Redhat
redhat
5,768 CVEs • 542 products
Products (542)
Click to collapseToggle
Products (542)
Click to collapse
CVEs (5,768)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a use...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read tha...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the s...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 6.3 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence interna...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable unde...Show more |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJun 30, 2026 Jun 9, 2026 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users. |
1Redhat 3389 Directory Server Directory ServerEnterprise LinuxJul 23, 2026 Jun 8, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additio...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 15, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFrontLeft can trigger an...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 13, 2026 Jun 5, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 13, 2026 Jun 5, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding the request buffer, l...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 15, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client conne...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 15, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters vi...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 15, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 15, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 15, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attacker would connect to t...Show more |
2Redhat X.org3Enterprise Linux X ServerXwaylandJul 15, 2026 Jun 5, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias re...Show more |
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and cou...Show more |
1Redhat 1Openshift Container Platform Jul 22, 2026 Jun 1, 2026 N/A· v4 5.0 MEDIUM· v3 N/A· v2 A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create po...Show more |
1Redhat 2Openshift Container Platform Openshift RouterJul 24, 2026 May 29, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated a...Show more |
1Redhat 2Openshift Container Platform Openshift RouterJul 21, 2026 May 29, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud...Show more |