Redhat
redhat
5,682 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,682)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 3Decision Manager Jboss Bpm SuiteJbpmNov 21, 2024 Jul 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote attacker could use this flaw to read files accessible to the user runnin...Show more |
A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user able to change an organization's name could exploit this flaw to perform XSS attacks against other S...Show more |
2Hawt Redhat2Hawtio Jboss FuseNov 21, 2024 Jul 26, 2018 N/A· v4 9.0 CRITICAL· v3 6.0 MEDIUM· v2 It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which me...Show more |
3Apache OracleRedhat5Database Jboss Middleware Text Only AdvisoriesKafka+2 moreNov 21, 2024 Jul 26, 2018 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data r...Show more |
2Openstack Redhat2Neutron OpenstackNov 21, 2024 Jul 26, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups wer...Show more |
2Qemu Redhat3Openstack QemuVirtualizationNov 21, 2024 Jul 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection negotiation, where the I/O coroutine was undefined. This could crash the qemu-nbd server if a clien...Show more |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Jul 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within...Show more |
1Redhat 2Ansible Engine VirtualizationNov 21, 2024 Jul 26, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it...Show more |
2Dogtagpki Redhat4Dogtagpki Enterprise Linux DesktopEnterprise Linux Server+1 moreNov 21, 2024 Jul 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially use this flaw to bypass the regular auth...Show more |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Jul 26, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing when invoking arbitrary methods via filtering on VMs that MiqExpression will execute that is trigge...Show more |
A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed by default (by director) listening on 0.0.0.0 (all interfaces) with no...Show more |
4Canonical DebianFreedesktop+1 more8Ansible Tower Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jul 25, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of...Show more |
3Codehaus Plexus DebianRedhat5Debian Linux Enterprise LinuxEnterprise Linux Desktop+2 moreNov 21, 2024 Jul 25, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is...Show more |
4Canonical DebianLinux+1 more4Debian Linux Enterprise LinuxLinux Kernel+1 moreNov 21, 2024 Jul 25, 2018 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a crafted ext4 image in ext4_update_inline_data(). An attacker could use this to cause a system crash and...Show more |
3Debian Fuse ProjectRedhat5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Jul 24, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option rega...Show more |
3Quagga RedhatSuse4Opensuse Package ManagerQuagga+1 moreNov 21, 2024 Jul 24, 2018 N/A· v4 8.2 HIGH· v3 4.3 MEDIUM· v2 Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same...Show more |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Jul 24, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an unprivileged local shell could use this flaw to execute commands as a...Show more |
1Redhat 2Keycloak Single Sign OnNov 21, 2024 Jul 23, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infinite loop. A malicious...Show more |
2Adobe Redhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreNov 21, 2024 Jul 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Adobe Flash Player 30.0.0.113 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. |
2Adobe Redhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreNov 21, 2024 Jul 20, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. |