Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Redhat3389 Directory Server Enterprise LinuxFedoraNov 3, 2025 Mar 23, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication. |
2Openstack Redhat2Openstack Tripleo Heat TemplatesNov 21, 2024 Mar 23, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the www_authenticate_uri parameter (which is vi...Show more |
5Canonical DebianFedoraproject+2 more6Debian Linux Enterprise LinuxEnterprise Linux Advanced Virtualization Eus+3 moreNov 21, 2024 Mar 23, 2022 N/A· v4 7.5 HIGH· v3 6.9 MEDIUM· v2 A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has b...Show more |
2Redhat Theforeman2Foreman Ansible SatelliteNov 21, 2024 Mar 23, 2022 N/A· v4 8.0 HIGH· v3 6.5 MEDIUM· v2 An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is...Show more |
5Debian FedoraprojectLinux+2 more13Debian Linux Enterprise LinuxFedora+10 moreNov 21, 2024 Mar 23, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause...Show more |
2Grafana Redhat3Ceph Storage GrafanaStorageNov 21, 2024 Mar 21, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can righ...Show more |
6Debian FedoraprojectLinux+3 more30Build Of Quarkus Codeready Linux BuilderCommunications Cloud Native Core Binding Support Function+27 moreNov 21, 2024 Mar 18, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege...Show more |
3Fedoraproject GolangRedhat4Advanced Cluster Management For Kubernetes Extra Packages For Enterprise LinuxFedora+1 moreNov 21, 2024 Mar 18, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey. |
2Port389 Redhat2389 Ds Base Enterprise LinuxNov 3, 2025 Mar 16, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message...Show more |
4Debian FedoraprojectQemu+1 more8Codeready Linux Builder Debian LinuxEnterprise Linux+5 moreNov 21, 2024 Mar 16, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. Th...Show more |
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker t...Show more |
1Redhat 5Descision Manager Jboss Enterprise Application PlatformJboss Enterprise Application Platform Expansion Pack+2 moreNov 21, 2024 Mar 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability. |
7Fedoraproject LinuxNetapp+4 more29Codeready Linux Builder Enterprise LinuxEnterprise Linux Eus+26 moreNov 6, 2025 Mar 10, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values....Show more |
5Debian FedoraprojectLinux+2 more23Codeready Linux Builder Debian LinuxEnterprise Linux+20 moreNov 21, 2024 Mar 10, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memo...Show more |
4Fedoraproject NetappPython+1 more20Codeready Linux Builder Codeready Linux Builder For Ibm Z SystemsCodeready Linux Builder For Power Little Endian+17 moreNov 3, 2025 Mar 10, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReD...Show more |
2Cockpit Project Redhat2Cockpit Enterprise LinuxNov 21, 2024 Mar 10, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate succes...Show more |
2Cockpit Project Redhat2Cockpit Enterprise LinuxNov 21, 2024 Mar 10, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious webs...Show more |
6Canonical FedoraprojectNetapp+3 more17Codeready Linux Builder Codeready Linux Builder For Ibm Z SystemsCodeready Linux Builder For Power Little Endian+14 moreDec 17, 2025 Mar 4, 2022 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU...Show more |
3Fedoraproject LinuxRedhat263scale Api Management Codeready Linux BuilderEnterprise Linux+23 moreNov 21, 2024 Mar 4, 2022 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due...Show more |
3Fedoraproject RedhatUclouvain3Enterprise Linux FedoraOpenjpegNov 3, 2025 Mar 4, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application...Show more |