Redhat
redhat
5,768 CVEs • 542 products
Products (542)
Click to collapseToggle
Products (542)
Click to collapse
CVEs (5,768)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to...Show more |
3Fedoraproject LatchsetRedhat6Enterprise Linux Enterprise Linux For Arm 64Enterprise Linux For Ibm Z Systems+3 moreJun 17, 2026 Feb 12, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result...Show more |
2Fedoraproject Redhat13389 Directory Server Directory ServerEnterprise Linux+10 moreJun 17, 2026 Feb 12, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr. |
4Debian FedoraprojectLinux+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Feb 11, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursively calls into the code block. The OVS module does not validate the stac...Show more |
3Fedoraproject RedhatX.org8Enterprise Linux Enterprise Linux AusEnterprise Linux Eus+5 moreJun 17, 2026 Feb 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash,...Show more |
3Debian LinuxRedhat17Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+14 moreJun 17, 2026 Feb 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer derefe...Show more |
2Linux Redhat16Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+13 moreJun 17, 2026 Feb 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer derefe...Show more |
3Debian LinuxRedhat17Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+14 moreJun 17, 2026 Feb 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer derefe...Show more |
3Fedoraproject GnuRedhat3Enterprise Linux FedoraGrub2Jun 17, 2026 Feb 6, 2024 N/A· v4 3.3 LOW· v3 N/A· v2 A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If th...Show more |
2Fedoraproject Redhat6Ansible Ansible Automation PlatformAnsible Developer+3 moreJun 17, 2026 Feb 6, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. D...Show more |
1Redhat 2Jboss Enterprise Application Platform Jboss Enterprise Application Platform Expansion PackJun 17, 2026 Feb 6, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP ser...Show more |
3Couchbase Cryptography.ioRedhat5Ansible Automation Platform Couchbase ServerCryptography+2 moreJun 17, 2026 Feb 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive...Show more |
2M2crypto Project Redhat3Enterprise Linux M2cryptoUpdate InfrastructureJun 17, 2026 Feb 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. |
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver...Show more |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Feb 4, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that us...Show more |
2Opensc Project Redhat11Enterprise Linux Enterprise Linux EusEnterprise Linux For Arm 64+8 moreJun 17, 2026 Jan 31, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data. |
5Debian FedoraprojectLinux+2 more12500f Firmware A250 FirmwareC250 Firmware+9 moreJun 17, 2026 Jan 31, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the...Show more |
2Opencryptoki Project Redhat2Enterprise Linux OpencryptokiJun 17, 2026 Jan 31, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signin...Show more |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Jan 30, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and t...Show more |
2Fedoraproject Redhat3Enterprise Linux FedoraShimJun 17, 2026 Jan 29, 2024 N/A· v4 5.1 MEDIUM· v3 N/A· v2 A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase. |