Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
It has been discovered in redhat-certification that any unauthorized user may download any file under /var/www/rhcert, provided they know its name. Red Hat Certification 6 and 7 is vulnerable to this issue. |
1Redhat 9A Mq Online Build Of QuarkusCodeready Studio+6 moreJun 17, 2026 Mar 16, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside t...Show more |
1Redhat 2Enterprise Linux LibnbdJun 17, 2026 Mar 15, 2021 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service. |
3Dogtagpki FedoraprojectRedhat4Certificate System DogtagpkiEnterprise Linux+1 moreJun 17, 2026 Mar 15, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat...Show more |
3Fedoraproject GnuRedhat3Enterprise Linux FedoraGnutlsJun 17, 2026 Mar 12, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences. |
4Fedoraproject GnuNetapp+1 more5Active Iq Unified Manager E Series Performance AnalyzerEnterprise Linux+2 moreJun 17, 2026 Mar 12, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences. |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Mar 11, 2021 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 A race condition was found in the Linux kernels implementation of the floppy disk drive controller driver software. The impact of this issue is lessened by the fact that the default permissions on the floppy device (/dev...Show more |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Mar 9, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a padding of int3 in the linking state. The highest threat from this vulnerability is to data confide...Show more |
5Debian FedoraprojectLibtiff+2 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Mar 9, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerabi...Show more |
4Debian LibtiffNetapp+1 more4Debian Linux Enterprise LinuxLibtiff+1 moreJun 17, 2026 Mar 9, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this...Show more |
4Fedoraproject LibtiffNetapp+1 more4Enterprise Linux FedoraLibtiff+1 moreJun 17, 2026 Mar 9, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a remote denial of service attack. |
4Fedoraproject LibtiffNetapp+1 more4Enterprise Linux FedoraLibtiff+1 moreJun 17, 2026 Mar 9, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service. |
4Debian FedoraprojectImagemagick+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Mar 9, 2021 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat...Show more |
4Debian FedoraprojectImagemagick+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Mar 9, 2021 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from thi...Show more |
4Debian FedoraprojectImagemagick+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Mar 9, 2021 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest t...Show more |
1Redhat 2Keycloak Single Sign OnJun 17, 2026 Mar 9, 2021 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s brows...Show more |
A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environ...Show more |
1Redhat 2Keycloak Single Sign OnJun 17, 2026 Mar 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same...Show more |
3Fedoraproject RedhatYtnef Project3Enterprise Linux FedoraYtnefJun 17, 2026 Mar 4, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file. |
3Fedoraproject RedhatYtnef Project3Enterprise Linux FedoraYtnefJun 17, 2026 Mar 4, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file. |