Redhat
redhat
5,653 CVEs • 533 products
Products (533)
Click to collapseToggle
Products (533)
Click to collapse
CVEs (5,653)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Jberet Redhat2Jberet Jboss Enterprise Application PlatformOct 24, 2025 Apr 25, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection. |
A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication proce...Show more |
2Fedoraproject Redhat23Codeready Linux Builder Codeready Linux Builder EusCodeready Linux Builder For Arm64+20 moreNov 3, 2025 Apr 18, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately. |
1Redhat 10Build Of Keycloak Jboss Middleware Text Only AdvisoriesKeycloak+7 moreJun 30, 2025 Apr 17, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive...Show more |
4Debian FedoraprojectNet Snmp+1 more15Debian Linux Enterprise LinuxEnterprise Linux Eus+12 moreJan 17, 2025 Apr 16, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a...Show more |
4Debian FedoraprojectNet Snmp+1 more15Debian Linux Enterprise LinuxEnterprise Linux Eus+12 moreJan 17, 2025 Apr 16, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable...Show more |
4Debian FedoraprojectNet Snmp+1 more15Debian Linux Enterprise LinuxEnterprise Linux Eus+12 moreJan 17, 2025 Apr 16, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory...Show more |
4Debian FedoraprojectNet Snmp+1 more15Debian Linux Enterprise LinuxEnterprise Linux Eus+12 moreJan 17, 2025 Apr 16, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed...Show more |
4Debian FedoraprojectNet Snmp+1 more15Debian Linux Enterprise LinuxEnterprise Linux Eus+12 moreJan 17, 2025 Apr 16, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds m...Show more |
A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This flaw allows a malici...Show more |
2Mholt Redhat3Advanced Cluster Security ArchiverOpenshift Container PlatformApr 25, 2025 Apr 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow th...Show more |
2Debian Redhat3Debian Linux Enterprise LinuxLibvirtApr 9, 2025 Mar 18, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virCo...Show more |
3Fedoraproject Libdwarf ProjectRedhat3Enterprise Linux FedoraLibdwarfApr 9, 2025 Mar 18, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, potentially causing unpredictable and various results. |
2Es Redhat5Enterprise Linux Enterprise Linux For Arm 64Enterprise Linux For Ibm Z Systems+2 moreNov 3, 2025 Mar 18, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the...Show more |
An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any con...Show more |
1Redhat 5Openshift Container Platform Openshift Container Platform For Arm64Openshift Container Platform For Ibm Z+2 moreMar 26, 2025 Mar 7, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a...Show more |
A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in. |
A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection policy discovers the Token Introspection endp...Show more |
2Redhat Sgi2Enterprise Linux Performance Co PilotFeb 25, 2026 Feb 28, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 4, 2025 Feb 22, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication...Show more |