Redhat
redhat
5,678 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,678)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectGoogle+1 more7Chrome Debian LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Dec 10, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more7Chrome Debian LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Dec 10, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more7Chrome Debian LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Dec 10, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more7Chrome Debian LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Dec 10, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page. |
3Debian OpenstackRedhat3Debian Linux OpenstackPython KeystoneclientNov 21, 2024 Dec 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass |
4Debian FedoraprojectOpenstack+1 more4Debian Linux FedoraOpenstack+1 moreNov 21, 2024 Dec 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass |
JBoss KeyCloak: XSS in login-status-iframe.html |
1Redhat 2Openstack Openstack EssexNov 21, 2024 Dec 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 openstack-utils openstack-db has insecure password creation |
1Redhat 2Jboss Community Application Server Jboss Enterprise Web ServerNov 21, 2024 Dec 6, 2019 N/A· v4 3.3 LOW· v3 1.9 LOW· v2 An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies |
4Fedoraproject OpenslpRedhat+1 more16Enterprise Linux Desktop Enterprise Linux For Ibm Z SystemsEnterprise Linux For Ibm Z Systems Eus+13 moreOct 30, 2025 Dec 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8. |
3Cesnet FedoraprojectRedhat3Enterprise Linux FedoraLibyangNov 21, 2024 Dec 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "identityref". An application that uses libyang to parse untrusted YANG file...Show more |
2Cesnet Redhat2Enterprise Linux LibyangNov 21, 2024 Dec 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits". An application that uses libyang to parse untrusted YANG files may b...Show more |
2Opencv Redhat2Enterprise Linux OpencvNov 21, 2024 Dec 6, 2019 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_scale within the calc()/ocl_calc() functions in dis_flow.cpp. However, t...Show more |
2Kubernetes Redhat4External Provisioner External ResizerExternal Snapshotter+1 moreNov 21, 2024 Dec 5, 2019 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2)...Show more |
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if inv...Show more |
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS |
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted. |
3Freeradius OpensuseRedhat3Enterprise Linux FreeradiusLeapNov 21, 2024 Dec 3, 2019 N/A· v4 6.5 MEDIUM· v3 2.9 LOW· v2 In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an atta...Show more |
Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging |
3Debian FedoraprojectRedhat4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Dec 3, 2019 N/A· v4 4.7 MEDIUM· v3 3.3 LOW· v2 shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees |