info...Show more
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to remove a "system" file, that is an xml file with host related information, not belonging to him.Show less
1Redhat
1Certification
Nov 21, 2024
May 26, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system,...Show more
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system, even if not belonging to him.Show less
1Redhat
1Certification
Nov 21, 2024
May 26, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker...Show more
It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker may use this flaw to gather sensible information.Show less
2Fedoraproject
Redhat
3Ansible
Ansible TowerFedora
Jun 17, 2026
May 26, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker t...Show more
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.Show less
1Redhat
13scale
Jun 17, 2026
May 26, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks.
2Netapp
Redhat
2Libvirt
Ontap Select Deploy Administration Utility
Jun 17, 2026
May 24, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used...Show more
A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that supports mediated devices (e.g., GRID driver). This flaw could be used by an unprivileged client with a read-only connection to crash the libvirt daemon by executing the 'nodedev-list' virsh command. The highest threat from this vulnerability is to system availability.Show less
4Debian
NetappRedhat+1 more
4Debian Linux
Enterprise LinuxLibwebp+1 more
Jun 17, 2026
May 21, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
5Apple
DebianNetapp+2 more
6Debian Linux
Enterprise LinuxIpados+3 more
Jun 17, 2026
May 21, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.
5Apple
DebianNetapp+2 more
6Debian Linux
Enterprise LinuxIpados+3 more
Jun 17, 2026
May 21, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availabilit...Show more
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.Show less
5Apple
DebianNetapp+2 more
6Debian Linux
Enterprise LinuxIpados+3 more
Jun 17, 2026
May 21, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as syst...Show more
A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less
5Apple
DebianNetapp+2 more
6Debian Linux
Enterprise LinuxIpados+3 more
Jun 17, 2026
May 21, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data...Show more
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less
2Redhat
Webmproject
2Enterprise Linux
Libwebp
Nov 21, 2024
May 21, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
2Redhat
Webmproject
2Enterprise Linux
Libwebp
Nov 21, 2024
May 21, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
2Redhat
Webmproject
2Enterprise Linux
Libwebp
Nov 21, 2024
May 21, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
2Redhat
Webmproject
2Enterprise Linux
Libwebp
Nov 21, 2024
May 21, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
2Redhat
Webmproject
2Enterprise Linux
Libwebp
Nov 21, 2024
May 21, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().
2Redhat
Webmproject
2Enterprise Linux
Libwebp
Nov 21, 2024
May 21, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
1Redhat
9Build Of Quarkus
Data GridDescision Manager+6 more
Jun 17, 2026
May 20, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality...Show more
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity.Show less
6Debian
FedoraprojectNetapp+3 more
10Cloud Backup
Communications Cloud Native Core Binding Support FunctionDebian Linux+7 more
Jun 17, 2026
May 20, 2021
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive inform...Show more
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.Show less
6Debian
FedoraprojectNetapp+3 more
28Active Iq Unified Manager
Clustered Data OntapClustered Data Ontap Antivirus Connector+25 more
Jun 17, 2026
May 19, 2021
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of...Show more
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.Show less