Vulnerabilities > Redhat

DATE CVE VULNERABILITY TITLE RISK
2018-07-25 CVE-2018-1002200 Path Traversal vulnerability in multiple products
plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction.
local
low complexity
codehaus-plexus redhat debian CWE-22
5.5
2018-07-25 CVE-2018-10880 Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a crafted ext4 image in ext4_update_inline_data().
local
low complexity
debian linux redhat canonical
5.5
2018-07-24 CVE-2018-10906 Improper Privilege Management vulnerability in multiple products
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active.
local
low complexity
debian fuse-project redhat CWE-269
7.8
2018-07-24 CVE-2017-3224 Insufficient Verification of Data Authenticity vulnerability in multiple products
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber.
high complexity
quagga suse redhat CWE-345
8.2
2018-07-24 CVE-2018-10905 OS Command Injection vulnerability in Redhat Cloudforms and Cloudforms Management Engine
CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms.
local
low complexity
redhat CWE-78
7.8
2018-07-23 CVE-2018-10912 Infinite Loop vulnerability in Redhat Keycloak
keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement.
network
low complexity
redhat CWE-835
4.9
2018-07-20 CVE-2018-5008 Out-of-bounds Read vulnerability in multiple products
Adobe Flash Player 30.0.0.113 and earlier versions have an Out-of-bounds read vulnerability.
network
low complexity
adobe redhat CWE-125
7.5
2018-07-20 CVE-2018-5007 Incorrect Type Conversion or Cast vulnerability in multiple products
Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability.
network
low complexity
adobe redhat CWE-704
8.8
2018-07-19 CVE-2018-10870 Improper Input Validation vulnerability in Redhat Certification
redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile.
network
low complexity
redhat CWE-20
critical
9.8
2018-07-19 CVE-2018-10869 Unspecified vulnerability in Redhat Certification and Enterprise Linux
redhat-certification does not properly restrict files that can be download through the /download page.
network
low complexity
redhat
7.5