Redhat
redhat
5,768 CVEs • 542 products
Products (542)
Click to collapseToggle
Products (542)
Click to collapse
CVEs (5,768)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Gnu Redhat3Enterprise Linux GnutlsOpenshift Container PlatformJun 30, 2026 Jul 10, 2025 N/A· v4 8.2 HIGH· v3 N/A· v2 A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is in...Show more |
2Libssh Redhat3Enterprise Linux LibsshOpenshift Container PlatformJun 30, 2026 Jul 4, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is fr...Show more |
2Libssh Redhat3Enterprise Linux LibsshOpenshift Container PlatformJun 17, 2026 Jul 4, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL use...Show more |
1Redhat 1Advanced Cluster Management For Kubernetes Jun 17, 2026 Jul 2, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed clus...Show more |
A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* endpoints are expected to enforce API key validation. However, the POST /invocations endpoint failed...Show more |
6Canonical DebianOpensuse+3 more8Debian Linux Enterprise LinuxLeap+5 moreJun 17, 2026 Jun 30, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. |
2Infinispan Redhat4Data Grid InfinispanJboss Enterprise Application Platform+1 moreJun 17, 2026 Jun 26, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a co...Show more |
2Libssh Redhat3Enterprise Linux LibsshOpenshift Container PlatformJul 21, 2026 Jun 24, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyo...Show more |
A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive...Show more |
2Redhat Xmlsoft4Enterprise Linux Jboss Core ServicesLibxml2+1 moreJul 23, 2026 Jun 16, 2025 N/A· v4 2.5 LOW· v3 N/A· v2 A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to...Show more |
2Redhat Xmlsoft20Enterprise Linux Enterprise Linux EusEnterprise Linux For Arm 64+17 moreJun 30, 2026 Jun 12, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJun 30, 2026 Jun 9, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can le...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJun 30, 2026 Jun 9, 2025 N/A· v4 5.0 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seeming...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJun 30, 2026 Jun 9, 2025 N/A· v4 5.6 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content by...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJun 30, 2026 Jun 9, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This mean...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformJul 26, 2026 Jun 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condit...Show more |
2Nbdkit Project Redhat3Enterprise Linux Enterprise Linux Advanced VirtualizationNbdkitJun 30, 2026 Jun 9, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even large...Show more |
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access...Show more |
5Debian LinuxOracle+2 more6Debian Linux Enterprise LinuxLinux+3 moreJun 30, 2026 May 30, 2025 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attack...Show more |
2Redhat Stackrox2Advanced Cluster Security StackroxJun 17, 2026 May 27, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. The only known potential exploit is if the script is included in the nam...Show more |