Redhat
redhat
5,678 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,678)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 1Jboss Application Server Nov 21, 2024 Nov 26, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could provide a specially-crafted web page and trick the valid JBoss AS user...Show more |
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common...Show more |
4Fedoraproject GoogleOpensuse+1 more6Backports ChromeEnterprise Linux Desktop+3 moreNov 21, 2024 Nov 25, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. |
1Redhat 1Openshift Container Platform Nov 21, 2024 Nov 25, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discove...Show more |
4Debian FedoraprojectLibuser Project+1 more4Debian Linux Enterprise LinuxFedora+1 moreJan 23, 2026 Nov 25, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 libuser has information disclosure when moving user's home directory |
3Fedoraproject Libuser ProjectRedhat3Enterprise Linux FedoraLibuserNov 21, 2024 Nov 25, 2019 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees. |
3Debian QuaggaRedhat3Debian Linux Enterprise LinuxQuaggaNov 21, 2024 Nov 25, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal |
4Canonical Ibus ProjectOracle+1 more4Enterprise Linux IbusUbuntu Linux+1 moreNov 21, 2024 Nov 25, 2019 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attac...Show more |
3Fedoraproject KubernetesRedhat3Cri O FedoraOpenshift Container PlatformNov 21, 2024 Nov 25, 2019 N/A· v4 5.0 MEDIUM· v3 6.0 MEDIUM· v2 A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of...Show more |
3Linux NetappRedhat18Altavault Baseboard Management ControllerCodeready Linux Builder Eus+15 moreNov 21, 2024 Nov 25, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver. |
5Buildah Project Libpod ProjectOpensuse+2 more6Buildah Enterprise LinuxLeap+3 moreNov 21, 2024 Nov 25, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container regi...Show more |
3Infinispan NetappRedhat7Active Iq Unified Manager FuseInfinispan+4 moreNov 21, 2024 Nov 25, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The att...Show more |
5Broadcom DebianFedoraproject+2 more5Debian Linux FedoraOpenstack+2 moreApr 2, 2025 Nov 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is v...Show more |
3Broadcom RedhatVmware3Openstack RabbitmqRabbitmq ServerApr 2, 2025 Nov 22, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, wh...Show more |
2Python Redhat3Enterprise Linux Enterprise Virtualization HypervisorPyxmlNov 21, 2024 Nov 22, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 PyXML: Hash table collisions CPU usage Denial of Service |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 22, 2019 N/A· v4 4.7 MEDIUM· v3 3.3 LOW· v2 libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files |
3Debian OpenstackRedhat3Debian Linux DesignateEnterprise Linux Openstack PlatformNov 21, 2024 Nov 22, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Designate does not enforce the DNS protocol limit concerning record set sizes |
1Redhat 2Ovirt Engine VirtualizationNov 21, 2024 Nov 22, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center |
1Redhat 2Enterprise Linux Redhat Upgrade ToolNov 21, 2024 Nov 22, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 redhat-upgrade-tool: Does not check GPG signatures when upgrading versions |
3Debian OpensuseRedhat4Ansible Backports SleDebian Linux+1 moreNov 21, 2024 Nov 22, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters....Show more |