← Back

Redhat

redhat

5,899 CVEs • 544 products

Products (544)

Click to collapse
Toggle
Satellite
satellite
Linux
linux
Openstack
openstack
Openshift
openshift
Keycloak
keycloak
Fedora Core
fedora_core
Libvirt
libvirt
Ansible Tower
ansible_tower
Cloudforms
cloudforms
Ansible
ansible
Ceph Storage
ceph_storage
Linux Desktop
linux_desktop
Linux Server
linux_server
Jboss Fuse
jboss_fuse
Undertow
undertow
Quay
quay
Storage
storage
Fuse
fuse
Data Grid
data_grid
Resteasy
resteasy
Wildfly
wildfly
Jboss A Mq
jboss_a-mq
Ceph
ceph

CVEs (5,899)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectRedhat
3389 Directory Server
Debian LinuxEnterprise Linux
Jun 17, 2026
Nov 8, 2019
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes,...Show more
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.Show less
3Ceph
FedoraprojectRedhat
3Ceph
Ceph StorageFedora
Jun 17, 2026
Nov 8, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connectio...Show more
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.Show less
3Netapp
OracleRedhat
189Access Manager
Active Iq Unified ManagerAgile Engineering Data Management+186 more
Aug 25, 2026
Nov 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can r...Show more
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.Show less
2Fedoraproject
Redhat
2Fedora
Tuned
Nov 21, 2024
Nov 8, 2019
N/A· v4
5.5 MEDIUM· v3
4.7 MEDIUM· v2
tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.
1Redhat
1Jboss Operations Network
Nov 21, 2024
Nov 8, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.
1Redhat
1Frysk
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
frysk packages through 2008-08-05 as shipped in Red Hat Enterprise Linux 5 are built with an insecure RPATH set in the ELF header of multiple binaries in /usr/bin/f* (e.g. fcore, fcatch, fstack, fstep, ...) shipped in th...Show more
frysk packages through 2008-08-05 as shipped in Red Hat Enterprise Linux 5 are built with an insecure RPATH set in the ELF header of multiple binaries in /usr/bin/f* (e.g. fcore, fcatch, fstack, fstep, ...) shipped in the package. A local attacker can exploit this vulnerability by running arbitrary code as another user.Show less
3Fedoraproject
LinuxRedhat
3Enterprise Linux
FedoraLinux Kernel
Jun 17, 2026
Nov 7, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_para...Show more
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.Show less
5Broadcom
LinuxNetapp+2 more
17Active Iq Unified Manager
Aff A400 FirmwareAff A700s Firmware+14 more
Jun 17, 2026
Nov 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc...Show more
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other impact, aka CID-19fad20d15a6.Show less
2Fedoraproject
Redhat
3Enterprise Linux
FedoraPagure
Nov 21, 2024
Nov 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Pagure: XSS possible in file attachment endpoint
1Redhat
2Enterprise Linux
Enterprise Mrg
Nov 21, 2024
Nov 6, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.
3Dovecot
OpensuseRedhat
4Dovecot
Enterprise LinuxLeap+1 more
Nov 21, 2024
Nov 5, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
5Debian
FedoraprojectPypa+2 more
6Debian Linux
FedoraOpenshift+3 more
Nov 21, 2024
Nov 5, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
1Redhat
2389 Directory Server
Directory Server
Nov 21, 2024
Nov 5, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer dereference) via a crafted search query.
4Isc
NicNlnetlabs+1 more
4Bind
Enterprise LinuxKnot Resolver+1 more
Nov 21, 2024
Nov 5, 2019
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
Cache Poisoning issue exists in DNS Response Rate Limiting.
3Debian
NokogiriRedhat
7Cloudforms Management Engine
Debian LinuxEnterprise Mrg+4 more
Nov 21, 2024
Nov 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
3Debian
NokogiriRedhat
7Cloudforms Management Engine
Debian LinuxEnterprise Mrg+4 more
Nov 21, 2024
Nov 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
4Debian
GnomeOpensuse+1 more
4Debian Linux
Enterprise LinuxGnome Display Manager+1 more
Nov 21, 2024
Nov 5, 2019
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
gdm3 3.14.2 and possibly later has an information leak before screen lock
2Kubernetes
Redhat
2Kube State Metrics
Openshift Container Platform
Jun 17, 2026
Nov 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-...Show more
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default `kubectl` behavior and this new feature can cause the entire secret content to end up in metric labels thus inadvertently exposing the secret content in metrics. This feature has been reverted and released as the v1.7.2 release. If you are running the v1.7.0 or v1.7.1 release, please upgrade to the v1.7.2 release as soon as possible.Show less
1Redhat
2Jboss Operations Network
Rhq Mongo Db Drift Server
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped files.
5Canonical
DebianIcoutils Project+2 more
11Debian Linux
Enterprise LinuxEnterprise Linux Desktop+8 more
Nov 21, 2024
Nov 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafte...Show more
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.Show less