Vulnerabilities > Redhat > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-02-11 CVE-2022-0561 NULL Pointer Dereference vulnerability in multiple products
Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file.
5.5
2022-02-09 CVE-2022-0529 Out-of-bounds Write vulnerability in multiple products
A flaw was found in Unzip.
5.5
2022-02-09 CVE-2022-0530 A flaw was found in Unzip. 5.5
2022-02-09 CVE-2022-0532 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier.
network
high complexity
kubernetes redhat CWE-732
4.2
2022-02-04 CVE-2022-0487 Use After Free vulnerability in multiple products
A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel.
local
low complexity
linux redhat debian CWE-416
5.5
2022-01-25 CVE-2021-4145 NULL Pointer Dereference vulnerability in multiple products
A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0.
local
low complexity
qemu redhat CWE-476
6.5
2022-01-13 CVE-2022-21682 Path Traversal vulnerability in multiple products
Flatpak is a Linux application sandboxing and distribution framework.
network
low complexity
flatpak fedoraproject redhat debian CWE-22
6.5
2021-12-23 CVE-2021-3622 A flaw was found in the hivex library.
network
low complexity
redhat fedoraproject
4.3
2021-12-23 CVE-2021-4024 Origin Validation Error vulnerability in multiple products
A flaw was found in podman.
network
low complexity
podman-project fedoraproject redhat CWE-346
6.5
2021-12-16 CVE-2021-42550 Deserialization of Untrusted Data vulnerability in multiple products
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
network
high complexity
qos redhat netapp siemens CWE-502
6.6