Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectLibarchive+1 more13Codeready Linux Builder Debian LinuxEnterprise Linux+10 moreNov 21, 2024 Aug 23, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger t...Show more |
3Debian RedhatSamba7Debian Linux Enterprise LinuxEnterprise Linux Aus+4 moreNov 21, 2024 Aug 23, 2022 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share. |
A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulner...Show more |
5Debian FedoraprojectLinux+2 more9Debian Linux Enterprise LinuxFedora+6 moreNov 21, 2024 Aug 22, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data. This f...Show more |
3Fedoraproject LinuxRedhat15Codeready Linux Builder Enterprise LinuxEnterprise Linux For Ibm Z Systems+12 moreNov 21, 2024 Aug 22, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highes...Show more |
A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is to data confidentiality...Show more |
1Redhat 2Openshift Service Mesh Servicemesh OperatorNov 21, 2024 Aug 22, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allowing access to all ports on these resources from any pod. The highest t...Show more |
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threa...Show more |
A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripts into some text boxes leading to a XSS attack. The highest threat from this vu...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Aug 22, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP...Show more |
1Redhat 1Ansible Automation Platform Nov 21, 2024 Aug 18, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remov...Show more |
3Fedoraproject PostgresqlRedhat3Enterprise Linux FedoraPostgresqlNov 21, 2024 Aug 18, 2022 N/A· v4 8.0 HIGH· v3 N/A· v2 A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension...Show more |
3Fedoraproject QemuRedhat5Enterprise Linux Extra Packages For Enterprise LinuxFedora+2 moreNov 21, 2024 Aug 17, 2022 N/A· v4 3.2 LOW· v3 N/A· v2 An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the h...Show more |
A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and information disclosure. |
XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application's processing of XML data. This attack occurs when XML input containing a reference to an external entity is p...Show more |
1Redhat 1Process Automation Manager Sep 24, 2025 Aug 10, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts. |
An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelNov 21, 2024 Aug 5, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes, this flaw allows unprivi...Show more |
1Redhat 3Integration Camel K Jboss FuseUndertowNov 21, 2024 Aug 5, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit implementation closes a connection without sending any response to the client/prox...Show more |
4Debian FedoraprojectGnu+1 more4Debian Linux Enterprise LinuxFedora+1 moreDec 2, 2025 Aug 1, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function. |