Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Bouncycastle CanonicalNetapp+1 more57 Mode Transition Tool Legion Of The Bouncy Castle Java Crytography ApiSatellite+2 moreMay 5, 2025 Jun 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and stil...Show more |
2Redhat Sinatrarb2Cloudforms SinatraNov 21, 2024 May 31, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception. |
5Canonical DebianGit Scm+2 more9Debian Linux Enterprise LinuxEnterprise Linux Desktop+6 moreNov 21, 2024 May 30, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbit...Show more |
5Canonical DebianHaxx+2 more9Communications Webrtc Session Controller CurlDebian Linux+6 moreApr 15, 2026 May 24, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer...Show more |
4Canonical DebianLinux+1 more10Debian Linux Enterprise LinuxEnterprise Linux Desktop+7 moreNov 21, 2024 May 24, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code executi...Show more |
5Canonical DebianProcps Ng Project+2 more10Debian Linux Enterprise LinuxEnterprise Linux Desktop+7 moreNov 21, 2024 May 23, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124. |
6Canonical DebianOpensuse+3 more9Debian Linux Enterprise LinuxEnterprise Linux Desktop+6 moreNov 21, 2024 May 23, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs b...Show more |
1Redhat 1Jboss Enterprise Application Platform Nov 21, 2024 May 22, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege escalation. |
12Arm CanonicalDebian+9 more282Atom C Atom EAtom X5 E3930+279 moreMay 29, 2026 May 22, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an atta...Show more |
1Redhat 3Jboss Enterprise Application Platform UndertowVirtualization HostNov 21, 2024 May 21, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, du...Show more |
2Adobe Redhat4Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+1 moreNov 21, 2024 May 19, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Adobe Flash Player versions 29.0.0.140 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. |
5Canonical GnuNetapp+2 more10Communications Session Border Controller Data Ontap EdgeElement Software Management+7 moreNov 21, 2024 May 18, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupp...Show more |
4Gnu NetappOracle+1 more9Communications Session Border Controller Data Ontap EdgeElement Software Management+6 moreNov 21, 2024 May 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leadin...Show more |
CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ which is accessible without authentication to Tectonic and allows an att...Show more |
2Fedoraproject Redhat7Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 May 17, 2018 N/A· v4 7.5 HIGH· v3 7.9 HIGH· v2 DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an at...Show more |
7Canonical DebianIjg+4 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Server+10 moreNov 21, 2024 May 16, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file. |
4Canonical DebianLinux+1 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 May 15, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stac...Show more |
2Infinispan Redhat2Infinispan Jboss Data GridNov 21, 2024 May 15, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Infinispan permits improper deserialization of trusted data via XML and JSON transcoders under certain server configurations. A user with authenticated access to the server could send a malicious object to a cache config...Show more |
4Canonical DebianExiv2+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 21, 2024 May 12, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Exiv2 0.26. readMetadata in jp2image.cpp allows remote attackers to cause a denial of service (SIGABRT) by triggering an incorrect Safe::add call. |
5Netapp OraclePivotal Software+2 more43Agile Plm Agile Product Lifecycle ManagementApplication Testing Suite+40 moreAug 25, 2026 May 11, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to met...Show more |