Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleNov 21, 2024 Jul 25, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a spec...Show more |
3Fedoraproject MoodleRedhat3Enterprise Linux FedoraMoodleNov 21, 2024 Jul 25, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafte...Show more |
3Fedoraproject LinuxfoundationRedhat3Ceph Ceph StorageFedoraNov 21, 2024 Jul 25, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Ma...Show more |
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the...Show more |
2Pki Core Project Redhat3Certificate System Enterprise LinuxPki CoreNov 21, 2024 Jul 14, 2022 N/A· v4 5.7 MEDIUM· v3 N/A· v2 A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to...Show more |
2Libguestfs Redhat2Enterprise Linux LibguestfsNov 21, 2024 Jul 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was found in libguestfs. This issue occurs while calculating the greatest possible number of matching keys in the get_keys() function. This flaw leads to a denial of service, either by mistake or maliciou...Show more |
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the clie...Show more |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Jul 6, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x. |
2Gnu Redhat12Codeready Linux Builder Developer ToolsEnterprise Linux+9 moreNov 21, 2024 Jul 6, 2022 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap la...Show more |
3Gnu NetappRedhat13Codeready Linux Builder Developer ToolsEnterprise Linux+10 moreNov 21, 2024 Jul 6, 2022 N/A· v4 4.5 MEDIUM· v3 6.9 MEDIUM· v2 A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low a...Show more |
4Fedoraproject GnuNetapp+1 more14Codeready Linux Builder Developer ToolsEnterprise Linux+11 moreNov 21, 2024 Jul 6, 2022 N/A· v4 4.5 MEDIUM· v3 4.4 MEDIUM· v2 A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure b...Show more |
Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could use these flaws to compromise the application with specially crafted inpu...Show more |
The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is user controlled. If a bogus applications is registered with bad deviceToke...Show more |
1Redhat 1Openshift Origin Node Util Nov 21, 2024 Jun 30, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission. |
In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity. |
3Debian LinuxRedhat4Debian Linux Enterprise LinuxLinux Kernel+1 moreNov 21, 2024 Jun 30, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allows an attacker to trigger a buffer overflow via nft_set_desc_concat_parse() , causing a denial of service and possibly t...Show more |
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Jun 30, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A NULL pointer dereference flaw was found in the Linux kernel’s KVM module, which can lead to a denial of service in the x86_emulate_insn in arch/x86/kvm/emulate.c. This flaw occurs while executing an illegal instruction...Show more |
2Packagekit Project Redhat2Enterprise Linux PackagekitNov 21, 2024 Jun 28, 2022 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to measure the time the methods take to execute and know whether a file ow...Show more |
A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where the AMQ Operator is deployed has access to clusterwide edit rights by che...Show more |
A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdo...Show more |