Redhat
redhat
5,653 CVEs • 536 products
Products (536)
Click to collapseToggle
Products (536)
Click to collapse
CVEs (5,653)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Redhat13Enterprise Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+10 moreMar 27, 2025 Feb 1, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters |
3Fedoraproject GnuRedhat3Binutils Enterprise LinuxFedoraMar 28, 2025 Jan 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-...Show more |
A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to set the seccomp profile for pods they control to "unconfined."...Show more |
2Openstack Redhat4Barbican OpenstackOpenstack For Ibm Power+1 moreApr 3, 2025 Jan 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API. |
The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the etcd components, to e...Show more |
A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a crash dump, and dump privileged information. |
A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker can shadow other users with the same email and lockout or impersonate t...Show more |
A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information. |
1Redhat 1Advanced Cluster Management For Kubernetes Apr 9, 2025 Jan 13, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker c...Show more |
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass va...Show more |
1Redhat 2Jboss Enterprise Application Platform Wildfly ElytronApr 9, 2025 Jan 13, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equals in several places, which is unsafe and vulnerable to timing attacks...Show more |
2Libsdl Redhat2Enterprise Linux Simple Directmedia LayerNov 25, 2025 Jan 12, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to cause a denial of service attack. The vulnerability affects SDL2 v2.0.4...Show more |
A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems. |
1Redhat 2Openshift Container Platform Openshift OsinNov 21, 2024 Dec 28, 2022 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing disc...Show more |
A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead...Show more |
When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lea...Show more |
A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attacker's server by modifying the Referer header in an HTTP request of specific r...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreAug 29, 2025 Dec 14, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. T...Show more |
3Fedoraproject GnuRedhat8Enterprise Linux Eus Enterprise Linux For Power Little Endian EusEnterprise Linux Server Aus+5 moreMay 27, 2026 Dec 14, 2022 N/A· v4 8.6 HIGH· v3 N/A· v2 A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this furt...Show more |
Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks. |