Redhat
redhat
5,682 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,682)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Openshift Openshift Container PlatformNov 21, 2024 Aug 1, 2018 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally...Show more |
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack. |
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the se...Show more |
1Redhat 2Jboss Bpm Suite Jboss Business Rules Management SystemNov 21, 2024 Aug 1, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 JBoss BRMS 6 and BPM Suite 6 are vulnerable to a stored XSS via business process editor. The flaw is due to an incomplete fix for CVE-2016-5398. Remote, authenticated attackers that have privileges to create business pro...Show more |
2Redhat Theforeman3Foreman SatelliteSatellite CapsuleNov 21, 2024 Aug 1, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML...Show more |
2Mozilla Redhat7Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+4 moreNov 21, 2024 Aug 1, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining the client DH key to s...Show more |
3Debian RedhatUclouvain7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Aug 1, 2018 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose som...Show more |
A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instea...Show more |
The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for othe...Show more |
Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansi...Show more |
1Redhat 1Jboss Enterprise Application Platform Nov 21, 2024 Jul 31, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On syst...Show more |
1Redhat 4Ceph Enterprise Linux DesktopEnterprise Linux Server+1 moreNov 21, 2024 Jul 31, 2018 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated attacker to launch a denial of service attack by sending null or specially crafted POST...Show more |
3Debian OpenstackRedhat3Debian Linux KeystoneOpenstackNov 21, 2024 Jul 31, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated...Show more |
2Openstack Redhat2Openstack Tripleo Heat TemplatesNov 21, 2024 Jul 30, 2018 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credent...Show more |
3Canonical CryptographyRedhat3Openstack Python CryptographyUbuntu LinuxNov 21, 2024 Jul 30, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_...Show more |
4Canonical DebianLinux+1 more7Debian Linux Enterprise LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Jul 30, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_dirty_metadata(), a denial of service, and a system crash by mounting and operating on a crafted ext4...Show more |
4Canonical DebianLinux+1 more9Debian Linux Enterprise LinuxEnterprise Linux Desktop+6 moreNov 21, 2024 Jul 30, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug exception(#DB) being raised...Show more |
A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before version 5.8.0. A user able to specify a failed action could exploit this flaw to perform XSS attacks aga...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise MrgLinux KernelNov 21, 2024 Jul 30, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the data pointer going ov...Show more |
5Cabextract Cabextract ProjectCanonical+2 more8Ansible Tower CabextractDebian Linux+5 moreNov 21, 2024 Jul 28, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression. |