Oran Agra
17 exploits
Active since Oct 2021
Redis < 6.2.0 - Reachable Assertion via Replica SET Command
CVSS 5.9
Redis 2.8.18-6.2.15 - Authenticated Stack-based Buffer Overflow via Lua Bit Library
CVSS 7.0
Redis < 6.2.0 - Reachable Assertion via Replica SET Command
CVSS 5.9
Redis 5.0.0-5.0.13 - Remote Code Execution via Integer Overflow in Stream Elements
CVSS 7.5
Redis 5.0.0-5.0.13 - Remote Code Execution via Ziplist Integer Overflow
CVSS 7.5
Redis 5.0.0-5.0.13 - Unauthenticated Denial of Service via RESP Request Memory Allocation
CVSS 7.5
Redis <6.2.6/<6.0.16/<5.0.14 - Heap Corruption via set-max-intset-entries
CVSS 7.5
Redis 5.0.0-5.0.13 - Integer Overflow in Multi-Bulk Reply Parsing
CVSS 7.5
Redis 6.0.0-6.0.16 - Authenticated Denial of Service via SETRANGE and SORT(_RO) Integer Overflow
CVSS 5.5
Redis <6.0.18, <6.2.11, <7.0.9 - DoS
CVSS 5.5
Redis 6.2.0-6.2.8 and 7.0.0-7.0.7 - Authenticated Denial of Service via HRANDFIELD or ZRANDMEMBER Command
CVSS 5.5
Redis < 6.0.18 - Authenticated Denial of Service via Integer Overflow in SRANDMEMBER ZRANDMEMBER and HRANDFIELD Commands
CVSS 5.5
Redis 7.0.8-7.0.9 - Authenticated Denial of Service via MSETNX Command
CVSS 5.5
Redis < 6.0.19 - Authenticated Denial of Service via HINCRBYFLOAT Command
CVSS 5.5
Redis 2.6.0-6.2.13 - Unauthenticated Unauthorized Connection via Unix Socket Permission Race Condition
CVSS 3.6
Redis 7.0.0-7.2.5 - Authenticated Denial of Service via Malformed ACL Selector
CVSS 4.4
Redis 2.2.5-6.2.15 - Authenticated Denial of Service via Long String Match Pattern Recursion
CVSS 5.5