Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Redhat Xmlsoft20Enterprise Linux Enterprise Linux EusEnterprise Linux For Arm 64+17 moreSep 18, 2026 Jun 12, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformSep 1, 2026 Jun 9, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can le...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformSep 1, 2026 Jun 9, 2025 N/A· v4 5.0 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seeming...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformSep 1, 2026 Jun 9, 2025 N/A· v4 5.6 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content by...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformSep 1, 2026 Jun 9, 2025 N/A· v4 6.6 MEDIUM· v3 N/A· v2 A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This mean...Show more |
2Libarchive Redhat3Enterprise Linux LibarchiveOpenshift Container PlatformSep 9, 2026 Jun 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condit...Show more |
2Nbdkit Project Redhat3Enterprise Linux Enterprise Linux Advanced VirtualizationNbdkitJun 30, 2026 Jun 9, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even large...Show more |
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access...Show more |
5Debian LinuxOracle+2 more6Debian Linux Enterprise LinuxLinux+3 moreSep 1, 2026 May 30, 2025 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attack...Show more |
2Redhat Stackrox2Advanced Cluster Security StackroxJun 17, 2026 May 27, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. The only known potential exploit is if the script is included in the nam...Show more |
2Freerdp Redhat2Enterprise Linux FreerdpJun 30, 2026 May 16, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial o...Show more |
A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server. |
A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git re...Show more |
A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository. |
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication. |
3Apache DebianRedhat3Debian Linux Enterprise LinuxHttp ServerJun 29, 2026 Apr 29, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is...Show more |
2Fig2dev Project Redhat2Enterprise Linux Fig2devJun 30, 2026 Apr 23, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobject function. |
2Fig2dev Project Redhat2Enterprise Linux Fig2devJun 30, 2026 Apr 23, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function. |
2Fig2dev Project Redhat2Enterprise Linux Fig2devJun 30, 2026 Apr 23, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function. |
2Fig2dev Project Redhat2Enterprise Linux Fig2devJun 30, 2026 Apr 23, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function. |