Skip to main content

Vendor archive

redhat CVEs

Beta · best-effort

5,982 CVEs tagged to vendor redhat666 Critical, 2,012 High, 2,837 Medium, 467 Low, 0 Unrated.

CVE-2023-5217

Published Sep 28, 2023

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a cr…

CVSS 8.8 · High
evidence mentions
21
Buzz score
69.5
KEV listed

CVE-2023-3223

Published Sep 27, 2023

A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause rem…

CVSS 7.5 · High

CVE-2023-0833

Published Sep 27, 2023

A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an i…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0456

Published Sep 27, 2023

A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This could allow a separate realm to be…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4318

Published Sep 25, 2023

A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.

CVSS 7.8 · High

CVE-2023-5156

Published Sep 25, 2023

A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1625

Published Sep 24, 2023

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are suppos…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4039

Published Sep 22, 2023

A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use…

CVSS 8.0 · High

CVE-2022-3874

Published Sep 22, 2023

A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3596

Published Sep 20, 2023

An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the under…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 626-650 of 5,982 CVEsPage 26 of 240