Vulnerabilities > Redhat

DATE CVE VULNERABILITY TITLE RISK
2024-11-12 CVE-2024-49394 Improper Verification of Cryptographic Signature vulnerability in multiple products
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.
network
low complexity
neomutt mutt redhat CWE-347
5.3
2024-11-12 CVE-2024-49395 In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
network
low complexity
neomutt mutt redhat
5.3
2024-11-12 CVE-2024-49393 Improper Verification of Cryptographic Signature vulnerability in multiple products
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compromise message confidentiality.
network
high complexity
neomutt mutt redhat CWE-347
5.9
2024-11-04 CVE-2024-51127 Unspecified vulnerability in Redhat Hornetq
An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.
local
low complexity
redhat
7.1
2024-10-29 CVE-2024-50074 Out-of-bounds Read vulnerability in multiple products
In the Linux kernel, the following vulnerability has been resolved: parport: Proper fix for array out-of-bounds access The recent fix for array out-of-bounds accesses replaced sprintf() calls blindly with snprintf().
local
low complexity
linux redhat CWE-125
7.8
2024-10-22 CVE-2024-10234 Cross-site Scripting vulnerability in Redhat products
A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system.
network
low complexity
redhat CWE-79
7.3
2024-10-22 CVE-2024-50311 Allocation of Resources Without Limits or Throttling vulnerability in Redhat Openshift Container Platform 4.0
A denial of service (DoS) vulnerability was found in OpenShift.
network
low complexity
redhat CWE-770
6.5
2024-10-22 CVE-2024-50312 Unspecified vulnerability in Redhat Openshift Container Platform 4.0
A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query.
network
low complexity
redhat
5.3
2024-10-16 CVE-2024-10033 Cross-site Scripting vulnerability in Redhat products
A vulnerability was found in aap-gateway.
network
low complexity
redhat CWE-79
6.1
2024-09-19 CVE-2024-8883 Open Redirect vulnerability in Redhat products
A misconfiguration flaw was found in Keycloak.
network
low complexity
redhat CWE-601
6.1