Skip to main content

Vendor/product archive

redislabs / redis CVEs

Beta · best-effort

22 CVEs tagged to redislabs / redis5 Critical, 12 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2020-21468

Published Sep 20, 2021

A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS). NOTE: the vendor cannot reproduce this issue in a released version, such as 5…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29478

Published May 4, 2021

Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis 6.2 before 6.2.3 could be e…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29477

Published May 4, 2021

Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis version 6.0 or newer could…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3470

Published Mar 31, 2021

A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemalloc or glibc's malloc, leading to pot…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21309

Published Feb 26, 2021

Redis is an open-source, in-memory database that persists on disk. In affected versions of Redis an integer overflow bug in 32-bit Redis version 4.0 or newer could be exploited to…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0180

Published Nov 1, 2019

Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0178

Published Nov 1, 2019

Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10193

Published Jul 11, 2019

A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperlo…

CVSS 7.2 · High

CVE-2019-10192

Published Jul 11, 2019

A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting…

CVSS 7.2 · High

CVE-2018-12326

Published Jun 17, 2018

Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command lin…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12453

Published Jun 16, 2018

Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via an XGROUP command in which th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10517

Published Oct 24, 2017

networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly o…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15047

Published Oct 6, 2017

The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and application crash) or possibly have unspeci…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-8339

Published Oct 28, 2016

A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-7458

Published Aug 10, 2016

linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1