Vulnerabilities > Redhat

DATE CVE VULNERABILITY TITLE RISK
2018-08-16 CVE-2016-9598 Out-of-bounds Read vulnerability in multiple products
libxml2, as used in Red Hat JBoss Core Services, allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted XML document.
network
low complexity
redhat xmlsoft CWE-125
6.5
2018-08-16 CVE-2016-9596 Resource Exhaustion vulnerability in multiple products
libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a denial of service (stack consumption) via a crafted XML document.
network
low complexity
redhat xmlsoft CWE-400
6.5
2018-08-13 CVE-2018-10864 Unspecified vulnerability in Redhat Certification
An uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded.
local
low complexity
redhat
6.2
2018-08-13 CVE-2017-15138 Information Exposure vulnerability in Redhat Openshift Container Platform 3.9
The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook tokens.
network
low complexity
redhat CWE-200
5.0
2018-08-09 CVE-2018-10931 It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC.
network
low complexity
cobbler-project redhat
critical
9.8
2018-08-09 CVE-2018-10915 SQL Injection vulnerability in multiple products
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections.
network
high complexity
redhat canonical debian postgresql CWE-89
7.5
2018-08-09 CVE-2018-10908 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources.
local
low complexity
ovirt redhat CWE-770
6.3
2018-08-06 CVE-2018-5390 Resource Exhaustion vulnerability in multiple products
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
7.5
2018-08-02 CVE-2018-1336 Infinite Loop vulnerability in multiple products
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service.
network
low complexity
apache redhat debian canonical CWE-835
7.5
2018-08-01 CVE-2015-9262 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow.
network
low complexity
debian canonical x redhat CWE-119
critical
9.8