Redhat
redhat
5,768 CVEs • 542 products
Products (542)
Click to collapseToggle
Products (542)
Click to collapse
CVEs (5,768)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy not properly unsetting...Show more |
2Opensc Project Redhat2Enterprise Linux OpenscJun 30, 2026 Sep 3, 2024 N/A· v4 3.9 LOW· v3 N/A· v2 A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially...Show more |
2Opensc Project Redhat2Enterprise Linux OpenscJun 30, 2026 Sep 3, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs....Show more |
2Opensc Project Redhat2Enterprise Linux OpenscJun 30, 2026 Sep 3, 2024 N/A· v4 3.9 LOW· v3 N/A· v2 A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking...Show more |
2Opensc Project Redhat2Enterprise Linux OpenscJun 30, 2026 Sep 3, 2024 N/A· v4 3.9 LOW· v3 N/A· v2 A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs....Show more |
2Opensc Project Redhat2Enterprise Linux OpenscJun 30, 2026 Sep 3, 2024 N/A· v4 3.9 LOW· v3 N/A· v2 A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs....Show more |
2Opensc Project Redhat2Enterprise Linux OpenscJun 30, 2026 Sep 3, 2024 N/A· v4 3.9 LOW· v3 N/A· v2 A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK.
The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.). |
1Redhat 7Build Of Keycloak KeycloakOpenshift Container Platform+4 moreJun 17, 2026 Sep 3, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed th...Show more |
A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails to properly verify the server's hostname, resulting in an insecure conn...Show more |
A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where allocating 0 bytes of memory results in a NULL pointer. This corner case w...Show more |
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS ce...Show more |
1Redhat 9Build Of Apache Camel Hawtio Build Of Apache Camel For Spring BootBuild Of Keycloak+6 moreJun 17, 2026 Aug 21, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple request...Show more |
2Frrouting Redhat2Enterprise Linux FrroutingJun 17, 2026 Aug 19, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value. |
1Redhat 2Openshift Ai Openshift Data ScienceJun 17, 2026 Aug 12, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, the UI provides the option to protect models wit...Show more |
2Libtiff Redhat5Enterprise Linux Enterprise Linux For Arm 64Enterprise Linux For Power Little Endian Eus+2 moreJun 17, 2026 Aug 12, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting...Show more |
2Openstack Redhat2Heat Openstack PlatformJun 17, 2026 Aug 2, 2024 N/A· v4 5.0 MEDIUM· v3 N/A· v2 An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix a...Show more |
3Fedoraproject Podman ProjectRedhat4Enterprise Linux FedoraOpenshift Container Platform+1 moreJun 17, 2026 Aug 2, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resourc...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Jul 24, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI that is remote HTTP/HTTPS or local. Access to this endpoint is gated by t...Show more |
A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift oauth-proxy with a static cookie-secret. In certain circumstances, thi...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 17, 2026 Jul 9, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service. |