Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject Packagekit ProjectRedhat3Enterprise Linux FedoraPackagekitJun 17, 2026 Jan 3, 2024 N/A· v4 3.3 LOW· v3 N/A· v2 A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously f...Show more |
3Fedoraproject LibsshRedhat3Enterprise Linux FedoraLibsshJun 17, 2026 Jan 3, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the...Show more |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Jan 2, 2024 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to cause a denial of service...Show more |
2Linux Redhat35Codeready Linux Builder Codeready Linux Builder For Arm64Codeready Linux Builder For Arm64 Eus+32 moreJun 17, 2026 Jan 2, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-collected when the pipapo set is removed, the element can be deactivated twice. This can cause a use-afte...Show more |
3Fedoraproject QemuRedhat3Enterprise Linux FedoraQemuJun 17, 2026 Jan 2, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest features VIRTIO_NET_F_HASH_REPORT, VIRTIO_F_VERSION_1 and VIRTIO_N...Show more |
2Redhat Shadow Maint9Codeready Linux Builder Codeready Linux Builder For Arm64Codeready Linux Builder For Ibm Z Systems+6 moreJun 17, 2026 Dec 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry...Show more |
1Redhat 1Jboss Enterprise Application Platform Jun 17, 2026 Dec 27, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious reque...Show more |
3Fedoraproject OpenbsdRedhat3Enterprise Linux FedoraOpensshJun 17, 2026 Dec 24, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single...Show more |
3Freebsd RedhatSendmail3Enterprise Linux FreebsdSendmailJun 17, 2026 Dec 24, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF p...Show more |
3Fedoraproject PostfixRedhat3Enterprise Linux FedoraPostfixJun 17, 2026 Dec 24, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remot...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelAug 6, 2026 Dec 21, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execute the GSMIOC_SETCONF ioctl on the same tty file descriptor with the gsm line discipline enabled, an...Show more |
1Redhat 5Openshift Container Platform Openshift Container Platform For Ibm ZOpenshift Container Platform For Linuxone+2 moreJun 17, 2026 Dec 21, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin in...Show more |
3Fedoraproject LibsshRedhat3Enterprise Linux FedoraLibsshJun 17, 2026 Dec 19, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause lo...Show more |
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security pat...Show more |
429bis ApacheApple+39 more68Advanced Cluster Security AsyncsshCeph Storage+65 moreJun 17, 2026 Dec 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negoti...Show more |
2Infinispan Redhat3Data Grid InfinispanJboss Data GridJun 17, 2026 Dec 18, 2023 N/A· v4 2.7 LOW· v3 N/A· v2 A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text a...Show more |
2Infinispan Redhat3Data Grid InfinispanJboss Data GridJun 17, 2026 Dec 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and...Show more |
2Debian Redhat4Ansible Automation Platform Ansible DeveloperAnsible Inside+1 moreJun 17, 2026 Dec 18, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file...Show more |
A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that would allow an authenticated attacker in the adjacent cluster to view deployments in all namespaces in t...Show more |
An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic overflow to create personal access tokens that are valid indefinitely, r...Show more |