Redhat
redhat
5,681 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,681)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical DebianFedoraproject+3 more22Active Iq Unified Manager Aff A700s FirmwareDebian Linux+19 moreNov 6, 2025 Jul 17, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by lev...Show more |
6Canonical DebianFedoraproject+3 more13Backports Sle Debian LinuxEnterprise Linux+10 moreNov 21, 2024 Jul 16, 2019 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c. |
1Redhat 1Openshift Container Platform Nov 21, 2024 Jul 11, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could u...Show more |
5Canonical DebianFedoraproject+2 more8Debian Linux Enterprise LinuxEnterprise Linux Eus+5 moreNov 21, 2024 Jul 11, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't g...Show more |
2Ovirt Redhat2Ovirt Virtualization ManagerNov 21, 2024 Jul 11, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks...Show more |
5Canonical DebianOracle+2 more9Communications Operations Monitor Debian LinuxEnterprise Linux+6 moreNov 21, 2024 Jul 11, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attac...Show more |
5Canonical DebianOracle+2 more10Communications Operations Monitor Debian LinuxEnterprise Linux+7 moreNov 21, 2024 Jul 11, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command,...Show more |
3Fasterxml OracleRedhat7Clusterware Communications Instant Messaging ServerGlobal Lifecycle Management Opatch+4 moreNov 21, 2024 Jul 9, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6. |
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py. |
3Fedoraproject LibosinfoRedhat6Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+3 moreNov 21, 2024 Jul 5, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line. |
1Redhat 2Enterprise Linux Virt ManagerNov 21, 2024 Jul 3, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction. This option accepts guest VM password as command line arguments, thus leaking...Show more |
A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary...Show more |
It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extend...Show more |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Jun 27, 2019 N/A· v4 6.5 MEDIUM· v3 6.0 MEDIUM· v2 A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is not properly sanitized. An attacker with least privilege to edit compute...Show more |
4Fedoraproject OpensusePostgresql+1 more4Enterprise Linux FedoraLeap+1 moreNov 21, 2024 Jun 26, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpos...Show more |
6Canonical DebianFedoraproject+3 more9Debian Linux Enterprise LinuxEnterprise Linux Eus+6 moreNov 21, 2024 Jun 25, 2019 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap abov...Show more |
3Debian FasterxmlRedhat3Debian Linux Enterprise LinuxJackson DatabindNov 21, 2024 Jun 24, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content,...Show more |
2Linux Redhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+2 moreNov 21, 2024 Jun 19, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS). |
4Canonical F5Linux+1 more21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+18 moreNov 21, 2024 Jun 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker cou...Show more |
6Canonical F5Ivanti+3 more24Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+21 moreNov 21, 2024 Jun 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker c...Show more |