Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Ovirt Redhat2Ovirt Virtualization ManagerJun 17, 2026 Jul 11, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks...Show more |
5Canonical DebianOracle+2 more9Communications Operations Monitor Debian LinuxEnterprise Linux+6 moreJun 17, 2026 Jul 11, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attac...Show more |
5Canonical DebianOracle+2 more10Communications Operations Monitor Debian LinuxEnterprise Linux+7 moreJun 17, 2026 Jul 11, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command,...Show more |
3Fasterxml OracleRedhat7Clusterware Communications Instant Messaging ServerGlobal Lifecycle Management Opatch+4 moreNov 21, 2024 Jul 9, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6. |
virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be present in the --root-password option to virt_bootstrap.py. |
3Fedoraproject LibosinfoRedhat6Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+3 moreJun 17, 2026 Jul 5, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line. |
1Redhat 2Enterprise Linux Virt ManagerJun 17, 2026 Jul 3, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction. This option accepts guest VM password as command line arguments, thus leaking...Show more |
A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary...Show more |
It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extend...Show more |
1Redhat 1Cloudforms Management Engine Jun 17, 2026 Jun 27, 2019 N/A· v4 6.5 MEDIUM· v3 6.0 MEDIUM· v2 A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is not properly sanitized. An attacker with least privilege to edit compute...Show more |
4Fedoraproject OpensusePostgresql+1 more4Enterprise Linux FedoraLeap+1 moreJun 17, 2026 Jun 26, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpos...Show more |
6Canonical DebianFedoraproject+3 more9Debian Linux Enterprise LinuxEnterprise Linux Eus+6 moreJun 17, 2026 Jun 25, 2019 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap abov...Show more |
3Debian FasterxmlRedhat3Debian Linux Enterprise LinuxJackson DatabindJun 17, 2026 Jun 24, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content,...Show more |
2Linux Redhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+2 moreJun 17, 2026 Jun 19, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS). |
4Canonical F5Linux+1 more21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+18 moreJun 17, 2026 Jun 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker cou...Show more |
6Canonical F5Ivanti+3 more24Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+21 moreJun 17, 2026 Jun 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker c...Show more |
6Canonical F5Ivanti+3 more24Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+21 moreJun 17, 2026 Jun 19, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to caus...Show more |
4Debian OpensusePhp+1 more4Debian Linux LeapPhp+1 moreJun 17, 2026 Jun 19, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 it is possible to supply it with data wh...Show more |
4Debian OpensusePhp+1 more4Debian Linux LeapPhp+1 moreJun 17, 2026 Jun 19, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may perform out-of-buffer read due to integer overflow when parsing MIME headers. This may lead to informa...Show more |
8Canonical DebianFedoraproject+5 more13Debian Linux Enterprise LinuxFedora+10 moreJun 17, 2026 Jun 19, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to...Show more |