Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Redhat Thekelleys2Dnsmasq Enterprise LinuxNov 3, 2025 Aug 29, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a crafted packet processed by dnsmasq, potentially causing a denial of service. |
2Convert2rhel Project Redhat2Convert2rhel Enterprise LinuxNov 21, 2024 Aug 29, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the password via the pro...Show more |
2Convert2rhel Project Redhat2Convert2rhel Enterprise LinuxNov 21, 2024 Aug 29, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription-manager via the command line, which could allow unauthorized users loc...Show more |
3Debian OpenstackRedhat4Debian Linux Openshift Container PlatformOpenstack Platform+1 moreNov 21, 2024 Aug 29, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext. |
3Dpdk OpenvswitchRedhat3Data Plane Development Kit Openshift Container PlatformOpenvswitchNov 21, 2024 Aug 29, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by...Show more |
A flaw was found in the copying tool `nbdcopy` of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather t...Show more |
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Aug 29, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exhaustion due to memcg not limiting the number of Portable Operating System Interface (POSIX) file loc...Show more |
A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs wit...Show more |
3Eurosoft Uk MicrosoftRedhat10Enterprise Linux Uefi BootloaderWindows 10+7 moreNov 21, 2024 Aug 26, 2022 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an atta...Show more |
3Horizondatasys MicrosoftRedhat10Enterprise Linux Uefi BootloaderWindows 10+7 moreNov 21, 2024 Aug 26, 2022 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot sta...Show more |
3Kidan MicrosoftRedhat10Cryptopro Securedisk For Bitlocker Enterprise LinuxWindows 10+7 moreNov 21, 2024 Aug 26, 2022 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot s...Show more |
A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack...Show more |
2Ovirt Redhat4Vdsm VirtualizationVirtualization For Ibm Power Little Endian+1 moreNov 21, 2024 Aug 26, 2022 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values being stored in clear text. |
2Redhat Virglrenderer Project2Enterprise Linux VirglrendererNov 21, 2024 Aug 26, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed memory resource. A malicious guest could use this flaw to mmap from the gu...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelNov 21, 2024 Aug 26, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU tha...Show more |
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Aug 26, 2022 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet File System (CIFS) due to an incorrect return from the memdup_user function. This fl...Show more |
1Redhat 4Integration Camel K Integration Camel QuarkusSingle Sign On+1 moreNov 21, 2024 Aug 26, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a message to another expected end. This flaw allows an attacker to send flawed requests to a server, possi...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelNov 21, 2024 Aug 26, 2022 N/A· v4 7.0 HIGH· v3 N/A· v2 A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to ef...Show more |
2Netapp Redhat6Cloud Secure Agent Jboss Enterprise Application PlatformOncommand Insight+3 moreNov 21, 2024 Aug 26, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks. |
ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, th...Show more |