Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Libarchive Redhat4Enterprise Linux Hardened ImagesLibarchive+1 moreSep 1, 2026 Mar 30, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image,...Show more |
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext within the initial HTTP CONNECT request. A network-positioned attacker...Show more |
1Redhat 10Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+7 moreJul 22, 2026 Mar 27, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, whic...Show more |
1Redhat 10Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+7 moreJun 29, 2026 Mar 27, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in he...Show more |
1Redhat 9Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootData Grid+6 moreJun 29, 2026 Mar 27, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions o...Show more |
2Firewalld Redhat2Enterprise Linux FirewalldSep 16, 2026 Mar 27, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows th...Show more |
A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed in other namespaces via direct network requests, because no NetworkPol...Show more |
A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read_icon` functions. This issue arises because a size calculation for imag...Show more |
A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Photoshop Document) file. This occurs because the buffer allocated for a Pa...Show more |
2P11 Kit Project Redhat3Enterprise Linux Hardened ImagesP11 KitSep 6, 2026 Mar 26, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could...Show more |
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This mis...Show more |
2Libssh Redhat2Enterprise Linux LibsshSep 1, 2026 Mar 26, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient...Show more |
2Libssh Redhat4Enterprise Linux Hardened ImagesLibssh+1 moreSep 1, 2026 Mar 26, 2026 N/A· v4 8.2 HIGH· v3 N/A· v2 A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service...Show more |
A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. Thi...Show more |
2Libssh Redhat4Enterprise Linux Hardened ImagesLibssh+1 moreSep 1, 2026 Mar 26, 2026 N/A· v4 6.3 MEDIUM· v3 N/A· v2 A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and m...Show more |
A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is stil...Show more |
A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to enforce the `uma_protection` role check. This allows any authenticated user with a token issued for...Show more |
1Redhat 4Build Of Keycloak Jboss Enterprise Application PlatformJboss Enterprise Application Platform Expansion Pack+1 moreJun 17, 2026 Mar 26, 2026 N/A· v4 7.2 HIGH· v3 N/A· v2 A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privil...Show more |
2Freedesktop Redhat3Enterprise Linux Openshift Container PlatformPolkitSep 10, 2026 Mar 26, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to...Show more |
1Redhat 4Build Of Keycloak Jboss Enterprise Application PlatformJboss Enterprise Application Platform Expansion Pack+1 moreJun 26, 2026 Mar 26, 2026 N/A· v4 3.1 LOW· v3 N/A· v2 A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client...Show more |