← Back

Redhat

redhat

5,899 CVEs • 544 products

Products (544)

Click to collapse
Toggle
Satellite
satellite
Linux
linux
Openstack
openstack
Openshift
openshift
Keycloak
keycloak
Fedora Core
fedora_core
Libvirt
libvirt
Ansible Tower
ansible_tower
Cloudforms
cloudforms
Ansible
ansible
Ceph Storage
ceph_storage
Linux Desktop
linux_desktop
Linux Server
linux_server
Jboss Fuse
jboss_fuse
Undertow
undertow
Quay
quay
Storage
storage
Fuse
fuse
Data Grid
data_grid
Resteasy
resteasy
Wildfly
wildfly
Jboss A Mq
jboss_a-mq
Ceph
ceph

CVEs (5,899)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A stagnant permission prompt in Prompts in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass permission policy via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Missing confusable characters in Internationalization in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
A lack of host validation in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page, if the user is running a remote DevTools debugging server.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A lack of CORS checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Inappropriate dismissal of file picker on keyboard events in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to read local files via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Inline metadata in GarbageCollection in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An integer overflow that lead to a heap buffer-overflow in Skia in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML pag...Show more
A lack of CORS checks, after a Service Worker redirected to a cross-origin PDF, in Service Worker in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak limited cross-origin data via a crafted HTML page.Show less
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An iterator-invalidation bug in PDFium in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A use-after-free in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A double-eviction in the Incognito mode cache that lead to a user-after-free in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
3Debian
GoogleRedhat
5Chrome
Debian LinuxLinux Desktop+2 more
Jun 17, 2026
Dec 4, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Re-entry of a destructor in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
2Artifex
Redhat
7Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Server Aus+4 more
Nov 21, 2024
Dec 3, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a...Show more
It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat Enterprise Linux 7.Show less
2Redhat
Rubyonrails
2Cloudforms
Rails
Nov 21, 2024
Nov 30, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they shoul...Show more
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.Show less