Redhat
redhat
5,768 CVEs • 542 products
Products (542)
Click to collapseToggle
Products (542)
Click to collapse
CVEs (5,768)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS becomes controllable. Setting excessively large values may cause an...Show more |
13Almalinux AmazonApple+10 more53500f Firmware 8300 Firmware8700 Firmware+50 moreJun 17, 2026 Jul 1, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able t...Show more |
2Freedesktop Redhat2Enterprise Linux PopplerJun 17, 2026 Jun 21, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to crash, leading to a de...Show more |
A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth token to authenticate despite not having access to the organization from which the application was crea...Show more |
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the runn...Show more |
2Kubernetes Redhat2Cri O Openshift Container PlatformJun 17, 2026 Jun 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host...Show more |
1Redhat 5Enterprise Linux Enterprise Linux AusEnterprise Linux Eus+2 moreJun 17, 2026 Jun 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attacks. However, the tick...Show more |
2Clusterlabs Redhat8Booth Enterprise LinuxEnterprise Linux Eus+5 moreJun 17, 2026 Jun 6, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server. |
1Redhat 2Openshift Container Platform Openshift Distributed TracingJun 17, 2026 Jun 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check during JSON web token (JWT) authentication. |
2Katello Project Redhat2Katello SatelliteJun 17, 2026 Jun 5, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Description" field of a user. This code can be executed when opening certain pages, for example, Host Co...Show more |
A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the process list and allows an attacker to take advantage and obtain the passwor...Show more |
A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of...Show more |
A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deploye...Show more |
A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the...Show more |
2Jberet Redhat2Jberet Jboss Enterprise Application PlatformJun 17, 2026 Apr 25, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection. |
A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication proce...Show more |
2Fedoraproject Redhat23Codeready Linux Builder Codeready Linux Builder EusCodeready Linux Builder For Arm64+20 moreJun 17, 2026 Apr 18, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately. |
1Redhat 10Build Of Keycloak Jboss Middleware Text Only AdvisoriesKeycloak+7 moreJun 17, 2026 Apr 17, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive...Show more |
4Debian FedoraprojectNet Snmp+1 more15Debian Linux Enterprise LinuxEnterprise Linux Eus+12 moreJun 17, 2026 Apr 16, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a...Show more |
4Debian FedoraprojectNet Snmp+1 more15Debian Linux Enterprise LinuxEnterprise Linux Eus+12 moreJun 17, 2026 Apr 16, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable...Show more |