VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2956 CVEsRSS

CVE-2022-38266Medium· 6.5
4y ago

An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.

An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.

▾ Sunlittesseract-ocr · tesseract_ocrEPSS 1.4%via NVD
CVE-2022-3037High· 7.8
4y ago

Use After Free in GitHub repository vim/vim prior to 9.0.0322.

Use After Free in GitHub repository vim/vim prior to 9.0.0322.

▾ Twilightneovim · neovimEPSS 0.53%via NVD
CVE-2022-3064High· 7.5
4y ago

go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents (CVE-2022-3064)

A flaw was found in go-yaml. This issue causes the consumption of excessive amounts of CPU or memory when attempting to parse a large or maliciously crafted YAML document.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 1.7%via CSAF
CVE-2022-37434Critical· 9.8PoC⚖ disputed
4y ago

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the af…

▾ Abyssalzlib · zlibEPSS 18%via NVD
CVE-2018-25032High· 7.5PoC
4y ago

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

▾ Midnightnokogiri · nokogiriEPSS 52%via NVD
CVE-2021-44227High· 8.0
4y ago

mailman: CSRF token bypass allows to perform CSRF attacks and admin takeover (CVE-2021-44227)

A Cross-Site Request Forgery (CSRF) attack can be performed in mailman due to a CSRF token bypass. CSRF tokens are not checked against the right type of user when performing admin operations and a token created by a regular user can be use…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream EUS (v. 8.2)EPSS 0.76%via CSAF
CVE-2021-40690High· 7.5
5y ago

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allo…

▾ Twilightapache · santuario_xml_security_for_javaEPSS 7.4%via NVD
CVE-2021-40438Critical· 9.0CISA KEVPoC
5y ago

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

▾ Hadalredhat · jboss_core_servicesEPSS 100%via NVD
CVE-2021-38554Medium· 5.3
5y ago

vault: UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser (CVE-2021-38554)

A flaw was found in the vault package. The Vault UI web application may fail to completely clear a client-side data cache on user logout. As a result, an authenticated user sharing a browser to access Vault may have been able to view the p…

▾ SunlitRed Hat · Red Hat Openshift Container Storage 4EPSS 0.91%via CSAF
CVE-2021-32760Medium· 5.5
5y ago

containerd: pulling and extracting crafted container image may result in Unix file permission changes (CVE-2021-32760)

A flaw was found in containerd where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expe…

▾ SunlitRed Hat · RHOSSM 2.4 for RHEL 8EPSS 1.6%via CSAF
CVE-2021-32923Medium· 6.5
5y ago

vault: Token leases incorrectly treated as non-expiring (CVE-2021-32923)

A flaw was found in the HashiCorp Vault and Vault Enterprise. The vault could allow a remote attacker to bypass security restrictions caused by a renewal logic flaw when a token lease or dynamic secret lease was renewed inside the last sec…

▾ SunlitRed Hat · Red Hat Openshift Container Storage 4EPSS 1.4%via CSAF
CVE-2021-33194High· 7.5
5y ago

golang: x/net/html: infinite loop in ParseFragment (CVE-2021-33194)

A flaw was found in golang. An attacker can craft an input to ParseFragment within parse.go that would cause it to enter an infinite loop and never return. The greatest threat to the system is of availability.

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 7.5%via CSAF
CVE-2021-29425Medium· 4.8PoC
5y ago

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent di…

In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent di…

▾ Twilightapache · commons_ioEPSS 9.9%via NVD
CVE-2020-14040High· 7.5
6y ago

golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040)

A denial of service vulnerability was found in the golang.org/x/text library. A library or application must use one of the vulnerable functions, such as unicode.Transform, transform.String, or transform.Byte, to be susceptible to this vuln…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.6EPSS 1.8%via CSAF
CVE-2020-6851High· 7.5
6y ago

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

▾ Twilightuclouvain · openjpegEPSS 5.2%via NVD
CVE-2017-7200Medium· 5.8
9y ago

An SSRF issue was discovered in OpenStack Glance before Newton

An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'ht…

▾ Sunlitopenstack · glanceEPSS 2.1%via NVD
CVEs tagged “red-hat” — page 99 · VulnSea