Redhat
redhat
5,653 CVEs • 533 products
Products (533)
Click to collapseToggle
Products (533)
Click to collapse
CVEs (5,653)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Ansible Automation Platform SatelliteDec 6, 2024 Nov 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the d...Show more |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleNov 21, 2024 Nov 9, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 The course upload preview contained an XSS risk for users uploading unsafe data. |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleNov 21, 2024 Nov 9, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleNov 21, 2024 Nov 9, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk. |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelMar 24, 2026 Nov 9, 2023 N/A· v4 6.4 MEDIUM· v3 N/A· v2 A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the qobj returned by the qxl_gem_object_create_with_handle(), but the handle is the only one holding a re...Show more |
1Redhat 2Jboss Enterprise Application Platform Wildfly CoreNov 21, 2024 Nov 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access...Show more |
A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque layers to trick a user into clicking on a button or link on another page when they intend to click on the top-level page. Dur...Show more |
3Fedoraproject Opensc ProjectRedhat3Enterprise Linux FedoraOpenscNov 21, 2024 Nov 6, 2023 N/A· v4 3.8 LOW· v3 N/A· v2 An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a spe...Show more |
2Opensc Project Redhat2Enterprise Linux OpenscNov 3, 2025 Nov 6, 2023 N/A· v4 6.4 MEDIUM· v3 N/A· v2 Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an at...Show more |
2Opensc Project Redhat2Enterprise Linux OpenscNov 3, 2025 Nov 6, 2023 N/A· v4 6.6 MEDIUM· v3 N/A· v2 A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed...Show more |
A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the browser cache. |
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Nov 6, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in KVM. An improper check in svm_set_x2apic_msr_interception() may allow direct access to host x2apic msrs when the guest resets its apic, potentially leading to a denial of service condition. |
2Redhat Samba8Enterprise Linux Enterprise Linux EusEnterprise Linux For Ibm Z Systems+5 moreNov 21, 2024 Nov 6, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnerability stems from an RPC function that can be blocked indefinitely. The...Show more |
A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). This could be used, for example, by L2 gues...Show more |
3Fedoraproject RedhatSamba5Enterprise Linux Enterprise Linux EusFedora+2 moreNov 21, 2024 Nov 3, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote...Show more |
2Linux Redhat6Enterprise Linux Enterprise Linux EusEnterprise Linux For Power Little Endian+3 moreNov 21, 2024 Nov 3, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between rmap walk and mremap, allowing a local user to crash the syst...Show more |
2Redhat Squid Cache2Enterprise Linux SquidNov 3, 2025 Nov 3, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall...Show more |
3Fedoraproject RedhatSamba5Enterprise Linux Enterprise Linux EusFedora+2 moreNov 21, 2024 Nov 3, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes"....Show more |
2Redhat Squid Cache5Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+2 moreNov 21, 2024 Nov 3, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input. |
2Redhat Squid Cache10Enterprise Linux Enterprise Linux EusEnterprise Linux For Arm 64+7 moreNov 21, 2024 Nov 3, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication...Show more |