Redhat
redhat
5,768 CVEs • 542 products
Products (542)
Click to collapseToggle
Products (542)
Click to collapse
CVEs (5,768)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectNet Snmp+1 more15Debian Linux Enterprise LinuxEnterprise Linux Eus+12 moreJun 17, 2026 Apr 16, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a malformed OID in a SET request to `SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable` can cause an out-of-bounds memory...Show more |
4Debian FedoraprojectNet Snmp+1 more15Debian Linux Enterprise LinuxEnterprise Linux Eus+12 moreJun 17, 2026 Apr 16, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed...Show more |
4Debian FedoraprojectNet Snmp+1 more15Debian Linux Enterprise LinuxEnterprise Linux Eus+12 moreJun 17, 2026 Apr 16, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds m...Show more |
A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This flaw allows a malici...Show more |
2Mholt Redhat3Advanced Cluster Security ArchiverOpenshift Container PlatformJun 17, 2026 Apr 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow th...Show more |
2Debian Redhat3Debian Linux Enterprise LinuxLibvirtJun 17, 2026 Mar 18, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the same time collecting the list of interfaces via virCo...Show more |
3Fedoraproject Libdwarf ProjectRedhat3Enterprise Linux FedoraLibdwarfJun 17, 2026 Mar 18, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, potentially causing unpredictable and various results. |
2Es Redhat5Enterprise Linux Enterprise Linux For Arm 64Enterprise Linux For Ibm Z Systems+2 moreJun 17, 2026 Mar 18, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the...Show more |
An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any con...Show more |
1Redhat 5Openshift Container Platform Openshift Container Platform For Arm64Openshift Container Platform For Ibm Z+2 moreJun 17, 2026 Mar 7, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a...Show more |
A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in. |
A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection policy discovers the Token Introspection endp...Show more |
2Redhat Sgi2Enterprise Linux Performance Co PilotJun 17, 2026 Feb 28, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Feb 22, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication...Show more |
2Netapp Redhat9Active Iq Unified Manager FuseIntegration Camel For Spring Boot+6 moreJun 17, 2026 Feb 19, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then...Show more |
2Fedoraproject Redhat19Codeready Linux Builder Codeready Linux Builder EusCodeready Linux Builder Eus For Power Little Endian+16 moreJun 17, 2026 Feb 15, 2024 N/A· v4 7.3 HIGH· v3 N/A· v2 A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953,...Show more |
6Debian FedoraprojectIsc+3 more8Active Iq Unified Manager BindBootstrap Os+5 moreJun 17, 2026 Feb 14, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in...Show more |
8Fedoraproject IscMicrosoft+5 more13Bind DnsmasqEnterprise Linux+10 moreJun 17, 2026 Feb 14, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue...Show more |
2Devfile Redhat3Openshift Openshift Developer Tools And ServicesRegistry SupportJun 17, 2026 Feb 14, 2024 N/A· v4 9.3 CRITICAL· v3 N/A· v2 A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. Thi...Show more |
3Fedoraproject Opensc ProjectRedhat3Enterprise Linux FedoraOpenscJun 17, 2026 Feb 12, 2024 N/A· v4 3.4 LOW· v3 N/A· v2 The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker must have...Show more |