Redhat
redhat
5,768 CVEs • 542 products
Products (542)
Click to collapseToggle
Products (542)
Click to collapse
CVEs (5,768)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack. |
1Redhat 3Keycloak Openshift Container PlatformSingle Sign OnJun 17, 2026 Oct 4, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can a...Show more |
7Canonical DebianFedoraproject+4 more39Bootstrap Os Codeready Linux BuilderCodeready Linux Builder Eus+36 moreJun 17, 2026 Oct 3, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES env...Show more |
2Linux Redhat10Codeready Linux Builder Codeready Linux Builder For Arm64Codeready Linux Builder For Power Little Endian+7 moreJun 17, 2026 Oct 3, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A flaw was found in pfn_swap_entry_to_page in memory management subsystem in the Linux Kernel. In this flaw, an attacker with a local user privilege may cause a denial of service problem due to a BUG statement referencin...Show more |
A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Sep 30, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding. |
8Apple DebianFedoraproject+5 more11Chrome Debian LinuxEdge+8 moreJun 17, 2026 Sep 28, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security sever...Show more |
A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-bit unsigned value). This issue could lead to an application crash or other unintended behavior for...Show more |
4Debian FedoraprojectLinux+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Sep 28, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue m...Show more |
1Redhat 3Jboss A Mq Jboss MiddlewareOpenshift Container PlatformJun 17, 2026 Sep 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details...Show more |
3Fedoraproject MariadbRedhat12Enterprise Linux Enterprise Linux EusEnterprise Linux For Arm 64+9 moreJun 17, 2026 Sep 27, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service. |
1Redhat 3Jboss A Mq Jboss MiddlewareOpenshift Container PlatformJun 17, 2026 Sep 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access inf...Show more |
1Redhat 7Jboss Enterprise Application Platform Jboss Enterprise Application Platform Text Only AdvisoriesOpenshift Container Platform+4 moreJun 17, 2026 Sep 27, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If th...Show more |
A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an a...Show more |
A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This could allow a separate realm to be accessible to an attacker, permitting ac...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelJun 17, 2026 Sep 25, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitraril...Show more |
3Fedoraproject KubernetesRedhat7Cri O Extra Packages For Enterprise LinuxFedora+4 moreJun 17, 2026 Sep 25, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable. |
2Codehaus Plexus Redhat2Integration Camel K Plexus UtilsJun 17, 2026 Sep 25, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpre...Show more |
2Codehaus Plexus Redhat2Integration Camel K Plexus UtilsJun 17, 2026 Sep 25, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manipulating files with "dot-dot-slash (../)"...Show more |
A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a malicious link to insert an arbitrary URI into a Keycloak error page. Th...Show more |