Redhat
redhat
5,681 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,681)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Jenkins Redhat2Git Openshift Container PlatformNov 21, 2024 Feb 6, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach correspo...Show more |
5Canonical DebianMozilla+2 more12Debian Linux Enterprise LinuxEnterprise Linux Desktop+9 moreNov 21, 2024 Feb 5, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the p...Show more |
4Canonical DebianMozilla+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 25, 2025 Feb 5, 2019 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is ins...Show more |
4Canonical DebianMozilla+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 21, 2024 Feb 5, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of...Show more |
4Canonical DebianMozilla+1 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreNov 21, 2024 Feb 5, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable c...Show more |
2Kube Rbac Proxy Project Redhat2Kube Rbac Proxy Openshift Container PlatformNov 21, 2024 Feb 5, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker could target traffic sen...Show more |
6Canonical DebianFedoraproject+3 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Feb 4, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ISO9660 parser, archive_read...Show more |
6Canonical DebianFedoraproject+3 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Feb 4, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_format_7zip.c, header_b...Show more |
4Canonical DebianRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Feb 4, 2019 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated...Show more |
10Canonical DebianHp+7 more32Active Iq Unified Manager Cloud BackupDebian Linux+29 moreMay 28, 2026 Feb 4, 2019 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute. |
5Canonical DebianFedoraproject+2 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 Feb 3, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have un...Show more |
10Apache CanonicalDebian+7 more19Debian Linux Enterprise LinuxEnterprise Linux Eus+16 moreDec 18, 2025 Jan 31, 2019 N/A· v4 5.9 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validati...Show more |
9Canonical DebianFedoraproject+6 more20Debian Linux Element SoftwareEnterprise Linux+17 moreMay 28, 2026 Jan 31, 2019 N/A· v4 6.8 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g.,...Show more |
7Apache CanonicalDebian+4 more12Debian Linux Enterprise Manager Ops CenterFedora+9 moreNov 21, 2024 Jan 30, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. Thi...Show more |
5Canonical DebianElfutils Project+2 more11Debian Linux ElfutilsEnterprise Linux+8 moreNov 21, 2024 Jan 29, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core fi...Show more |
2Debian Redhat7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Jan 28, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to...Show more |
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable. |
3Debian RedhatRsyslog12Debian Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+9 moreNov 21, 2024 Jan 25, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnera...Show more |
An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs...Show more |
2Jenkins Redhat2Jenkins Openshift Container PlatformJun 17, 2026 Jan 22, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/AuthenticationProcessingFilter2.java that allows attackers to extend the duration...Show more |