Redhat
redhat
5,653 CVEs • 533 products
Products (533)
Click to collapseToggle
Products (533)
Click to collapse
CVEs (5,653)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Netapp Redhat9Active Iq Unified Manager FuseIntegration Camel For Spring Boot+6 moreJun 25, 2025 Feb 19, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then...Show more |
2Fedoraproject Redhat19Codeready Linux Builder Codeready Linux Builder EusCodeready Linux Builder Eus For Power Little Endian+16 moreJan 30, 2025 Feb 15, 2024 N/A· v4 7.3 HIGH· v3 N/A· v2 A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953,...Show more |
6Debian FedoraprojectIsc+3 more8Active Iq Unified Manager BindBootstrap Os+5 moreDec 23, 2025 Feb 14, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in...Show more |
8Fedoraproject IscMicrosoft+5 more13Bind DnsmasqEnterprise Linux+10 moreNov 4, 2025 Feb 14, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue...Show more |
2Devfile Redhat3Openshift Openshift Developer Tools And ServicesRegistry SupportMar 24, 2026 Feb 14, 2024 N/A· v4 9.3 CRITICAL· v3 N/A· v2 A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. Thi...Show more |
3Fedoraproject Opensc ProjectRedhat3Enterprise Linux FedoraOpenscNov 3, 2025 Feb 12, 2024 N/A· v4 3.4 LOW· v3 N/A· v2 The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker must have...Show more |
A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to...Show more |
3Fedoraproject LatchsetRedhat6Enterprise Linux Enterprise Linux For Arm 64Enterprise Linux For Ibm Z Systems+3 moreNov 21, 2024 Feb 12, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result...Show more |
2Fedoraproject Redhat13389 Directory Server Directory ServerEnterprise Linux+10 moreFeb 18, 2025 Feb 12, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr. |
4Debian FedoraprojectLinux+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Feb 11, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursively calls into the code block. The OVS module does not validate the stac...Show more |
3Fedoraproject RedhatX.org8Enterprise Linux Enterprise Linux AusEnterprise Linux Eus+5 moreNov 4, 2025 Feb 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash,...Show more |
3Debian LinuxRedhat17Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+14 moreNov 4, 2025 Feb 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer derefe...Show more |
2Linux Redhat16Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+13 moreNov 4, 2025 Feb 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer derefe...Show more |
3Debian LinuxRedhat17Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+14 moreNov 4, 2025 Feb 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer derefe...Show more |
3Fedoraproject GnuRedhat3Enterprise Linux FedoraGrub2Nov 21, 2024 Feb 6, 2024 N/A· v4 3.3 LOW· v3 N/A· v2 A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If th...Show more |
2Fedoraproject Redhat6Ansible Ansible Automation PlatformAnsible Developer+3 moreNov 4, 2025 Feb 6, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. D...Show more |
1Redhat 2Jboss Enterprise Application Platform Jboss Enterprise Application Platform Expansion PackNov 21, 2024 Feb 6, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP ser...Show more |
3Couchbase Cryptography.ioRedhat5Ansible Automation Platform Couchbase ServerCryptography+2 moreMar 24, 2026 Feb 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive...Show more |
2M2crypto Project Redhat3Enterprise Linux M2cryptoUpdate InfrastructureMay 12, 2026 Feb 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. |
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver...Show more |