Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of...Show more |
5Debian FedoraprojectLinux+2 more23Build Of Quarkus Codeready Linux BuilderCodeready Linux Builder Eus+20 moreNov 21, 2024 Mar 4, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is simi...Show more |
3Fedoraproject PostgresqlRedhat6Enterprise Linux Enterprise Linux For Ibm Z SystemsEnterprise Linux For Power Little Endian+3 moreNov 21, 2024 Mar 4, 2022 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established,...Show more |
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the fil...Show more |
6Canonical DebianFedoraproject+3 more37Bootstrap Os Codeready Linux BuilderCodeready Linux Builder For Power Little Endian+34 moreJun 3, 2026 Mar 3, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to esca...Show more |
1Redhat 9Ansible Automation Platform Early Access Ansible EngineEnterprise Linux+6 moreNov 21, 2024 Mar 3, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulner...Show more |
3Linux NetappRedhat323scale Api Management Build Of QuarkusCodeready Linux Builder Eus+29 moreNov 21, 2024 Mar 3, 2022 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in ne...Show more |
2Buildah Project Redhat4Buildah Enterprise LinuxEnterprise Linux For Ibm Z Systems+1 moreNov 21, 2024 Mar 3, 2022 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and...Show more |
5Debian LinuxNetapp+2 more18Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+15 moreNov 21, 2024 Mar 2, 2022 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can s...Show more |
2Nbdkit Project Redhat2Enterprise Linux NbdkitNov 21, 2024 Mar 2, 2022 N/A· v4 3.1 LOW· v3 3.5 LOW· v2 A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everythi...Show more |
3Fedoraproject PostgresqlRedhat7Enterprise Linux Enterprise Linux For Ibm Z SystemsEnterprise Linux For Power Little Endian+4 moreNov 21, 2024 Mar 2, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not requi...Show more |
3Debian NetappRedhat4Debian Linux Enterprise LinuxLibvirt+1 moreFeb 10, 2025 Mar 2, 2022 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL...Show more |
2Openstack Redhat2Nova Openstack PlatformNov 21, 2024 Mar 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL. |
2Netapp Redhat4Enterprise Linux LibvirtOntap Select Deploy Administration Utility+1 moreNov 21, 2024 Mar 2, 2022 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt co...Show more |
3Fedoraproject Libtpms ProjectRedhat3Enterprise Linux FedoraLibtpmsNov 21, 2024 Mar 2, 2022 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of-bounds access when the volatile state of the TPM 2 is marshalled/writt...Show more |
3Debian HaproxyRedhat5Debian Linux Enterprise LinuxHaproxy+2 moreNov 21, 2024 Mar 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulti...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Feb 24, 2022 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write da...Show more |
3Fedoraproject ImagemagickRedhat3Enterprise Linux FedoraImagemagickJan 26, 2026 Feb 24, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to...Show more |
4Debian FedoraprojectImagemagick+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Feb 24, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and u...Show more |
3Fedoraproject Htmldoc ProjectRedhat3Enterprise Linux FedoraHtmldocNov 21, 2024 Feb 24, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service. |