Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Argoproj Redhat2Argo Cd Openshift GitopsNov 21, 2024 Feb 16, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster i...Show more |
4Dogtagpki FedoraprojectOracle+1 more12Dogtagpki Enterprise LinuxEnterprise Linux Eus+9 moreNov 21, 2024 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin p...Show more |
5Debian FedoraprojectLibtiff+2 more5Debian Linux Enterprise LinuxFedora+2 moreNov 21, 2024 Feb 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that c...Show more |
2Kubernetes Redhat2Cri O Openshift Container PlatformNov 21, 2024 Feb 9, 2022 N/A· v4 4.2 MEDIUM· v3 4.9 MEDIUM· v2 An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod...Show more |
5Apple DebianFedoraproject+2 more6Debian Linux Enterprise LinuxFedora+3 moreNov 21, 2024 Feb 9, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file,...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Feb 9, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file,...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelNov 21, 2024 Feb 4, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidenti...Show more |
3Linux NetappRedhat4Enterprise Linux Hci Baseboard Management ControllerLinux Kernel+1 moreNov 21, 2024 Feb 4, 2022 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsco...Show more |
7Canonical OraclePolkit Project+4 more30Command Center Enterprise LinuxEnterprise Linux Desktop+27 moreNov 6, 2025 Jan 28, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined polic...Show more |
2Qemu Redhat2Enterprise Linux QemuNov 21, 2024 Jan 25, 2022 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` pointer is dereferenced in mirror_wait_on_conflicts() without ensuring that it's not NULL. A malicious u...Show more |
A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user regist...Show more |
5Advanced Intrusion Detection Environment Project CanonicalDebian+2 more7Advanced Intrusion Detection Environment Debian LinuxEnterprise Linux+4 moreNov 21, 2024 Jan 20, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow. |
4Debian FedoraprojectFlatpak+1 more5Debian Linux Enterprise LinuxFedora+2 moreNov 21, 2024 Jan 13, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At thi...Show more |
4Debian FedoraprojectFlatpak+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Jan 12, 2022 N/A· v4 8.6 HIGH· v3 6.8 MEDIUM· v2 Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the...Show more |
6Debian FedoraprojectOpensuse+3 more9Cgi Debian LinuxEnterprise Linux+6 moreMay 22, 2025 Jan 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby. |
6Debian FedoraprojectOpensuse+3 more9Date Debian LinuxEnterprise Linux+6 moreNov 21, 2024 Jan 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1. |
7Apple DebianFedoraproject+4 more8Debian Linux Enterprise LinuxFactory+5 moreNov 21, 2024 Dec 25, 2021 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 vim is vulnerable to Out-of-bounds Read |
2Fedoraproject Redhat4Enterprise Linux Enterprise Linux WorkstationFedora+1 moreNov 21, 2024 Dec 23, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack...Show more |
2Fedoraproject Redhat8Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+5 moreNov 3, 2025 Dec 23, 2021 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially c...Show more |
3Fedoraproject Podman ProjectRedhat3Enterprise Linux FedoraPodmanNov 21, 2024 Dec 23, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on p...Show more |