redhat

5,618 tracked vulnerabilities.

CVE-2020-14301 MEDIUM
libvirt < 6.3.0 - Information Disclosure via HTTP Cookie Exposure in dumpxml Command
May 27, 2021
CVSS 6.5
EPSS 0.00
CVE-2020-10729 MEDIUM
Ansible Engine < 2.9.6 - Use of Insufficiently Random Values in Password Lookup
May 27, 2021
CVSS 5.5
EPSS 0.00
CVE-2020-10716 MEDIUM
Red Hat Satellite - Info Disclosure
May 27, 2021
CVSS 6.5
EPSS 0.00
CVE-2020-10709 HIGH
Ansible Tower < 3.5.6 - Insufficient Session Expiration via OAuth2 Token
May 27, 2021
CVSS 7.1
EPSS 0.00
CVE-2020-10701 MEDIUM
libvirt < 6.2.0 - Unauthenticated Denial of Service via QEMU Agent Response Timeout
May 27, 2021
CVSS 6.5
EPSS 0.00
CVE-2020-10698 LOW
Ansible Tower <3.6.4-3.4.6 - Info Disclosure
May 27, 2021
CVSS 3.3
EPSS 0.00
CVE-2020-10697 MEDIUM
Ansible Tower < 3.4.6 - Denial of Service via Memcached Cache Pollution
May 27, 2021
CVSS 4.4
EPSS 0.00
CVE-2020-10688 MEDIUM
RESTEasy <3.11.1.Final-4.5.3.Final - XSS
May 27, 2021
CVSS 6.1
EPSS 0.00
CVE-2020-27832 CRITICAL
Red Hat Quay 3.0.0-3.3.1 - Stored Cross-Site Scripting in Repository Notification Display
May 27, 2021
CVSS 9.0
EPSS 0.00
CVE-2020-27831 MEDIUM
Red Hat Quay 3.0.0-3.3.2 - Improper Access Control in Email Notification Authorization
May 27, 2021
CVSS 4.3
EPSS 0.00
CVE-2020-27839 MEDIUM
ceph < 14.2.17 - Insufficiently Protected Credentials via JWT Storage in localStorage
May 26, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-10695 HIGH
redhat-sso-7 - Privilege Escalation
May 26, 2021
CVSS 7.8
EPSS 0.00
CVE-2020-25724 MEDIUM
RESTEasy <2.0.0.Alpha3 - Info Disclosure
May 26, 2021
CVSS 4.3
EPSS 0.00
CVE-2020-25634 MEDIUM
Red Hat 3scale < 2.10.0 - Unauthenticated Sensitive Information Exposure via API Docs URL
May 26, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-36332 HIGH
libwebp < 1.0.1 - Denial of Service via Excessive Memory Allocation
May 21, 2021
CVSS 7.5
EPSS 0.01
CVE-2020-36331 CRITICAL
libwebp < 1.0.1 - Out-of-bounds Read in ChunkAssignData
May 21, 2021
CVSS 9.1
EPSS 0.00
CVE-2020-36330 CRITICAL
libwebp < 1.0.1 - Out-of-bounds Read in ChunkVerifyAndAssign
May 21, 2021
CVSS 9.1
EPSS 0.00
CVE-2020-36329 CRITICAL
libwebp < 1.0.1 - Use-After-Free
May 21, 2021
CVSS 9.8
EPSS 0.01
CVE-2020-36328 CRITICAL
libwebp < 1.0.1 - Heap-Based Buffer Overflow in WebPDecodeRGBInto
May 21, 2021
CVSS 9.8
EPSS 0.01
CVE-2020-25709 HIGH
OpenLDAP < 2.4.56 - Denial of Service via Assertion Failure
May 18, 2021
CVSS 7.5
EPSS 0.36
CVE-2020-27833 HIGH
OpenShift Container Platform < 4.7 - Arbitrary File Write via Symbolic Link in oc image extract
May 14, 2021
CVSS 7.1
EPSS 0.00
CVE-2020-27769 LOW
ImageMagick < 7.0.9-0 - Integer Overflow in Quantize Component
May 14, 2021
CVSS 3.3
EPSS 0.00
CVE-2020-27824 MEDIUM
OpenJPEG < 2.4.0 - Out-of-bounds Read in opj_dwt_calc_explicit_stepsizes
May 13, 2021
CVSS 5.5
EPSS 0.00
CVE-2020-35518 MEDIUM
389 Directory Server < 1.4.3.19 - Unauthenticated LDAP Entry Existence Disclosure
Mar 26, 2021
CVSS 5.3
EPSS 0.01
CVE-2020-35508 MEDIUM
Linux Kernel < 5.12 - Improper Initialization in Process ID Handling
Mar 26, 2021
CVSS 4.5
EPSS 0.00