Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Jboss Enterprise Application Platform Jboss Enterprise Application Platform Expansion PackJun 17, 2026 Feb 6, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP ser...Show more |
3Couchbase Cryptography.ioRedhat5Ansible Automation Platform Couchbase ServerCryptography+2 moreJun 17, 2026 Feb 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive...Show more |
2M2crypto Project Redhat3Enterprise Linux M2cryptoUpdate InfrastructureSep 16, 2026 Feb 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data. |
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver...Show more |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Feb 4, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that us...Show more |
2Opensc Project Redhat11Enterprise Linux Enterprise Linux EusEnterprise Linux For Arm 64+8 moreJun 17, 2026 Jan 31, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data. |
5Debian FedoraprojectLinux+2 more18500f Firmware A250 FirmwareBootstrap Os+15 moreAug 7, 2026 Jan 31, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within t...Show more |
2Opencryptoki Project Redhat2Enterprise Linux OpencryptokiJun 17, 2026 Jan 31, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signin...Show more |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Jan 30, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and t...Show more |
2Fedoraproject Redhat3Enterprise Linux FedoraShimJun 17, 2026 Jan 29, 2024 N/A· v4 5.1 MEDIUM· v3 N/A· v2 A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase. |
2Fedoraproject Redhat3Enterprise Linux FedoraShimJun 17, 2026 Jan 29, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's boot phase. |
2Fedoraproject Redhat3Enterprise Linux FedoraShimJun 17, 2026 Jan 29, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shi...Show more |
2Fedoraproject Redhat3Enterprise Linux FedoraShimJun 17, 2026 Jan 29, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the l...Show more |
A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from the PE binary being used by Shim. This value is further used for m...Show more |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Jan 28, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A null pointer dereference flaw was found in the hugetlbfs_fill_super function in the Linux kernel hugetlbfs (HugeTLB pages) functionality. This issue may allow a local user to crash the system or potentially escalate th...Show more |
1Redhat 7Keycloak Migration Toolkit For ApplicationsOpenshift Container Platform+4 moreJun 17, 2026 Jan 26, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for...Show more |
2Libtiff Redhat2Enterprise Linux LibtiffJun 17, 2026 Jan 25, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a d...Show more |
2Libtiff Redhat2Enterprise Linux LibtiffAug 3, 2026 Jan 25, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input...Show more |
A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, lea...Show more |
2Linux Redhat2Enterprise Linux Linux KernelAug 10, 2026 Jan 22, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an information leak problem while freeing the old quota file names before a pot...Show more |