Redhat
redhat
5,682 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,682)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Ansible Tower CloudformsNov 21, 2024 May 2, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passw...Show more |
3Canonical LinuxRedhat9Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+6 moreNov 21, 2024 May 2, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls. |
1Redhat 1Automatic Bug Reporting Tool Nov 21, 2024 May 1, 2018 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Automatic Bug Reporting Tool (ABRT) before 2.1.6 allows local users to obtain sensitive information about arbitrary files via vectors related to sha1sums. |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 May 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token.rb secret. |
1Redhat 1Manageiq Enterprise Virtualization Manager Nov 21, 2024 May 1, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vect...Show more |
5Apache CanonicalDebian+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 May 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=fi...Show more |
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation. |
2Fedoraproject Redhat2389 Directory Server Enterprise LinuxNov 21, 2024 Apr 30, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or possib...Show more |
2Gnu Redhat4Binutils Enterprise Linux DesktopEnterprise Linux Server+1 moreNov 21, 2024 Apr 29, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The ignore_section_sym function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, does not validate the output_section pointer in the case of a symtab entry with a "S...Show more |
2Gnu Redhat4Binutils Enterprise Linux DesktopEnterprise Linux Server+1 moreNov 21, 2024 Apr 29, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, processes a negative Data Directory size with an unbounde...Show more |
3Google OracleRedhat17Banking Payments Communications Ip Service ActivatorCustomer Management And Segmentation Foundation+14 moreNov 21, 2024 Apr 26, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data,...Show more |
2Ovirt Redhat2Enterprise Virtualization OvirtNov 21, 2024 Apr 26, 2018 N/A· v4 7.2 HIGH· v3 4.0 MEDIUM· v2 ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator co...Show more |
2Openstack Redhat2Openstack Puppet SwiftNov 21, 2024 Apr 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for...Show more |
3Debian RedhatXiph.org6Debian Linux Enterprise LinuxEnterprise Linux Eus+3 moreNov 21, 2024 Apr 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read. |
3Debian RedhatXiph.org6Debian Linux Enterprise LinuxEnterprise Linux Eus+3 moreNov 21, 2024 Apr 26, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have u...Show more |
2Gnu Redhat4Binutils Enterprise Linux DesktopEnterprise Linux Server+1 moreNov 21, 2024 Apr 25, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (NULL pointer dereference and application cr...Show more |
2Gnu Redhat4Binutils Enterprise Linux DesktopEnterprise Linux Server+1 moreNov 21, 2024 Apr 25, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted binary file, as demonstrated by readelf. |
3Debian GnomeRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Apr 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code execution. An attacker can send a special HT...Show more |
3Canonical DpdkRedhat9Ceph Storage Data Plane Development KitEnterprise Linux+6 moreNov 21, 2024 Apr 24, 2018 N/A· v4 6.1 MEDIUM· v3 2.9 LOW· v2 The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead t...Show more |
2Ansible Redhat3Ansible AnsibleOpenstackNov 21, 2024 Apr 24, 2018 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ab...Show more |