Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Redhat Theforeman2Foreman SatelliteNov 21, 2024 Dec 23, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threa...Show more |
1Redhat 1Jboss Enterprise Application Platform Nov 21, 2024 Dec 23, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using a JMS ObjectMessage. |
4Fedoraproject GeglGimp+1 more4Enterprise Linux FedoraGegl+1 moreNov 3, 2025 Dec 23, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick conv...Show more |
5Debian FedoraprojectLinux+2 more12Debian Linux Enterprise LinuxFedora+9 moreNov 21, 2024 Dec 22, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object. |
4Netapp QosRedhat+1 more6Cloud Manager LogbackSatellite+3 moreNov 21, 2024 Dec 16, 2021 N/A· v4 6.6 MEDIUM· v3 8.5 HIGH· v2 In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers. |
5Debian FedoraprojectGnu+2 more5Binutils Debian LinuxEnterprise Linux+2 moreNov 21, 2024 Dec 15, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds wr...Show more |
4Apache FedoraprojectOracle+1 more46Advanced Supply Chain Planning Business IntelligenceBusiness Process Management Suite+43 moreMay 28, 2026 Dec 14, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName c...Show more |
5Fedoraproject JulialangLapack Project+2 more8Ceph Storage Enterprise LinuxFedora+5 moreNov 21, 2024 Dec 8, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these function...Show more |
5Canonical DebianDjangoproject+2 more5Debian Linux DjangoFedora+2 moreNov 21, 2024 Dec 8, 2021 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths. |
3Fedoraproject RedhatUdisks Project3Enterprise Linux FedoraUdisksNov 21, 2024 Nov 29, 2021 N/A· v4 4.2 MEDIUM· v3 6.3 MEDIUM· v2 A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability. |
6C Ares Project FedoraprojectNodejs+3 more17C Ares Enterprise LinuxEnterprise Linux Computer Node+14 moreNov 21, 2024 Nov 23, 2021 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The h...Show more |
4Debian FedoraprojectPgbouncer+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 3, 2025 Nov 22, 2021 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encrypt...Show more |
4Debian LinuxOracle+1 more6Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+3 moreNov 21, 2024 Nov 4, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c. |
3Fedoraproject Libtpms ProjectRedhat3Enterprise Linux FedoraLibtpmsNov 21, 2024 Oct 19, 2021 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 A flaw was found in the libtpms code that may cause access beyond the boundary of internal buffers. The vulnerability is triggered by specially-crafted TPM2 command packets that then trigger the issue when the state of t...Show more |
2Postgresql Redhat2Jboss Enterprise Application Platform PostgresqlNov 21, 2024 Oct 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is...Show more |
6Debian FedoraprojectNetapp+3 more8Communications Operations Monitor Debian LinuxEnterprise Linux+5 moreNov 21, 2024 Oct 4, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. Thi...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelNov 21, 2024 Sep 29, 2021 N/A· v4 8.8 HIGH· v3 6.1 MEDIUM· v2 A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due...Show more |
1Redhat 3Ansible Automation Platform Ansible EngineAnsible TowerNov 21, 2024 Sep 22, 2021 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and th...Show more |
2Infinispan Redhat2Data Grid Infinispan Server RestNov 21, 2024 Sep 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when DIGEST is used as the authentication met...Show more |
11Apache BroadcomDebian+8 more39Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+36 moreOct 27, 2025 Sep 16, 2021 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |