Redhat
redhat
5,653 CVEs • 536 products
Products (536)
Click to collapseToggle
Products (536)
Click to collapse
CVEs (5,653)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject HaproxyRedhat9Ceph Storage Extra Packages For Enterprise LinuxFedora+6 moreFeb 25, 2025 Mar 23, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenSh...Show more |
2Openstack Redhat3Openstack Openstack For Ibm PowerTripleo AnsibleNov 21, 2024 Mar 23, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the rele...Show more |
2Openstack Redhat3Openstack Openstack For Ibm PowerTripleo AnsibleNov 21, 2024 Mar 23, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the rele...Show more |
3Fedoraproject ImagemagickRedhat4Enterprise Linux Extra Packages For Enterprise LinuxFedora+1 moreNov 21, 2024 Mar 23, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segme...Show more |
3C Ares Project FedoraprojectRedhat4C Ares Enterprise LinuxFedora+1 moreDec 2, 2025 Mar 6, 2023 N/A· v4 8.6 HIGH· v3 N/A· v2 A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or...Show more |
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images. |
A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service. |
2Linux Redhat2Enterprise Linux Linux KernelMar 7, 2025 Mar 6, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resource overload, causing a fail in the intel_gvt_dma_map_guest_page function. This issue could allow a l...Show more |
2Linux Redhat2Enterprise Linux Linux KernelMar 6, 2025 Mar 6, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl function is called by the user, where a fail pass occurs in the gru_check_chiplet_assignment function. Thi...Show more |
2Openstack Redhat2Neutron Openstack PlatformMar 7, 2025 Mar 6, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unco...Show more |
3Redhat WebkitgtkWpewebkit23Codeready Linux Builder Codeready Linux Builder EusCodeready Linux Builder For Arm64 Eus+20 moreNov 18, 2025 Mar 6, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issu...Show more |
3Debian LinuxfoundationRedhat4Debian Linux Enterprise LinuxOpenshift Container Platform+1 moreDec 6, 2024 Mar 3, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount con...Show more |
3Fedoraproject PostgresqlRedhat6Enterprise Linux FedoraIntegration Camel K+3 moreMar 7, 2025 Mar 3, 2023 N/A· v4 3.7 LOW· v3 N/A· v2 In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report...Show more |
2Linux Redhat2Enterprise Linux Linux KernelMar 18, 2025 Feb 28, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In nf_tables_updtable, if nf_tables_table_enable returns an error, nft_trans_destroy is called to free the transaction object. nft_trans_destroy() calls list_del(), but the transaction was never placed on a list -- the l...Show more |
2Fedoraproject Redhat2Directory Server FedoraNov 21, 2024 Feb 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker wit...Show more |
2Quarkus Redhat2Build Of Quarkus QuarkusNov 21, 2024 Feb 23, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF...Show more |
1Redhat 10Build Of Quarkus Integration Camel For Spring BootIntegration Camel K+7 moreMar 12, 2025 Feb 23, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add...Show more |
2Netapp Redhat3Active Iq Unified Manager Oncommand Workflow AutomationResteasyMar 18, 2025 Feb 17, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user. |
5Debian FedoraprojectGnu+2 more7Active Iq Unified Manager Converged Systems Advisor AgentDebian Linux+4 moreMar 19, 2025 Feb 15, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbache...Show more |
3Fedoraproject Pesign ProjectRedhat3Enterprise Linux FedoraPesignMar 26, 2025 Feb 2, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privi...Show more |