Redhat
redhat
5,681 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,681)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical F5Ivanti+3 more24Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+21 moreNov 21, 2024 Jun 19, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to caus...Show more |
4Debian OpensusePhp+1 more4Debian Linux LeapPhp+1 moreNov 21, 2024 Jun 19, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 it is possible to supply it with data wh...Show more |
4Debian OpensusePhp+1 more4Debian Linux LeapPhp+1 moreNov 21, 2024 Jun 19, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due to integer overflow when parsing MIME headers. This may lead to informa...Show more |
8Canonical DebianFedoraproject+5 more13Debian Linux Enterprise LinuxFedora+10 moreNov 21, 2024 Jun 19, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to...Show more |
2Gnu Redhat2Bash Enterprise LinuxNov 21, 2024 Jun 18, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment variable, are printed through the echo built-in function. A local attac...Show more |
4Debian OpensuseRedhat+1 more4Debian Linux Enterprise LinuxLeap+1 moreNov 21, 2024 Jun 17, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eva...Show more |
1Redhat 2Cfme Gemset CloudformsNov 21, 2024 Jun 14, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration log controller. An attacker with access to an unprivileged user can access all V...Show more |
6Canonical DebianLinux+3 more23A700s Firmware Active Iq Unified ManagerCn1610 Firmware+20 moreNov 21, 2024 Jun 14, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences. |
2Adobe Redhat4Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+1 moreNov 21, 2024 Jun 12, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Adobe Flash Player versions 32.0.0.192 and earlier, 32.0.0.192 and earlier, and 32.0.0.192 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution. |
2Netapp Redhat6Active Iq Unified Manager Jboss Data GridOpenshift Application Runtimes+3 moreNov 21, 2024 Jun 12, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR le...Show more |
1Redhat 2Keycloak Single Sign OnNov 21, 2024 Jun 12, 2019 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate it...Show more |
1Redhat 2Jboss Enterprise Application Platform Single Sign OnNov 21, 2024 Jun 12, 2019 N/A· v4 9.0 CRITICAL· v3 6.0 MEDIUM· v2 It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting...Show more |
1Redhat 2Jboss Enterprise Application Platform Single Sign OnNov 21, 2024 Jun 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-...Show more |
1Redhat 2Keycloak Single Sign OnNov 21, 2024 Jun 12, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a mal...Show more |
5Fedoraproject LibreswanRedhat+2 more5Enterprise Linux FedoraLibreswan+2 moreNov 21, 2024 Jun 12, 2019 N/A· v4 3.1 LOW· v3 3.5 LOW· v2 The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a r...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Jun 12, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, cou...Show more |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Jun 12, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive inform...Show more |
6Apache CanonicalFedoraproject+3 more11Communications Session Report Manager Communications Session Route ManagerEnterprise Manager Ops Center+8 moreNov 21, 2024 Jun 11, 2019 N/A· v4 4.2 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the fir...Show more |
7Canonical DebianFedoraproject+4 more14Cloud Backup Converged Systems Advisor AgentDebian Linux+11 moreNov 21, 2024 Jun 7, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attack...Show more |
2Redhat Tuxera6Enterprise Linux Enterprise Linux EusEnterprise Linux Server+3 moreNov 21, 2024 Jun 5, 2019 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer o...Show more |