Redhat
redhat
5,653 CVEs • 536 products
Products (536)
Click to collapseToggle
Products (536)
Click to collapse
CVEs (5,653)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Qemu Redhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Openstack Platform+6 moreNov 21, 2024 Sep 29, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables....Show more |
3Fedoraproject QemuRedhat10Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Openstack Platform+7 moreNov 21, 2024 Sep 29, 2022 N/A· v4 6.2 MEDIUM· v3 N/A· v2 Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snaps...Show more |
2Qemu Redhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Openstack Platform+6 moreNov 21, 2024 Sep 29, 2022 N/A· v4 8.6 HIGH· v3 N/A· v2 QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input validations which could...Show more |
1Redhat 1Ansible Automation Platform Nov 21, 2024 Sep 13, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection |
2Buildah Project Redhat3Buildah Enterprise LinuxOpenshift Container PlatformNov 21, 2024 Sep 13, 2022 N/A· v4 7.1 HIGH· v3 N/A· v2 An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected containe...Show more |
2Podman Project Redhat3Enterprise Linux Openshift Container PlatformPodmanJun 5, 2025 Sep 13, 2022 N/A· v4 7.1 HIGH· v3 N/A· v2 An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container...Show more |
1Redhat 8Amq Amq OnlineIntegration Camel K+5 moreNov 21, 2024 Sep 13, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain. |
3Linux NetappRedhat7Enterprise Linux H300s FirmwareH410c Firmware+4 moreNov 21, 2024 Sep 9, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes. |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelNov 21, 2024 Sep 9, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unau...Show more |
3Fedoraproject PythonRedhat5Enterprise Linux FedoraPython+2 moreNov 3, 2025 Sep 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (fl...Show more |
A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file. This flaw allows an attacker to pass a specially crafted file to Fribidi,...Show more |
A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap-rtl.c file. This flaw allows an attacker to pass a specially crafted f...Show more |
A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the Fribidi application, which leads to a possible memory leak or a denial of service. |
2Openstack Redhat2Barbican Openstack PlatformNov 21, 2024 Sep 6, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This...Show more |
2Netapp Redhat9Active Iq Unified Manager Cloud Secure AgentIntegration Camel K+6 moreNov 21, 2024 Sep 1, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations. |
2Podman Project Redhat3Enterprise Linux Server Enterprise Linux WorkstationPodmanNov 21, 2024 Sep 1, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:505...Show more |
2Podman Project Redhat3Enterprise Linux Server Enterprise Linux WorkstationPodmanNov 21, 2024 Sep 1, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixed via RHSA-2020:2117...Show more |
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Sep 1, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does...Show more |
2Openstack Redhat4Keystone Openstack PlatformQuay+1 moreNov 21, 2024 Sep 1, 2022 N/A· v4 6.6 MEDIUM· v3 N/A· v2 A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote admini...Show more |
A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps, and accessible to any authenticated Open...Show more |