← Back

Redhat

redhat

5,682 CVEs • 537 products

Products (537)

Click to collapse
Toggle
Linux
linux
Satellite
satellite
Openstack
openstack
Openshift
openshift
Keycloak
keycloak
Fedora Core
fedora_core
Libvirt
libvirt
Ansible Tower
ansible_tower
Cloudforms
cloudforms
Ansible
ansible
Ceph Storage
ceph_storage
Linux Desktop
linux_desktop
Linux Server
linux_server
Jboss Fuse
jboss_fuse
Undertow
undertow
Storage
storage
Quay
quay
Fuse
fuse
Data Grid
data_grid
Resteasy
resteasy
Wildfly
wildfly
Jboss A Mq
jboss_a-mq
Ceph
ceph

CVEs (5,682)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Google
Redhat
4Chrome
Enterprise Linux DesktopEnterprise Linux Server+1 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
2Google
Redhat
4Chrome
Enterprise Linux DesktopEnterprise Linux Server+1 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An out of bounds read in Swiftshader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
2Google
Redhat
4Chrome
Enterprise Linux DesktopEnterprise Linux Server+1 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
Allowing the chrome.debugger API to run on file:// URLs in DevTools in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malicious extension to access files on the local file syste...Show more
Allowing the chrome.debugger API to run on file:// URLs in DevTools in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system without file access permission via a crafted Chrome Extension.Show less
2Google
Redhat
4Chrome
Enterprise Linux DesktopEnterprise Linux Server+1 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
A race condition between permission prompts and navigations in Prompts in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
2Google
Redhat
4Chrome
Enterprise Linux DesktopEnterprise Linux Server+1 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Unsafe handling of credit card details in Autofill in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
2Google
Redhat
4Chrome
Enterprise Linux DesktopEnterprise Linux Server+1 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Missing bounds check in PDFium in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
2Google
Redhat
4Chrome
Enterprise Linux DesktopEnterprise Linux Server+1 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
3Debian
GoogleRedhat
5Chrome
Debian LinuxEnterprise Linux Desktop+2 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxEnterprise Linux Desktop+2 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A use after free in WebAudio in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxEnterprise Linux Desktop+2 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A use after free in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxEnterprise Linux Desktop+2 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Javascript reentrancy issues that caused a use-after-free in V8 in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
2Google
Redhat
4Chrome
Enterprise Linux DesktopEnterprise Linux Server+1 more
Nov 21, 2024
Jan 9, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
2Redhat
Xtermjs
2Openshift Container Platform
Xterm.js
Jun 17, 2026
Jan 9, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.
2Linux
Redhat
2Enterprise Linux Server
Linux Kernel
Nov 21, 2024
Jan 3, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buffer length which causes the read beyond the buffer boundaries, in certain cases...Show more
A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buffer length which causes the read beyond the buffer boundaries, in certain cases causing a memory access fault and a system halt by accessing invalid memory address. This issue only affects kernel version 3.10.x as shipped with Red Hat Enterprise Linux 7.Show less
4Canonical
DebianRedhat+1 more
9Ansible
Ansible EngineDebian Linux+6 more
Nov 21, 2024
Jan 3, 2019
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
1Redhat
1Ansible Tower
Nov 21, 2024
Jan 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive in...Show more
Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.Show less
5Canonical
DebianFedoraproject+2 more
11Debian Linux
Enterprise LinuxEnterprise Linux Desktop+8 more
Nov 21, 2024
Jan 3, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in whi...Show more
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing.Show less
4Debian
FasterxmlOracle+1 more
12Automation Manager
Business Process Management SuiteDebian Linux+9 more
Nov 21, 2024
Jan 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
4Debian
FasterxmlOracle+1 more
12Automation Manager
Business Process Management SuiteDebian Linux+9 more
Nov 21, 2024
Jan 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
4Debian
FasterxmlOracle+1 more
12Automation Manager
Business Process Management SuiteDebian Linux+9 more
Nov 21, 2024
Jan 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.