Redhat
redhat
5,653 CVEs • 533 products
Products (533)
Click to collapseToggle
Products (533)
Click to collapse
CVEs (5,653)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Feb 4, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that us...Show more |
2Opensc Project Redhat11Enterprise Linux Enterprise Linux EusEnterprise Linux For Arm 64+8 moreNov 3, 2025 Jan 31, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data. |
5Debian FedoraprojectLinux+2 more12500f Firmware A250 FirmwareC250 Firmware+9 moreOct 27, 2025 Jan 31, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the...Show more |
2Opencryptoki Project Redhat2Enterprise Linux OpencryptokiMar 24, 2026 Jan 31, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signin...Show more |
2Linux Redhat2Enterprise Linux Linux KernelNov 25, 2024 Jan 30, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and t...Show more |
2Fedoraproject Redhat3Enterprise Linux FedoraShimNov 21, 2024 Jan 29, 2024 N/A· v4 5.1 MEDIUM· v3 N/A· v2 A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase. |
2Fedoraproject Redhat3Enterprise Linux FedoraShimNov 21, 2024 Jan 29, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's boot phase. |
2Fedoraproject Redhat3Enterprise Linux FedoraShimNov 21, 2024 Jan 29, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shi...Show more |
2Fedoraproject Redhat3Enterprise Linux FedoraShimNov 21, 2024 Jan 29, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the l...Show more |
A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from the PE binary being used by Shim. This value is further used for m...Show more |
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Jan 28, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A null pointer dereference flaw was found in the hugetlbfs_fill_super function in the Linux kernel hugetlbfs (HugeTLB pages) functionality. This issue may allow a local user to crash the system or potentially escalate th...Show more |
1Redhat 7Keycloak Migration Toolkit For ApplicationsOpenshift Container Platform+4 moreNov 21, 2024 Jan 26, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for...Show more |
2Libtiff Redhat2Enterprise Linux LibtiffMay 12, 2026 Jan 25, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a d...Show more |
2Libtiff Redhat2Enterprise Linux LibtiffFeb 27, 2026 Jan 25, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input...Show more |
A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, lea...Show more |
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Jan 22, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an information leak problem while freeing the old quota file names before a pot...Show more |
2Linux Redhat2Enterprise Linux Linux KernelNov 4, 2025 Jan 21, 2024 N/A· v4 7.0 HIGH· v3 N/A· v2 A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic() on the socket that the SKB is queued on. |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelNov 21, 2024 Jan 18, 2024 N/A· v4 6.6 MEDIUM· v3 N/A· v2 A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a loop and writes to the `dst` array. On each iteration, 8 bytes are wri...Show more |
4Fedoraproject RedhatTigervnc+1 more12Enterprise Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+9 moreAug 29, 2025 Jan 18, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that...Show more |
4Fedoraproject RedhatTigervnc+1 more12Enterprise Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+9 moreAug 29, 2025 Jan 18, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry...Show more |