Redhat
redhat
5,682 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,682)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian GoogleRedhat5Chrome Debian LinuxLinux Desktop+2 moreNov 21, 2024 Nov 14, 2018 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Incorrect refcounting in AppCache in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform a sandbox escape via a crafted HTML page. |
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. This can lead to an Ope...Show more |
1Redhat 2Keycloak Single Sign OnNov 21, 2024 Nov 13, 2018 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not enforce its protection measures. |
1Redhat 2Keycloak Single Sign OnNov 21, 2024 Nov 13, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascript-Code via the 'state'-parameter in the authentication URL. This allows...Show more |
3Canonical PostgresqlRedhat3Enterprise Linux PostgresqlUbuntu LinuxNov 21, 2024 Nov 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL stat...Show more |
2Nasm Redhat2Enterprise Linux Netwide AssemblerNov 21, 2024 Nov 12, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and ! characters. |
2Nasm Redhat2Enterprise Linux Netwide AssemblerNov 21, 2024 Nov 12, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input. |
3Libwpd Project RedhatSuse3Enterprise Linux LibwpdSuse Linux Enterprise ServerNov 21, 2024 Nov 12, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h. |
3Debian Jasper ProjectRedhat3Debian Linux FedoraJasperNov 21, 2024 Nov 9, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c. |
3Debian KeepalivedRedhat7Debian Linux Enterprise Linux ServerEnterprise Linux Server Aus+4 moreNov 21, 2024 Nov 8, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status cod...Show more |
4Canonical DebianExiv2+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Nov 8, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file. |
4Canonical DebianExiv2+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Nov 8, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-based buffer over-read) caused by an integer overflow via a crafted PSD im...Show more |
4Canonical DebianFreedesktop+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Nov 7, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Poppler 0.71.0. There is a reachable abort in Object.h, will lead to denial of service because EmbFile::save2 in FileSpec.cc lacks a stream check before saving an embedded file. |
1Redhat 2Enterprise Linux RichfacesNov 3, 2025 Nov 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain o...Show more |
A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Si...Show more |
4Canonical DebianFreedesktop+1 more10Debian Linux Enterprise LinuxEnterprise Linux Desktop+7 moreNov 21, 2024 Nov 2, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo. |
3Debian GlusterRedhat5Debian Linux Enterprise Linux ServerGlusterfs+2 moreNov 21, 2024 Nov 1, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode...Show more |
3Debian GlusterRedhat3Debian Linux Enterprise LinuxGlusterfsNov 21, 2024 Oct 31, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of these flaws to execute arbitrary code, cr...Show more |
3Debian GlusterRedhat5Debian Linux Enterprise Linux ServerGlusterfs+2 moreNov 21, 2024 Oct 31, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vulnerable to a format string attack. A remote, authenticated attacker coul...Show more |
3Apache DebianRedhat3Debian Linux Jboss Core ServicesTomcat Jk ConnectorNov 21, 2024 Oct 31, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If...Show more |