redhat

5,618 tracked vulnerabilities.

CVE-2019-11459 MEDIUM
GNOME Evince <3.32.0 - Memory Corruption
Apr 22, 2019
CVSS 5.5
EPSS 0.00
CVE-2019-3902 MEDIUM
Mercurial < 4.9 - Path Traversal via Symlinks and Subrepositories
Apr 22, 2019
CVSS 5.1
EPSS 0.01
CVE-2019-3899 CRITICAL
Openshift Container Platform 3.11 - Unauthenticated Heketi Management Interface Exposure
Apr 22, 2019
CVSS 9.8
EPSS 0.00
CVE-2019-11244 MEDIUM
Kubernetes 1.8.0-1.14.0 - Sensitive Information Exposure via World-Writable Cache Directory
Apr 22, 2019
CVSS 5.0
EPSS 0.00
CVE-2019-11235 CRITICAL
FreeRADIUS < 3.0.19 - Insufficient Verification of Data Authenticity
Apr 22, 2019
CVSS 9.8
EPSS 0.05
CVE-2019-11234 CRITICAL
FreeRADIUS < 3.0.19 - Authentication Spoofing via Reflection
Apr 22, 2019
CVSS 9.8
EPSS 0.17
CVE-2019-11358 MEDIUM
jQuery < 3.4.0 - Prototype Pollution via jQuery.extend
Apr 20, 2019
CVSS 6.1
EPSS 0.02
CVE-2019-10245 HIGH
Eclipse OpenJ9 < 0.14.0 - Denial of Service via Bytecode Verifier Bypass
Apr 19, 2019
CVSS 7.5
EPSS 0.02
CVE-2019-11035 CRITICAL
PHP 7.1.x < 7.1.28, 7.2.x < 7.2.17, 7.3.x < 7.3.4 - Out-of-bounds Read in EXIF Extension
Apr 18, 2019
CVSS 9.1
EPSS 0.03
CVE-2019-11034 CRITICAL
PHP 7.1.x < 7.1.28, 7.2.x < 7.2.17, 7.3.x < 7.3.4 - Out-of-bounds Read in EXIF Extension
Apr 18, 2019
CVSS 9.1
EPSS 0.03
CVE-2019-3883 HIGH
389 Directory Server < 1.4.1.2 - Unauthenticated Denial of Service via SSL/TLS Connection Hang
Apr 17, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-3891 HIGH
Red Hat Satellite 6.4 - Sensitive Information Exposure in Candlepin Log File
Apr 15, 2019
CVSS 7.8
EPSS 0.00
CVE-2019-3460 MEDIUM
Linux Kernel < 5.1 - Heap Data Information Disclosure in L2CAP Configuration Response Parser
Apr 11, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-3459 MEDIUM
Linux Kernel < 5.1 - Heap Address Information Leak via L2CAP_GET_CONF_OPT
Apr 11, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-3845 HIGH
Red Hat Satellite < 6.2 - Authenticated Privileged Command Execution via QPID Broker QMF Methods
Apr 11, 2019
CVSS 8.0
EPSS 0.00
CVE-2019-3837 MEDIUM
Linux Kernel 2.6.32 - Use-After-Free in net_dma tcp_recvmsg()
Apr 11, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-1003050 MEDIUM
Jenkins < 2.164.2 - Stored Cross-Site Scripting via Job URL in f:validateButton
Apr 10, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-1003049 HIGH
Jenkins < 2.164.1 and < 2.171 - Insufficient Session Expiration
Apr 10, 2019
CVSS 8.1
EPSS 0.01
CVE-2019-3842 HIGH
systemd < 242-rc4 - Improper Authorization via XDG_SEAT Environment Variable
Apr 09, 2019
CVSS 7.0
EPSS 0.00
CVE-2019-3893 MEDIUM
Foreman 1.20.0-1.20.2 - Unauthenticated Plaintext Password Exposure via Compute Resource Deletion
Apr 09, 2019
CVSS 4.9
EPSS 0.00
CVE-2019-3887 MEDIUM
Linux Kernel >= 4.16 - Denial of Service via KVM x2APIC MSR Access
Apr 09, 2019
CVSS 5.6
EPSS 0.00
CVE-2019-3880 MEDIUM
Samba 3.2.0-4.8.10 - Unauthenticated Path Traversal via Registry RPC Endpoint
Apr 09, 2019
CVSS 5.4
EPSS 0.03
CVE-2019-0757 MEDIUM
NuGet Package Manager - Path Traversal
Apr 09, 2019
CVSS 6.5
EPSS 0.05
CVE-2019-0211 HIGH KEV
Apache HTTP Server 2.4.17-2.4.38 - Use-After-Free in Scoreboard
Apr 08, 2019
CVSS 7.8
EPSS 0.90
CVE-2019-0217 HIGH
Apache HTTP Server < 2.4.38 - Authentication Bypass via Race Condition in mod_auth_digest
Apr 08, 2019
CVSS 7.5
EPSS 0.43