VYPR

Vendor CVEs

Red Hat

All CVEs

6,464 total · sorted by risk
  • CVE-2023-5156HigSep 25, 2023
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.

  • CVE-2022-3596HigSep 20, 2023
    risk 0.49cvss 7.5epss 0.01

    An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the undercloud, possibly leading to compromising private information, including administrator access…

  • CVE-2023-0813HigSep 15, 2023
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows…

  • CVE-2023-2680HigSep 13, 2023
    risk 0.49cvss 7.5epss 0.00

    This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 via RHSA-2022:7967 included a version of qemu-kvm that was actually missing the fix for CVE-2021-3750.

  • CVE-2023-39417HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.02

    IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension,…

  • CVE-2023-32252HigJul 24, 2023
    risk 0.49cvss 7.5epss 0.04

    A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_LOGOFF commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker can leverage this…

  • CVE-2023-32248HigJul 24, 2023
    risk 0.49cvss 7.5epss 0.04

    A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_TREE_CONNECT and SMB2_QUERY_INFO commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An…

  • CVE-2023-32247HigJul 24, 2023
    risk 0.49cvss 7.5epss 0.04

    A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_SESSION_SETUP commands. The issue results from the lack of control of resource consumption. An attacker can leverage this vulnerability to…

  • CVE-2023-3354HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake…

  • CVE-2023-2953HigMay 30, 2023
    risk 0.49cvss 7.5epss 0.02

    A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.

  • CVE-2023-2295HigMay 17, 2023
    risk 0.49cvss 7.5epss 0.02

    A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the…

  • CVE-2023-2156HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.06

    A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to…

  • CVE-2013-4253HigOct 19, 2022
    risk 0.49cvss 7.5epss 0.01

    The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.

  • CVE-2019-14840HigOct 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials.

  • CVE-2022-2963HigOct 14, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.

  • CVE-2022-1278HigSep 13, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.

  • CVE-2020-10735HigSep 9, 2022
    risk 0.49cvss 7.5epss 0.07

    A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases…

  • CVE-2022-2738HigSep 1, 2022
    risk 0.49cvss 7.5epss 0.01

    The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixed via RHSA-2020:2117. This issue could possibly be used to crash or cause…

  • CVE-2022-1259HigAug 31, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.

  • CVE-2022-1199HigAug 29, 2022
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability.

  • CVE-2022-0934HigAug 29, 2022
    risk 0.49cvss 7.5epss 0.02

    A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a crafted packet processed by dnsmasq, potentially causing a denial of service.

  • CVE-2021-3703HigAug 26, 2022
    risk 0.49cvss 7.5epss 0.01

    It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless 1.16.0 and Serverless client kn 1.16.0. These have been fixed with Serverless 1.17.0.

  • CVE-2022-2509HigAug 1, 2022
    risk 0.49cvss 7.5epss 0.02

    A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.

  • CVE-2014-3648HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is user controlled. If a bogus applications is registered with bad deviceTokens, one can generate endless exceptions when those…

  • CVE-2022-1949HigJun 2, 2022
    risk 0.49cvss 7.5epss 0.01

    An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a…

  • CVE-2021-3523HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. This flaw allows an attacker to bypass security restrictions for an API request when hosting multiple APIs on the same IP address.

  • CVE-2021-4047HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9.

  • CVE-2019-14839HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.

  • CVE-2021-3814HigMar 25, 2022
    risk 0.49cvss 7.5epss 0.01

    It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure.

  • CVE-2022-27191HigMar 18, 2022
    risk 0.49cvss 7.5epss 0.04

    The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

  • CVE-2022-0918HigMar 16, 2022
    risk 0.49cvss 7.5epss 0.06

    A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other…

  • CVE-2022-0853HigMar 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.

  • CVE-2021-3698HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL)…

  • CVE-2021-4091HigFeb 18, 2022
    risk 0.49cvss 7.5epss 0.02

    A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.

  • CVE-2021-41819HigJan 1, 2022
    risk 0.49cvss 7.5epss 0.03

    CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

  • CVE-2021-3580HigAug 5, 2021
    risk 0.49cvss 7.5epss 0.03

    A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.

  • CVE-2021-3637HigJul 9, 2021
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.

  • CVE-2020-14380HigJun 2, 2021
    risk 0.49cvss 7.5epss 0.01

    An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already existing local users of Satellite.

  • CVE-2020-25710HigMay 28, 2021
    risk 0.49cvss 7.5epss 0.03

    A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.

  • CVE-2018-10868HigMay 26, 2021
    risk 0.49cvss 7.5epss 0.01

    redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user to run a "Billion Laugh Attack" by replying to XMLRPC methods when getting the status of an host.

  • CVE-2018-10865HigMay 26, 2021
    risk 0.49cvss 7.5epss 0.01

    It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system, even if not belonging to him.

  • CVE-2018-10863HigMay 26, 2021
    risk 0.49cvss 7.5epss 0.01

    It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker may use this flaw to gather sensible information.

  • CVE-2021-3480HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.

  • CVE-2021-3445HigMay 19, 2021
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of…

  • CVE-2020-25709HigMay 18, 2021
    risk 0.49cvss 7.5epss 0.03

    A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.

  • CVE-2021-31918HigMay 6, 2021
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.

  • CVE-2019-19343HigMar 23, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting…

  • CVE-2019-14852HigMar 18, 2021
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break its encryption, gaining access to unauthorized information. Version shipped in Red Hat 3scale API Management Platform is…

  • CVE-2020-27827HigMar 18, 2021
    risk 0.49cvss 7.5epss 0.03

    A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

  • CVE-2020-27779HigMar 3, 2021
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory…

Page 32 of 130