Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apache CanonicalDebian+1 more7Debian Linux Enterprise LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Aug 26, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code fo...Show more |
5Canonical DebianFedoraproject+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Aug 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact. |
A NULL pointer deference flaw was found in the way libvirt from 2.5.0 to 3.0.0 handled empty drives. A remote authenticated attacker could use this flaw to crash libvirtd daemon resulting in denial of service. |
4Canonical DebianRedhat+1 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Aug 22, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba vers...Show more |
2Openstack Redhat2Openstack Tripleo CommonNov 21, 2024 Aug 22, 2018 N/A· v4 8.2 HIGH· v3 7.2 HIGH· v2 A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. The sudoers file as installed with OSP's openstack-tripleo-common package is much too permissive. It contains several l...Show more |
1Redhat 2Ansible Tower Cloudforms Management EngineNov 21, 2024 Aug 22, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF Injection. It was found that X-Forwarded-For header allows internal servers to deploy other systems (using callback). |
It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a Postgre...Show more |
3Canonical RedhatSamba5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreNov 21, 2024 Aug 22, 2018 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and...Show more |
Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users into visiting a malici...Show more |
5Canonical DebianFedoraproject+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Aug 22, 2018 N/A· v4 5.6 MEDIUM· v3 1.9 LOW· v2 A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Luc...Show more |
5Canonical DebianFedoraproject+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Aug 22, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via stat...Show more |
5Canonical DebianFedoraproject+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Aug 22, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via stati...Show more |
4Canonical DebianLinux+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreJul 7, 2026 Aug 21, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_ra...Show more |
2Nodejs Redhat2Node.js Openshift Container PlatformNov 21, 2024 Aug 21, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`), `Buffer#write()` can be abused to wri...Show more |
3Ibm OracleRedhat6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+3 moreNov 21, 2024 Aug 20, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files....Show more |
2Ibm Redhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreNov 21, 2024 Aug 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data. IBM X-Force ID: 141681. |
2Libvirt Redhat10Enterprise Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreNov 21, 2024 Aug 20, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing. |
5Debian Dom4j ProjectNetapp+2 more14Debian Linux Dom4jFlexcube Investor Servicing+11 moreNov 21, 2024 Aug 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection....Show more |
7Canonical DebianNetapp+4 more22Aff Baseboard Management Controller Cloud BackupClustered Data Ontap+19 moreDec 17, 2025 Aug 17, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c,...Show more |
4Canonical DebianRedhat+1 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreNov 21, 2024 Aug 17, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send speci...Show more |