Redhat
redhat
5,682 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,682)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 3Jboss Enterprise Application Platform VirtualizationWildfly CoreNov 21, 2024 Jul 27, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vu...Show more |
2Debian Redhat3Debian Linux Jboss Enterprise Application PlatformUndertowNov 21, 2024 Jul 27, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a diffe...Show more |
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py. |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Jul 27, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. This would allow...Show more |
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive informatio...Show more |
1Redhat 1Jboss Enterprise Application Platform Nov 21, 2024 Jul 27, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able t...Show more |
4Debian HpRedhat+1 more8Cifs Server Debian LinuxEnterprise Linux+5 moreNov 21, 2024 Jul 27, 2018 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DF...Show more |
3Canonical LinuxRedhat9Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+6 moreNov 21, 2024 Jul 26, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly validate the sigevent->sigev_notify field, which leads to out-of-bounds access in the show_timer fu...Show more |
4Canonical DebianLinux+1 more8Debian Linux Enterprise Linux DesktopEnterprise Linux For Real Time+5 moreNov 21, 2024 Jul 26, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound access in ext4_get_group_info function, a denial of service, and a system crash by mounting and operating on a crafted ext4 f...Show more |
4Canonical DebianLinux+1 more7Debian Linux Enterprise LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Jul 26, 2018 N/A· v4 7.8 HIGH· v3 6.1 MEDIUM· v2 A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause a use-after-free in ext4_xattr_set_entry function and a denial of service or unspecified other impact may occur by renaming a file in a craft...Show more |
4Canonical DebianLinux+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Jul 26, 2018 N/A· v4 7.8 HIGH· v3 6.1 MEDIUM· v2 A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem im...Show more |
3Debian RedhatSamba6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Jul 26, 2018 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack...Show more |
2Linux Redhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+2 moreNov 21, 2024 Jul 26, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the previous host value, but instead sets it to 64KB. With a corrupted GDT limit a host's userspace code has...Show more |
1Redhat 2Jboss Enterprise Application Platform KeycloakNov 21, 2024 Jul 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine...Show more |
Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality. |
2Apache Redhat5Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Jul 26, 2018 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator could unintentionally al...Show more |
1Redhat 1Jboss Enterprise Application Platform Nov 21, 2024 Jul 26, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information...Show more |
An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is not present in a certificate an assertion error is triggered causing a...Show more |
3Debian RedhatSamba6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Jul 26, 2018 N/A· v4 7.1 HIGH· v3 4.8 MEDIUM· v2 An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a...Show more |
2Mit Redhat5Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Jul 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote attacker able to communicate with the KDC could potentially use this flaw...Show more |