Redhat
redhat
5,681 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,681)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
7Apple CanonicalDebian+4 more147Alp Al00b Firmware AndroidAres Al00b Firmware+144 moreNov 21, 2024 Aug 14, 2019 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-...Show more |
1Redhat 2Keycloak Single Sign OnNov 21, 2024 Aug 14, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the <Signature> sections, the message is still accepted, an...Show more |
It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request fr...Show more |
11Apache AppleCanonical+8 more18Debian Linux Diskstation ManagerEnterprise Linux+15 moreJan 14, 2025 Aug 13, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These fra...Show more |
12Apache AppleCanonical+9 more23Clustered Data Ontap Communications Element ManagerDebian Linux+20 moreJan 14, 2025 Aug 13, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they...Show more |
12Apache AppleCanonical+9 more19Debian Linux Diskstation ManagerEnterprise Linux+16 moreJan 14, 2025 Aug 13, 2019 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman en...Show more |
12Apache AppleCanonical+9 more22Big Ip Local Traffic Manager Debian LinuxDiskstation Manager+19 moreJan 14, 2025 Aug 13, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one...Show more |
13Apache AppleCanonical+10 more28Big Ip Local Traffic Manager Cloud InsightsDebian Linux+25 moreJan 14, 2025 Aug 13, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream o...Show more |
12Apache AppleCanonical+9 more20Debian Linux Diskstation ManagerEnterprise Communications Broker+17 moreJan 14, 2025 Aug 13, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that c...Show more |
12Apache AppleCanonical+9 more20Debian Linux Diskstation ManagerEnterprise Communications Broker+17 moreJan 14, 2025 Aug 13, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified res...Show more |
7Apple CanonicalDebian+4 more7Debian Linux LeapMac Os X+4 moreNov 21, 2024 Aug 9, 2019 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data wh...Show more |
7Apple CanonicalDebian+4 more7Debian Linux LeapMac Os X+4 moreNov 21, 2024 Aug 9, 2019 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data wh...Show more |
4Canonical DebianOpenstack+1 more4Debian Linux NovaOpenstack+1 moreNov 21, 2024 Aug 9, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the un...Show more |
6Canonical DebianFedoraproject+3 more8Backports Sle Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Aug 7, 2019 N/A· v4 7.8 HIGH· v3 5.1 MEDIUM· v2 In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .dir...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Aug 2, 2019 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability...Show more |
2Fedoraproject Redhat2389 Directory Server Enterprise Linux Server EusNov 21, 2024 Aug 2, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial...Show more |
1Redhat 9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Aug 2, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain....Show more |
1Redhat 9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Aug 2, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt wi...Show more |
1Redhat 9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Aug 2, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state fil...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux Enterprise LinuxFedora+2 moreNov 21, 2024 Aug 1, 2019 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc. |