Vendor CVEs
Red Hat
All CVEs
6,364 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-40549 | Med | 0.40 | 6.2 | 0.00 | Jan 29, 2024 | An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service. | ||
| CVE-2023-40546 | Med | 0.40 | 6.2 | 0.00 | Jan 29, 2024 | A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the logging function doesn't match the format string used by it,… | ||
| CVE-2023-5384 | Hig | 0.40 | 7.2 | 0.01 | Dec 18, 2023 | A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration. | ||
| CVE-2023-4958 | Med | 0.40 | 6.1 | 0.01 | Dec 12, 2023 | In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web… | ||
| CVE-2023-38473 | Med | 0.40 | 6.2 | 0.00 | Nov 2, 2023 | A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function. | ||
| CVE-2022-4900 | Med | 0.40 | 6.2 | 0.00 | Nov 2, 2023 | A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow. | ||
| CVE-2023-38472 | Med | 0.40 | 6.2 | 0.00 | Nov 2, 2023 | A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function. | ||
| CVE-2023-38471 | Med | 0.40 | 6.2 | 0.00 | Nov 2, 2023 | A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function. | ||
| CVE-2023-38470 | Med | 0.40 | 6.2 | 0.00 | Nov 2, 2023 | A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function. | ||
| CVE-2023-38469 | Med | 0.40 | 6.2 | 0.00 | Nov 2, 2023 | A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record. | ||
| CVE-2023-39193 | Med | 0.40 | 6.1 | 0.00 | Oct 9, 2023 | A flaw was found in the Netfilter subsystem in the Linux kernel. The sctp_mt_check did not validate the flag_count field. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, leading to a crash or information disclosure. | ||
| CVE-2023-3428 | Med | 0.40 | 6.2 | 0.00 | Oct 4, 2023 | A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service. | ||
| CVE-2023-32627 | Med | 0.40 | 6.2 | 0.00 | Jul 10, 2023 | A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service. | ||
| CVE-2023-26590 | Med | 0.40 | 6.2 | 0.00 | Jul 10, 2023 | A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service. | ||
| CVE-2023-0044 | Med | 0.40 | 6.1 | 0.01 | Feb 23, 2023 | If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature. | ||
| CVE-2020-15855 | Med | 0.40 | 6.1 | 0.00 | Oct 7, 2022 | Two cross-site scripting vulnerabilities were fixed in Bodhi 5.6.1. | ||
| CVE-2014-0147 | Med | 0.40 | 6.2 | 0.00 | Sep 29, 2022 | Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snapshots, which leads to incorrectly calling update_refcount()… | ||
| CVE-2022-1355 | Med | 0.40 | 6.1 | 0.01 | Aug 31, 2022 | A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of… | ||
| CVE-2022-2668 | Hig | 0.40 | 7.2 | 0.01 | Aug 5, 2022 | An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled | ||
| CVE-2021-20293 | Med | 0.40 | 6.1 | 0.01 | Jun 10, 2021 | A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL encoding when calling @javax.ws.rs.PathParam without any @Produces MediaType. This flaw allows an attacker to launch a reflected… | ||
| CVE-2020-1761 | Med | 0.40 | 6.1 | 0.01 | May 27, 2021 | A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects openshift/console versions… | ||
| CVE-2020-10688 | Med | 0.40 | 6.1 | 0.01 | May 27, 2021 | A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack. | ||
| CVE-2021-3507 | Med | 0.40 | 6.1 | 0.00 | May 6, 2021 | A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this… | ||
| CVE-2020-1721 | Med | 0.40 | 6.1 | 0.01 | Apr 30, 2021 | A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitize the recovery ID during a key recovery request, enabling a reflected cross-site scripting (XSS) vulnerability. An attacker could trick an authenticated victim… | ||
| CVE-2021-20288 | Hig | 0.40 | 7.2 | 0.02 | Apr 15, 2021 | An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of any user to request a… | ||
| CVE-2020-1723 | Med | 0.40 | 6.1 | 0.01 | Jan 28, 2021 | A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0 | ||
| CVE-2020-27816 | Med | 0.40 | 6.1 | 0.01 | Dec 2, 2020 | The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR for the new kibana resource.… | ||
| CVE-2020-25626 | Med | 0.40 | 6.1 | 0.01 | Sep 30, 2020 | A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject… | ||
| CVE-2019-11556 | Med | 0.40 | 6.1 | 0.01 | Sep 25, 2020 | Pagure before 5.6 allows XSS via the templates/blame.html blame view. | ||
| CVE-2020-10748 | Med | 0.40 | 6.1 | 0.01 | Sep 16, 2020 | A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks. | ||
| CVE-2019-14904 | Hig | 0.40 | 7.3 | 0.00 | Aug 26, 2020 | A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker could take advantage of this flaw… | ||
| CVE-2019-3865 | Med | 0.40 | 6.1 | 0.01 | Jun 22, 2020 | A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay. Attackers are able to use the name field of service key to inject scripts and make it run when admin users try to change the name. | ||
| CVE-2020-12685 | Med | 0.40 | 6.1 | 0.01 | May 15, 2020 | XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote attackers to steal credentials or data via browser JavaScript. | ||
| CVE-2019-19336 | Med | 0.40 | 6.1 | 0.01 | Mar 19, 2020 | A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML pages that can run scripts in… | ||
| CVE-2020-1697 | Med | 0.40 | 6.1 | 0.01 | Feb 10, 2020 | It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly… | ||
| CVE-2019-19332 | Med | 0.40 | 6.1 | 0.01 | Jan 9, 2020 | An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by the KVM hypervisor. A user or process able to access… | ||
| CVE-2019-17022 | Med | 0.40 | 6.1 | 0.02 | Jan 8, 2020 | When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage;… | ||
| CVE-2019-17016 | Med | 0.40 | 6.1 | 0.02 | Jan 8, 2020 | When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR < 68.4 and… | ||
| CVE-2014-0183 | Med | 0.40 | 6.1 | 0.01 | Jan 2, 2020 | Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering. | ||
| CVE-2016-1000229 | Med | 0.40 | 6.1 | 0.04 | Dec 20, 2019 | swagger-ui has XSS in key names | ||
| CVE-2013-6495 | Med | 0.40 | 6.1 | 0.01 | Dec 11, 2019 | JBossWeb Bayeux has reflected XSS | ||
| CVE-2014-3592 | Med | 0.40 | 6.1 | 0.01 | Nov 13, 2019 | OpenShift Origin: Improperly validated team names could allow stored XSS attacks | ||
| CVE-2010-3857 | Med | 0.40 | 6.1 | 0.01 | Nov 12, 2019 | JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID parameter. | ||
| CVE-2016-1000037 | Med | 0.40 | 6.1 | 0.01 | Nov 6, 2019 | Pagure: XSS possible in file attachment endpoint | ||
| CVE-2014-3649 | Med | 0.40 | 6.1 | 0.01 | Nov 4, 2019 | JBoss AeroGear has reflected XSS via the password field | ||
| CVE-2013-0186 | Med | 0.40 | 6.1 | 0.01 | Nov 1, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2018-9090 | Med | 0.40 | 6.1 | 0.01 | Sep 24, 2019 | CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (admin/admin) for the administrator account located at grafana-credentials secret. This occurs because CoreOS does not randomize the administrative password to… | ||
| CVE-2019-1125 | Med | 0.40 | 5.6 | 0.05 | Sep 3, 2019 | An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would… | ||
| CVE-2019-11041 | Hig | 0.40 | 7.1 | 0.04 | Aug 9, 2019 | When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This… | ||
| CVE-2019-3837 | Med | 0.40 | 6.1 | 0.00 | Apr 11, 2019 | It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unprivileged multi-threaded userspace application calling recvmsg() for the same network socket in parallel executed on ioatdma-enabled hardware with net_dma… |
- risk 0.40cvss 6.2epss 0.00
An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service.
- risk 0.40cvss 6.2epss 0.00
A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the logging function doesn't match the format string used by it,…
- risk 0.40cvss 7.2epss 0.01
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
- risk 0.40cvss 6.1epss 0.01
In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web…
- risk 0.40cvss 6.2epss 0.00
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.
- risk 0.40cvss 6.2epss 0.00
A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.
- risk 0.40cvss 6.2epss 0.00
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.
- risk 0.40cvss 6.2epss 0.00
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
- risk 0.40cvss 6.2epss 0.00
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function.
- risk 0.40cvss 6.2epss 0.00
A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record.
- risk 0.40cvss 6.1epss 0.00
A flaw was found in the Netfilter subsystem in the Linux kernel. The sctp_mt_check did not validate the flag_count field. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, leading to a crash or information disclosure.
- risk 0.40cvss 6.2epss 0.00
A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.
- risk 0.40cvss 6.2epss 0.00
A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.
- risk 0.40cvss 6.2epss 0.00
A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service.
- risk 0.40cvss 6.1epss 0.01
If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature.
- risk 0.40cvss 6.1epss 0.00
Two cross-site scripting vulnerabilities were fixed in Bodhi 5.6.1.
- risk 0.40cvss 6.2epss 0.00
Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snapshots, which leads to incorrectly calling update_refcount()…
- risk 0.40cvss 6.1epss 0.01
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of…
- risk 0.40cvss 7.2epss 0.01
An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled
- risk 0.40cvss 6.1epss 0.01
A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where it did not properly handle URL encoding when calling @javax.ws.rs.PathParam without any @Produces MediaType. This flaw allows an attacker to launch a reflected…
- risk 0.40cvss 6.1epss 0.01
A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects openshift/console versions…
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
- risk 0.40cvss 6.1epss 0.00
A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_transfer_handler() in hw/block/fdc.c while processing DMA read data transfers from the floppy drive to the guest system. A privileged guest user could use this…
- risk 0.40cvss 6.1epss 0.01
A flaw was found in the Key Recovery Authority (KRA) Agent Service in pki-core 10.10.5 where it did not properly sanitize the recovery ID during a key recovery request, enabling a reflected cross-site scripting (XSS) vulnerability. An attacker could trick an authenticated victim…
- risk 0.40cvss 7.2epss 0.02
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of any user to request a…
- risk 0.40cvss 6.1epss 0.01
A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0
- risk 0.40cvss 6.1epss 0.01
The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR for the new kibana resource.…
- risk 0.40cvss 6.1epss 0.01
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject…
- risk 0.40cvss 6.1epss 0.01
Pagure before 5.6 allows XSS via the templates/blame.html blame view.
- risk 0.40cvss 6.1epss 0.01
A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.
- risk 0.40cvss 7.3epss 0.00
A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker could take advantage of this flaw…
- risk 0.40cvss 6.1epss 0.01
A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay. Attackers are able to use the name field of service key to inject scripts and make it run when admin users try to change the name.
- risk 0.40cvss 6.1epss 0.01
XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote attackers to steal credentials or data via browser JavaScript.
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML pages that can run scripts in…
- risk 0.40cvss 6.1epss 0.01
It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly…
- risk 0.40cvss 6.1epss 0.01
An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by the KVM hypervisor. A user or process able to access…
- risk 0.40cvss 6.1epss 0.02
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage;…
- risk 0.40cvss 6.1epss 0.02
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR < 68.4 and…
- risk 0.40cvss 6.1epss 0.01
Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.
- risk 0.40cvss 6.1epss 0.04
swagger-ui has XSS in key names
- risk 0.40cvss 6.1epss 0.01
JBossWeb Bayeux has reflected XSS
- risk 0.40cvss 6.1epss 0.01
OpenShift Origin: Improperly validated team names could allow stored XSS attacks
- risk 0.40cvss 6.1epss 0.01
JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID parameter.
- risk 0.40cvss 6.1epss 0.01
Pagure: XSS possible in file attachment endpoint
- risk 0.40cvss 6.1epss 0.01
JBoss AeroGear has reflected XSS via the password field
- risk 0.40cvss 6.1epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (admin/admin) for the administrator account located at grafana-credentials secret. This occurs because CoreOS does not randomize the administrative password to…
- risk 0.40cvss 5.6epss 0.05
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would…
- risk 0.40cvss 7.1epss 0.04
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This…
- risk 0.40cvss 6.1epss 0.00
It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unprivileged multi-threaded userspace application calling recvmsg() for the same network socket in parallel executed on ioatdma-enabled hardware with net_dma…
Page 57 of 128