Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianNetty+1 more4Debian Linux Jboss Enterprise Application PlatformNetty+1 moreJun 17, 2026 Sep 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling. |
8Apache CanonicalDebian+5 more10Clustered Data Ontap Communications Element ManagerDebian Linux+7 moreJun 17, 2026 Sep 26, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of...Show more |
4Canonical DebianNovnc+1 more4Debian Linux NovncOpenstack+1 moreNov 21, 2024 Sep 25, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name. |
3Fedoraproject RedhatRubyzip Project3Cloudforms FedoraRubyzipJun 17, 2026 Sep 25, 2019 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). |
6Canonical DockerFedoraproject+3 more10Docker Enterprise LinuxEnterprise Linux Eus+7 moreJun 17, 2026 Sep 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image...Show more |
CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (admin/admin) for the administrator account located at grafana-credentials secret. This occurs because...Show more |
4Canonical DebianGnome+1 more4Debian Linux Enterprise LinuxFile Roller+1 moreJun 17, 2026 Sep 21, 2019 N/A· v4 4.3 MEDIUM· v3 2.6 LOW· v2 An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction. |
7Canonical DebianFedoraproject+4 more39A220 Firmware A320 FirmwareA700s Firmware+36 moreJun 17, 2026 Sep 20, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute ar...Show more |
6Canonical DebianLinux+3 more34A220 Firmware A320 FirmwareA700s Firmware+31 moreJun 17, 2026 Sep 20, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly exec...Show more |
8Canonical DebianFedoraproject+5 more28Aff A700s Firmware Data Availability ServicesDebian Linux+25 moreJun 17, 2026 Sep 19, 2019 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kv...Show more |
8Canonical DebianFedoraproject+5 more34Aff A700s Firmware Data Availability ServicesDebian Linux+31 moreJun 17, 2026 Sep 17, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged gu...Show more |
2Freeipa Redhat2Enterprise Linux FreeipaJun 17, 2026 Sep 17, 2019 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain ac...Show more |
6Debian FasterxmlFedoraproject+3 more17Banking Platform Customer Management And Segmentation FoundationDebian Linux+14 moreJun 17, 2026 Sep 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540. |
6Debian FasterxmlFedoraproject+3 more19Banking Platform Customer Management And Segmentation FoundationDebian Linux+16 moreJun 17, 2026 Sep 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig. |
4Canonical LinuxOpensuse+1 more4Enterprise Linux LeapLinux Kernel+1 moreJun 17, 2026 Sep 13, 2019 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via an interrupt. To exploit the venerability, a local user starts a transaction (via the hardw...Show more |
4Canonical LinuxOpensuse+1 more4Enterprise Linux LeapLinux Kernel+1 moreJun 17, 2026 Sep 13, 2019 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a Facility Unavailable exception. To exploit the venerability, a local user starts a transa...Show more |
4Canonical LinuxOpensuse+1 more4Enterprise Linux LeapLinux Kernel+1 moreJun 17, 2026 Sep 11, 2019 N/A· v4 4.1 MEDIUM· v3 4.7 MEDIUM· v2 drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. |
4Canonical LinuxOpensuse+1 more4Enterprise Linux LeapLinux Kernel+1 moreJun 17, 2026 Sep 11, 2019 N/A· v4 4.1 MEDIUM· v3 4.7 MEDIUM· v2 drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. |
3Canonical LinuxRedhat3Enterprise Linux Linux KernelUbuntu LinuxJun 17, 2026 Sep 11, 2019 N/A· v4 4.1 MEDIUM· v3 4.7 MEDIUM· v2 drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: The security community disputes this issues as not being...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 Sep 6, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the sha...Show more |