Vulnerabilities > Redhat > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-02-04 CVE-2022-0487 Use After Free vulnerability in multiple products
A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel.
local
low complexity
linux redhat debian CWE-416
5.5
2022-01-25 CVE-2021-4145 NULL Pointer Dereference vulnerability in multiple products
A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0.
local
low complexity
qemu redhat CWE-476
6.5
2022-01-13 CVE-2022-21682 Path Traversal vulnerability in multiple products
Flatpak is a Linux application sandboxing and distribution framework.
network
low complexity
flatpak fedoraproject redhat debian CWE-22
6.5
2021-12-23 CVE-2021-3622 Resource Exhaustion vulnerability in multiple products
A flaw was found in the hivex library.
network
low complexity
redhat fedoraproject CWE-400
4.3
2021-12-23 CVE-2021-4024 Origin Validation Error vulnerability in multiple products
A flaw was found in podman.
network
low complexity
podman-project fedoraproject redhat CWE-346
6.5
2021-12-16 CVE-2021-42550 Deserialization of Untrusted Data vulnerability in multiple products
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
network
high complexity
qos redhat netapp siemens CWE-502
6.6
2021-11-29 CVE-2021-3802 Improper Input Validation vulnerability in multiple products
A vulnerability found in udisks2.
local
low complexity
udisks-project fedoraproject redhat CWE-20
4.2
2021-11-23 CVE-2021-3672 Cross-site Scripting vulnerability in multiple products
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking.
5.6
2021-11-04 CVE-2021-43389 Out-of-bounds Read vulnerability in multiple products
An issue was discovered in the Linux kernel before 5.14.15.
local
low complexity
linux redhat debian oracle CWE-125
5.5
2021-10-19 CVE-2021-3746 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
A flaw was found in the libtpms code that may cause access beyond the boundary of internal buffers.
network
low complexity
libtpms-project fedoraproject redhat CWE-119
6.5