Redhat
redhat
5,682 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,682)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical DebianMariadb+3 more15Active Iq Unified Manager Debian LinuxEnterprise Linux Desktop+12 moreNov 21, 2024 Apr 19, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerab...Show more |
6Canonical DebianMariadb+3 more15Active Iq Unified Manager Debian LinuxEnterprise Linux Desktop+12 moreNov 21, 2024 Apr 19, 2018 N/A· v4 4.4 MEDIUM· v3 3.5 LOW· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Locking). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerab...Show more |
6Canonical DebianMariadb+3 more15Active Iq Unified Manager Debian LinuxEnterprise Linux Desktop+12 moreNov 21, 2024 Apr 19, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerab...Show more |
6Canonical DebianMariadb+3 more15Active Iq Unified Manager Debian LinuxEnterprise Linux Desktop+12 moreNov 21, 2024 Apr 19, 2018 N/A· v4 7.7 HIGH· v3 3.7 LOW· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vuln...Show more |
4Artifex CanonicalDebian+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Apr 18, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause...Show more |
3Debian OpensuseRedhat6Debian Linux Enterprise Linux ServerGluster Storage+3 moreNov 21, 2024 Apr 18, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss FuseUndertow+1 moreNov 21, 2024 Apr 18, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP r...Show more |
4Canonical DebianPerl+1 more5Debian Linux Enterprise Linux ServerEnterprise Linux Workstation+2 moreJun 17, 2026 Apr 17, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure. |
4Canonical DebianPerl+1 more5Debian Linux Enterprise Linux ServerEnterprise Linux Workstation+2 moreJun 17, 2026 Apr 17, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written. |
2Redhat Theforeman2Foreman SatelliteNov 21, 2024 Apr 16, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those systems. |
openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation to fail with 'VolumeInUse' error. Since the delete operation is retried every 30...Show more |
2Bouncycastle Redhat3Bc Java SatelliteSatellite CapsuleJun 17, 2026 Apr 16, 2018 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS keystore. Bouncy Castle release 1.47 changes the BKS format to a format which uses a 160 bi...Show more |
4Canonical DebianLibreoffice+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Apr 16, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 and 6.x before 6.0.2.1 does not validate a customizations index, which allows remote attackers to cause a denial of ser...Show more |
4Canonical DebianLibreoffice+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Apr 16, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-fre...Show more |
4Canonical CorosyncDebian+1 more4Corosync Debian LinuxEnterprise Linux Server+1 moreNov 21, 2024 Apr 12, 2018 N/A· v4 7.5 HIGH· v3 7.5 HIGH· v2 corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c. |
2Clusterlabs Redhat2Enterprise Linux Pacemaker Command Line InterfaceNov 21, 2024 Apr 12, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd service did not properly sanitize the file name from the /remote/put_fil...Show more |
3Clusterlabs DebianRedhat3Debian Linux Enterprise Linux Server EusPacemaker Command Line InterfaceNov 21, 2024 Apr 12, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensi...Show more |
rhnreg_ks in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7 does not properly validate hostnames in X.509 certificates from SSL servers, which a...Show more |
3Canonical RedhatZsh5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreNov 21, 2024 Apr 11, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploit this to execute arbitrary code in the context of another user. |
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable link...Show more |