Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Artifex Redhat2Enterprise Linux GhostscriptJun 17, 2026 Sep 3, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service. |
6Canonical DebianFedoraproject+3 more7Debian Linux Enterprise LinuxFedora+4 moreJun 17, 2026 Aug 31, 2020 N/A· v4 5.0 MEDIUM· v3 4.4 MEDIUM· v2 An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[409...Show more |
3Fedoraproject OpensuseRedhat4Backports Sle FedoraLeap+1 moreJun 17, 2026 Aug 30, 2020 N/A· v4 8.0 HIGH· v3 8.5 HIGH· v2 A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be abl...Show more |
2Debian Redhat2Ansible Debian LinuxJun 17, 2026 Aug 26, 2020 N/A· v4 7.3 HIGH· v3 6.1 MEDIUM· v2 A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the re...Show more |
2Oracle Redhat2Ovirt Engine VirtualizationJun 17, 2026 Aug 24, 2020 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the ma...Show more |
6Canonical DebianLinux+3 more10Active Iq Unified Manager Cloud BackupDebian Linux+7 moreJun 17, 2026 Aug 19, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privile...Show more |
1Redhat 1Cloudforms Management Engine Jun 17, 2026 Aug 11, 2020 N/A· v4 9.1 CRITICAL· v3 6.5 MEDIUM· v2 A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerability can be exploited by authenticated attacker while setuping conversio...Show more |
An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the exi...Show more |
1Redhat 1Cloudforms Management Engine Jun 17, 2026 Aug 11, 2020 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not nor...Show more |
1Redhat 1Cloudforms Management Engine Jun 17, 2026 Aug 11, 2020 N/A· v4 6.3 MEDIUM· v3 4.9 MEDIUM· v2 Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering...Show more |
Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and non-existent role-based access control user, with groups and roles. Wi...Show more |
Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group can perform actions restricted only to EVM-Super-administrator group, leads to, exporting or importi...Show more |
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible...Show more |
In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate...Show more |
A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms. |
7Apache CanonicalDebian+4 more25Communications Element Manager Communications Session Report ManagerCommunications Session Route Manager+22 moreJun 17, 2026 Aug 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Confi...Show more |
2Fedoraproject Redhat2Etcd FedoraJun 17, 2026 Aug 6, 2020 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on endpoints identified i...Show more |
2Fedoraproject Redhat2Etcd FedoraJun 17, 2026 Aug 6, 2020 N/A· v4 7.7 HIGH· v3 4.0 MEDIUM· v2 In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a...Show more |
2Fedoraproject Redhat2Etcd FedoraJun 17, 2026 Aug 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users'...Show more |
It was found that the AMQ Online console is vulnerable to a Cross-Site Request Forgery (CSRF) which is exploitable in cases where preflight checks are not instigated or bypassed. For example authorised users using an old...Show more |