Vulnerabilities > Redhat

DATE CVE VULNERABILITY TITLE RISK
2019-11-08 CVE-2019-10219 A vulnerability was found in Hibernate-Validator.
network
low complexity
redhat netapp oracle
6.1
2019-11-08 CVE-2013-1820 Improper Input Validation vulnerability in multiple products
tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.
local
low complexity
redhat fedoraproject CWE-20
5.5
2019-11-08 CVE-2008-5083 Information Exposure vulnerability in Redhat Jboss Operations Network 2.1.0/2.1.2
In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.
network
low complexity
redhat CWE-200
6.5
2019-11-07 CVE-2008-3278 Insecure Default Initialization of Resource vulnerability in Redhat Frysk 20080805
frysk packages through 2008-08-05 as shipped in Red Hat Enterprise Linux 5 are built with an insecure RPATH set in the ELF header of multiple binaries in /usr/bin/f* (e.g.
local
low complexity
redhat CWE-1188
7.8
2019-11-07 CVE-2019-18811 Memory Leak vulnerability in multiple products
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.
local
low complexity
linux fedoraproject redhat CWE-401
5.5
2019-11-07 CVE-2019-18805 Integer Overflow or Wraparound vulnerability in multiple products
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11.
network
low complexity
linux opensuse redhat netapp broadcom CWE-190
critical
9.8
2019-11-06 CVE-2016-1000037 Cross-site Scripting vulnerability in multiple products
Pagure: XSS possible in file attachment endpoint
network
low complexity
redhat fedoraproject CWE-79
6.1
2019-11-06 CVE-2014-8181 Improper Initialization vulnerability in Redhat Enterprise Linux and Enterprise MRG
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.
local
low complexity
redhat CWE-665
5.5
2019-11-05 CVE-2016-4983 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
local
low complexity
dovecot opensuse redhat CWE-732
3.3
2019-11-05 CVE-2013-5123 Improper Authentication vulnerability in multiple products
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
network
high complexity
pypa virtualenv fedoraproject redhat debian CWE-287
5.9