redhat

5,618 tracked vulnerabilities.

CVE-2021-20325 CRITICAL
Red Hat Enterprise Linux 8.5.0 - Security Regression via Missing httpd Fixes
Feb 18, 2022
CVSS 9.8
EPSS 0.01
CVE-2021-20321 MEDIUM
Linux Kernel < 5.15 - Denial of Service via OverlayFS File Rename Race Condition
Feb 18, 2022
CVSS 4.7
EPSS 0.00
CVE-2021-20320 MEDIUM
Linux Kernel - Exposure of Sensitive Information via s390 eBPF JIT Verifier Bypass
Feb 18, 2022
CVSS 5.5
EPSS 0.00
CVE-2021-3773 CRITICAL
Linux Kernel < 5.14 - Exposure of Sensitive Information via netfilter
Feb 16, 2022
CVSS 9.8
EPSS 0.01
CVE-2021-3753 MEDIUM
Linux Kernel < 5.15 - Out-of-bounds Read via VT IOCTL Race Condition
Feb 16, 2022
CVSS 4.7
EPSS 0.00
CVE-2021-3752 HIGH
Linux Kernel 2.6.12-4.4.293 - Use-After-Free via Bluetooth Socket Race Condition
Feb 16, 2022
CVSS 7.1
EPSS 0.00
CVE-2021-3560 HIGH KEV
polkit < 0.119 - Unauthenticated Privilege Escalation via D-Bus Request
Feb 16, 2022
CVSS 7.8
EPSS 0.06
CVE-2021-3557 MEDIUM
Argo CD < 1.1.1 - Unauthenticated Cluster Resource and Secret Exposure via ServiceAccount
Feb 16, 2022
CVSS 6.5
EPSS 0.00
CVE-2021-3551 HIGH
dogtagpki 10.10.0-10.10.5 - Cleartext Storage of Sensitive Information in Installation Log File
Feb 16, 2022
CVSS 7.8
EPSS 0.00
CVE-2021-4154 HIGH
Linux Kernel >=5.1 <5.4.134 - Use-After-Free in cgroup v1 Parser
Feb 04, 2022
CVSS 8.8
EPSS 0.01
CVE-2021-4034 HIGH KEV
Local Privilege Escalation in polkits pkexec
Jan 28, 2022
CVSS 7.8
EPSS 0.89
CVE-2021-4145 MEDIUM
QEMU < 6.2.0 - Denial of Service via NULL Pointer Dereference in Block Mirror Layer
Jan 25, 2022
CVSS 6.5
EPSS 0.00
CVE-2021-4133 HIGH
Keycloak 12.0.0-15.1.0 - Incorrect Authorization via Administrative REST API
Jan 25, 2022
CVSS 8.8
EPSS 0.00
CVE-2021-45417 HIGH
Advanced Intrusion Detection Environment - Out-of-Bounds Write
Jan 20, 2022
CVSS 7.8
EPSS 0.00
CVE-2021-43860 HIGH
Flatpak <1.12.3-1.10.6 - Privilege Escalation
Jan 12, 2022
CVSS 8.2
EPSS 0.00
CVE-2021-41819 HIGH
Ruby CGI < 2.6.8 and CGI Gem < 0.3.1 - Cookie Security Prefix Bypass
Jan 01, 2022
CVSS 7.5
EPSS 0.01
CVE-2021-41817 HIGH
ruby-lang/date < 2.0.1 - Regular Expression Denial of Service via Date.parse
Jan 01, 2022
CVSS 7.5
EPSS 0.00
CVE-2021-4166 HIGH
vim < 8.2.3884 - Out-of-bounds Read
Dec 25, 2021
CVSS 7.1
EPSS 0.00
CVE-2021-3622 MEDIUM
hivex - Denial of Service via Recursive _get_children() Function Call
Dec 23, 2021
CVSS 4.3
EPSS 0.01
CVE-2021-3621 HIGH
SSSD - OS Command Injection via sssctl logs-fetch and cache-expire Subcommands
Dec 23, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-4024 MEDIUM
Podman <3.4.3 - gvproxy API Exposure Allows Host-to-VM Port Forwarding
Dec 23, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-3584 HIGH
Foreman - Remote Code Execution via Sendmail Configuration
Dec 23, 2021
CVSS 7.2
EPSS 0.00
CVE-2021-20318 HIGH
JBoss Enterprise Application Platform - Remote Code Execution via JMS ObjectMessage Deserialization
Dec 23, 2021
CVSS 7.2
EPSS 0.02
CVE-2021-45463 HIGH
GEGL < 0.4.34 - OS Command Injection via ImageMagick Convert Fallback
Dec 23, 2021
CVSS 7.8
EPSS 0.02
CVE-2021-44733 HIGH
Linux Kernel < 5.15.11 - Use-After-Free in TEE Shared Memory Handling
Dec 22, 2021
CVSS 7.0
EPSS 0.00