Redhat
redhat
5,653 CVEs • 536 products
Products (536)
Click to collapseToggle
Products (536)
Click to collapse
CVEs (5,653)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console, abusing the defaul...Show more |
1Redhat 1Advanced Cluster Management For Kubernetes Nov 21, 2024 Sep 1, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific str...Show more |
2Openstack Redhat2Barbican Openstack PlatformNov 21, 2024 Sep 1, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and ca...Show more |
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL A...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Sep 1, 2022 N/A· v4 6.3 MEDIUM· v3 N/A· v2 In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry ca...Show more |
2Fedoraproject Redhat3Ansible Automation Platform FedoraOpenshift Container PlatformNov 21, 2024 Sep 1, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allo...Show more |
4Debian FedoraprojectLinux+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Aug 31, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unp...Show more |
4Debian DpdkFedoraproject+1 more8Data Plane Development Kit Debian LinuxEnterprise Linux+5 moreNov 21, 2024 Aug 31, 2022 N/A· v4 8.6 HIGH· v3 N/A· v2 A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK. |
5Debian FedoraprojectLibtiff+2 more5Debian Linux Enterprise LinuxFedora+2 moreNov 21, 2024 Aug 31, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting...Show more |
5Debian FedoraprojectLibtiff+2 more5Debian Linux Enterprise LinuxFedora+2 moreNov 21, 2024 Aug 31, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue a...Show more |
2Netapp Redhat7Active Iq Unified Manager Cloud Secure AgentOncommand Insight+4 moreNov 21, 2024 Aug 31, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the co...Show more |
4Debian GnuRedhat+1 more4Debian Linux GzipJboss Data Grid+1 moreJun 9, 2025 Aug 31, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arb...Show more |
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Aug 31, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops co...Show more |
2Netapp Redhat10Active Iq Unified Manager Build Of QuarkusCloud Secure Agent+7 moreNov 21, 2024 Aug 31, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelNov 21, 2024 Aug 31, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 An issue found in linux-kernel that leads to a race condition in rose_connect(). The rose driver uses rose_neigh->use to represent how many objects are using the rose_neigh. When a user wants to delete a rose_route via r...Show more |
3Linux NetappRedhat8Active Iq Unified Manager Enterprise LinuxH300s Firmware+5 moreApr 23, 2025 Aug 29, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability...Show more |
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Aug 29, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows an attacker to crash linux kernel by simulating ax25 device using 6pack driver from user space. |
4Canonical DebianLinux+1 more4Debian Linux Enterprise LinuxLinux Kernel+1 moreNov 21, 2024 Aug 29, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block() in the Linux kernel’s filesystem sub-component. This flaw allows a local attacker with a user privilege to cause a denial of service. |
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Aug 29, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information...Show more |
2Redhat Thekelleys2Dnsmasq Enterprise LinuxNov 3, 2025 Aug 29, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a crafted packet processed by dnsmasq, potentially causing a denial of service. |