Redhat
redhat
5,653 CVEs • 536 products
Products (536)
Click to collapseToggle
Products (536)
Click to collapse
CVEs (5,653)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Quarkus Redhat12Build Of Optaplanner Build Of QuarkusDecision Manager+9 moreNov 21, 2024 Sep 20, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an at...Show more |
3Fedoraproject GnuRedhat22Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little EndianCodeready Linux Builder Eus For Power Little Endian Eus+19 moreMay 12, 2026 Sep 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module imp...Show more |
4Fedoraproject GnuNetapp+1 more27Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little EndianCodeready Linux Builder Eus For Power Little Endian Eus+24 moreMay 12, 2026 Sep 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can...Show more |
A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making requests to the Jupyter API. This flaw can lead to file content exposur...Show more |
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the O...Show more |
A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem. |
2Kubernetes Redhat2Cri O Openshift Container PlatformNov 21, 2024 Sep 15, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing t...Show more |
A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, it was detected that the config-editor page is vulnerable to CSRF. The c...Show more |
2Netapp Redhat16Build Of Quarkus Decision ManagerFuse+13 moreNov 21, 2024 Sep 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelNov 21, 2024 Sep 13, 2023 N/A· v4 5.6 MEDIUM· v3 N/A· v2 A flaw was found in KVM AMD Secure Encrypted Virtualization (SEV) in the Linux kernel. A KVM guest using SEV-ES or SEV-SNP with multiple vCPUs can trigger a double fetch race condition vulnerability and invoke the `VMGEX...Show more |
A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window...Show more |
3Fedoraproject QemuRedhat3Enterprise Linux FedoraQemuNov 21, 2024 Sep 13, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker controlled zlib buffer in the `inflate_buffer` func...Show more |
This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 via RHSA-2022:7967 included a version of qemu-kvm that was actually mis...Show more |
4Fedoraproject GnuNetapp+1 more16Active Iq Unified Manager Enterprise LinuxEnterprise Linux Eus+13 moreSep 26, 2025 Sep 12, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is...Show more |
A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "password" and "password-confirm" field from the form will occur as regula...Show more |
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the sy...Show more |
1Redhat 4Decision Manager DroolsJboss Middleware Text Only Advisories+1 moreNov 21, 2024 Sep 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadge...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelNov 21, 2024 Aug 28, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a...Show more |
3Fedoraproject KeylimeRedhat9Enterprise Linux Enterprise Linux EusEnterprise Linux For Ibm Z Systems+6 moreNov 21, 2024 Aug 25, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allow an attacker to impersonate an agent and hide the true status of a mon...Show more |
2Artifex Redhat9Codeready Linux Builder Codeready Linux Builder For Arm64Codeready Linux Builder For Ibm Z Systems+6 moreNov 21, 2024 Aug 23, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat E...Show more |