Redhat
redhat
5,682 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,682)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Jboss Bpm Suite Jboss Data Virtualization & ServicesNov 21, 2024 Jul 27, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 It was discovered that the Dashbuilder login page as used in Red Hat JBoss BPM Suite before 6.4.2 and Red Hat JBoss Data Virtualization & Services before 6.4.3 could be opened in an IFRAME, which made it possible to inte...Show more |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Jul 27, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead of just POST requests. This could allow an attacker to bypass the protect_from_forgery XSRF protect...Show more |
It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in a infinite loop. An attacker could use this flaw to c...Show more |
3Debian PidginRedhat7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Jul 27, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this flaw to crash Pidgin or execute arbitrary code in the context of the pidgi...Show more |
2Redhat X.org7Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Jul 27, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to...Show more |
2Redhat Rpm Ostree3Enterprise Linux Rpm OstreeRpm Ostree ClientNov 21, 2024 Jul 27, 2018 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as exp...Show more |
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this fl...Show more |
1Redhat 1Enterprise Virtualization Nov 21, 2024 Jul 27, 2018 N/A· v4 6.3 MEDIUM· v3 2.1 LOW· v2 When updating a password in the rhvm database the ovirt-aaa-jdbc-tool tools before 1.1.3 fail to correctly check for the current password if it is expired. This would allow access to an attacker with access to change the...Show more |
2Freeipa Redhat7Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Jul 27, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use...Show more |
2Redhat Theforeman3Katello SatelliteSatellite CapsuleNov 21, 2024 Jul 27, 2018 N/A· v4 5.5 MEDIUM· v3 3.6 LOW· v2 A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the con...Show more |
4Canonical DebianQemu+1 more4Debian Linux QemuUbuntu Linux+1 moreNov 21, 2024 Jul 27, 2018 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste CPU time on reading up...Show more |
2Ovirt Redhat2Ovirt VirtualizationNov 21, 2024 Jul 27, 2018 N/A· v4 6.6 MEDIUM· v3 3.5 LOW· v2 ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents...Show more |
2Fedoraproject Redhat6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+3 moreNov 21, 2024 Jul 27, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password ha...Show more |
1Redhat 2Ansible Tower CloudformsNov 21, 2024 Jul 27, 2018 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not have the 'delete before update' flag set, an attacker with commit access...Show more |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Jul 27, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other t...Show more |
2Debian Redhat3Debian Linux Jboss Enterprise Application PlatformUndertowNov 21, 2024 Jul 27, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS. |
1Redhat 1Jboss Enterprise Application Platform Nov 21, 2024 Jul 27, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal. |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Jul 27, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and JavaScript input. An attacker could use this flaw to execute a stored XSS...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Jul 27, 2018 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the t...Show more |
1Redhat 2Jboss Enterprise Application Platform UndertowNov 21, 2024 Jul 27, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling. |