Vulnerabilities > Redhat

DATE CVE VULNERABILITY TITLE RISK
2024-06-06 CVE-2024-3049 A flaw was found in Booth, a cluster ticket manager.
network
high complexity
clusterlabs redhat
5.9
2024-06-05 CVE-2024-5037 Unspecified vulnerability in Redhat products
A flaw was found in OpenShift's Telemeter.
network
low complexity
redhat
7.5
2024-06-05 CVE-2024-3716 Unspecified vulnerability in Redhat Satellite 6.0
A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter.
local
low complexity
redhat
6.2
2024-06-05 CVE-2024-4812 A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Description" field of a user.
network
low complexity
redhat katello-project
4.8
2024-04-10 CVE-2024-3567 A flaw was found in QEMU.
local
low complexity
qemu redhat
5.5
2024-02-22 CVE-2023-52160 Improper Authentication vulnerability in multiple products
The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass.
network
low complexity
debian redhat fedoraproject w1-fi CWE-287
6.5
2024-02-14 CVE-2023-50387 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue.
7.5
2024-02-14 CVE-2024-1485 Path Traversal vulnerability in multiple products
A flaw was found in the decompression function of registry-support.
network
low complexity
redhat devfile CWE-22
critical
9.3
2024-02-12 CVE-2024-1454 The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. 3.4
2024-02-12 CVE-2024-1459 Unspecified vulnerability in Redhat Undertow
A path traversal vulnerability was found in Undertow.
network
low complexity
redhat
5.3