Redhat
redhat
5,678 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,678)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreNov 21, 2024 Feb 11, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page. |
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreNov 21, 2024 Feb 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreNov 21, 2024 Feb 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page. |
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreNov 21, 2024 Feb 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreNov 21, 2024 Feb 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user coul...Show more |
2Golang Redhat3Enterprise Linux GoOpenstackNov 21, 2024 Feb 8, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and...Show more |
2Kde Redhat5Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server Eus+2 moreNov 21, 2024 Feb 8, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion." |
1Redhat 1Openshift Container Platform Nov 21, 2024 Feb 7, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers modify the permissions of /etc/passwd to make them modifiable by users oth...Show more |
4Canonical CephOpensuse+1 more4Ceph LeapOpenshift Container Storage+1 moreNov 21, 2024 Feb 7, 2020 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket conn...Show more |
5Debian NodejsOpensuse+2 more7Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxEnterprise Linux+4 moreNov 21, 2024 Feb 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons |
6Debian FedoraprojectNodejs+3 more13Debian Linux Enterprise LinuxEnterprise Linux Desktop+10 moreNov 21, 2024 Feb 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed |
5Debian NodejsOpensuse+2 more10Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxEnterprise Linux+7 moreNov 21, 2024 Feb 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate |
2Gnome Redhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreNov 21, 2024 Feb 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which mig...Show more |
2Redhat Unzip Project6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Eus+3 moreNov 21, 2024 Jan 31, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command. |
7Arista CanonicalFedoraproject+4 more11Enterprise Linux EosFedora+8 moreNov 21, 2024 Jan 31, 2020 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop a...Show more |
2Redhat Unzip Project7Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+4 moreNov 21, 2024 Jan 31, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command. |
2Redhat Unzip Project7Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+4 moreNov 21, 2024 Jan 31, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command. |
3Abrt Project FedoraprojectRedhat5Abrt Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Jan 31, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ABRT might allow attackers to obtain sensitive information from crash reports. |
6Apache CanonicalDebian+3 more7Debian Linux FedoraJboss Amq Clients+4 moreNov 21, 2024 Jan 29, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header. |