Redhat
redhat
5,682 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,682)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianLinux+1 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 May 15, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stac...Show more |
2Infinispan Redhat2Infinispan Jboss Data GridNov 21, 2024 May 15, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache config...Show more |
4Canonical DebianExiv2+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 May 12, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call. |
5Netapp OraclePivotal Software+2 more42Agile Plm Application Testing SuiteBig Data Discovery+39 moreNov 21, 2024 May 11, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to met...Show more |
3Oracle RedhatVmware30Agile Product Lifecycle Management Application Testing SuiteBig Data Discovery+27 moreNov 21, 2024 May 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through t...Show more |
1Redhat 2Jboss Enterprise Application Platform KeycloakNov 21, 2024 May 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacke...Show more |
4Canonical DebianLinux+1 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 May 10, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This can allow local privile...Show more |
4Canonical DebianFreedesktop+1 more7Ansible Tower Debian LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 May 10, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops. |
4Canonical DebianLinux+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 May 10, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Linux kernel before version 4.16-rc7 is vulnerable to a null pointer dereference in dccp_write_xmit() function in net/dccp/output.c in that allows a local user to cause a denial of service by a number of certain crafted...Show more |
3Debian FedoraprojectRedhat5389 Directory Server Debian LinuxEnterprise Linux Desktop+2 moreNov 21, 2024 May 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could potential...Show more |
An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without authentication. NOTE: the Security Realms...Show more |
2Haproxy Redhat2Enterprise Linux HaproxyNov 21, 2024 May 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in HAProxy before 1.8.8. The incoming H2 frame length was checked against the max_frame_size setting instead of being checked against the bufsize. The max_frame_size only applies to outgoing traff...Show more |
8Apple CanonicalCitrix+5 more11Debian Linux Diskstation ManagerEnterprise Linux Server+8 moreJun 17, 2026 May 8, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected beh...Show more |
2Jenkins Redhat2Jenkins OpenshiftNov 21, 2024 May 8, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing...Show more |
4Canonical DebianFreedesktop+1 more7Ansible Tower Debian LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 May 6, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages suc...Show more |
2Gnome Redhat5Ansible Tower Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 May 6, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_rea...Show more |
4Canonical DebianGnu+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 May 6, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line. |
Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys. |
3Gnome OpensuseRedhat6Ansible Tower Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 May 4, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack. |
1Redhat 2Ansible Tower CloudformsNov 21, 2024 May 2, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server. |