redhat

5,618 tracked vulnerabilities.

CVE-2020-14299 MEDIUM
JBoss Enterprise Application Platform < 5.0.3 - Authentication Bypass via Legacy SecurityRealm Configuration
Oct 16, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-14355 MEDIUM
spice < 0.14.2 - Buffer Overflow in QUIC Image Decoding
Oct 07, 2020
CVSS 6.6
EPSS 0.01
CVE-2020-25743 LOW
QEMU < 5.1.1 - NULL Pointer Dereference in IDE PCI Controller
Oct 06, 2020
CVSS 3.2
EPSS 0.00
CVE-2020-25644 HIGH
WildFly OpenSSL < 1.1.3 - Memory Leak Denial of Service via HTTP Session Removal
Oct 06, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-25643 HIGH
Linux Kernel < 5.9-rc7 - Memory Corruption and Denial of Service in HDLC_PPP Module
Oct 06, 2020
CVSS 7.2
EPSS 0.00
CVE-2020-25641 MEDIUM
Linux Kernel < 5.9-rc7 - Denial of Service via Zero-Length Biovec Request
Oct 06, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-25637 MEDIUM
libvirt < 6.8.0 - Double Free in QEMU Domain Network Interface Request
Oct 06, 2020
CVSS 6.7
EPSS 0.00
CVE-2020-25635 MEDIUM
Ansible < 2.10.1 - Sensitive Information Exposure via AWS SSM Connection Plugin
Oct 05, 2020
CVSS 5.0
EPSS 0.00
CVE-2020-25636 MEDIUM
Ansible - Unauthenticated Arbitrary File Write via AWS SSM Connection Plugin
Oct 05, 2020
CVSS 6.6
EPSS 0.00
CVE-2020-25626 MEDIUM
Django REST Framework < 3.12.0 and < 3.11.2 - Cross-Site Scripting in Browseable API Viewer
Sep 30, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-14370 MEDIUM
Podman < 2.0.5 - Information Disclosure via Environment Variable Leak
Sep 23, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-14365 HIGH
Ansible Engine 2.8.0-2.8.14 and 2.9.0-2.9.12 - Improper Verification of Cryptographic Signature in DNF Module
Sep 23, 2020
CVSS 7.1
EPSS 0.00
CVE-2020-10714 HIGH
WildFly Elytron <1.11.3.Final - Privilege Escalation
Sep 23, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-10687 MEDIUM
Undertow < 2.2.0.Final - HTTP Request Smuggling via Invalid Characters in HTTP Request
Sep 23, 2020
CVSS 4.8
EPSS 0.00
CVE-2020-25633 MEDIUM
RESTEasy < 4.5.6.Final - Information Disclosure via WebApplicationException Error Message
Sep 18, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-14338 MEDIUM
Xerces < 2.12.0.SP3 - XML Schema Validation Bypass via Grammar Pool Manipulation
Sep 17, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-1694 MEDIUM
Keycloak < 10.0.0 - Unauthenticated Information Disclosure via NodeJS Adapter
Sep 16, 2020
CVSS 4.9
EPSS 0.00
CVE-2020-10718 HIGH
Wildfly <13.0.0.Final - Privilege Escalation
Sep 16, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-14348 MEDIUM
AMQ Online < 1.5.2 - Denial of Service via Invalid AddressSpace Configuration Field
Sep 16, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-10748 MEDIUM
Keycloak 10.0.1 - Cross-Site Scripting via Data URL Processing
Sep 16, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-10715 MEDIUM
openshift/console <4 - Content Spoofing
Sep 16, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-1748 HIGH
WildFly <wildfly-elytron-1.6.8.Final-redhat-00001 - Info Disclosure
Sep 16, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-10758 HIGH
Keycloak < 11.0.1 - Denial of Service via Malformed Content-Length Header
Sep 16, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-1710 MEDIUM
JBoss EAP 6.4.21 - HTTP Request Parsing Issue
Sep 16, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-14382 HIGH
cryptsetup - Out-of-bounds Write in LUKS2 Segments Validation
Sep 16, 2020
CVSS 7.8
EPSS 0.00