Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFreedesktop+1 more10Debian Linux Enterprise LinuxEnterprise Linux Desktop+7 moreNov 21, 2024 Jan 1, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in...Show more |
5Debian GoogleOpensuse+2 more5Chrome Debian LinuxLeap+2 moreNov 21, 2024 Dec 21, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers...Show more |
3Artifex DebianRedhat7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Dec 20, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code i...Show more |
2Elastic Redhat2Kibana Openshift Container PlatformNov 21, 2024 Dec 20, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code....Show more |
6Canonical DebianFedoraproject+3 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Dec 20, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can...Show more |
5Canonical DebianFedoraproject+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Dec 20, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes...Show more |
3Canonical GnuRedhat5Binutils Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Dec 20, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successf...Show more |
4Canonical DebianLibvnc Project+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Dec 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution |
4Canonical DebianLinux+1 more5Debian Linux Enterprise LinuxEnterprise Mrg+2 moreNov 21, 2024 Dec 18, 2018 N/A· v4 8.0 HIGH· v3 6.7 MEDIUM· v2 A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerabilit...Show more |
3Grafana NetappRedhat7Active Iq Performance Analytics Services Ceph StorageEnterprise Linux Desktop+4 moreNov 21, 2024 Dec 13, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions. |
3Canonical HaproxyRedhat3Haproxy Openshift Container PlatformUbuntu LinuxNov 21, 2024 Dec 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid poin...Show more |
3Canonical HaproxyRedhat3Haproxy Openshift Container PlatformUbuntu LinuxNov 21, 2024 Dec 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding t...Show more |
4Debian Exiv2Fedoraproject+1 more6Debian Linux Enterprise Linux DekstopEnterprise Linux Server+3 moreNov 21, 2024 Dec 12, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack. |
3Canonical LinuxRedhat10Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+7 moreNov 21, 2024 Dec 12, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user ha...Show more |
3Debian GoogleRedhat5Chrome Debian LinuxLinux Desktop+2 moreNov 21, 2024 Dec 11, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreNov 21, 2024 Dec 11, 2018 N/A· v4 5.7 MEDIUM· v3 2.9 LOW· v2 Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file. |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreNov 21, 2024 Dec 11, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. |
5Canonical DebianGoogle+2 more10Chrome Debian LinuxEnterprise Linux Desktop+7 moreNov 21, 2024 Dec 11, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreNov 21, 2024 Dec 11, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreNov 21, 2024 Dec 11, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launch external programs via a crafted HTML page. |