Redhat
redhat
5,682 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,682)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian OracleRedhat+1 more28Application Testing Suite Big Data DiscoveryCommunications Converged Application Server+25 moreNov 21, 2024 Apr 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the...Show more |
4Canonical DebianGnu+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreApr 14, 2025 Apr 6, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via...Show more |
2Redhat Theforeman2Foreman SatelliteNov 21, 2024 Apr 5, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database. |
2Redhat Theforeman2Foreman SatelliteNov 21, 2024 Apr 4, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource. |
4Canonical DebianRedhat+1 more4Debian Linux Enterprise LinuxRuby+1 moreJun 17, 2026 Apr 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-re...Show more |
4Canonical DebianRedhat+1 more4Debian Linux Enterprise LinuxRuby+1 moreJun 17, 2026 Apr 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with a crafted header to WEBrick server or a crafted body to WEBrick server...Show more |
4Canonical DebianRedhat+1 more4Debian Linux Enterprise LinuxRuby+1 moreJun 17, 2026 Apr 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arb...Show more |
DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address). |
2Fedoraproject Redhat2Etcd FedoraNov 21, 2024 Apr 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theore...Show more |
5Apple CanonicalDebian+2 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreNov 21, 2024 Apr 3, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is...Show more |
4Apple ChromiumDebian+1 more7Chromium Debian LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Apr 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause...Show more |
3Canonical LinuxRedhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreNov 21, 2024 Apr 2, 2018 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.15.15 does not always initialize the crc32c checksum driver, which allows attackers to cause a denial of service (ext4_xattr_inode_hash NULL p...Show more |
6Canonical DebianLinux+3 more12Communications Eagle Application Processor Debian LinuxEnterprise Linux Desktop+9 moreJun 17, 2026 Mar 30, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user. |
2Debian Redhat2Debian Linux LibvirtNov 21, 2024 Mar 28, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent. |
4Canonical DebianRedhat+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 Mar 28, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the con...Show more |
5Apache CanonicalDebian+2 more13Cloud Backup Clustered Data OntapDebian Linux+10 moreNov 21, 2024 Mar 26, 2018 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a co...Show more |
5Apache CanonicalDebian+2 more8Clustered Data Ontap Debian LinuxEnterprise Linux+5 moreNov 21, 2024 Mar 26, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very...Show more |
5Apache CanonicalDebian+2 more8Clustered Data Ontap Debian LinuxEnterprise Linux+5 moreNov 21, 2024 Mar 26, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. Thi...Show more |
5Apache CanonicalDebian+2 more8Clustered Data Ontap Debian LinuxEnterprise Linux+5 moreNov 21, 2024 Mar 26, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in envi...Show more |
5Apache CanonicalDebian+2 more8Clustered Data Ontap Debian LinuxEnterprise Linux+5 moreNov 21, 2024 Mar 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying...Show more |