Vulnerabilities > Redhat > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-05-06 CVE-2021-3507 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including).
local
low complexity
qemu debian redhat CWE-119
6.1
2021-05-05 CVE-2021-20254 Out-of-bounds Read vulnerability in multiple products
A flaw was found in samba.
network
high complexity
samba fedoraproject redhat debian CWE-125
6.8
2021-04-19 CVE-2021-20208 Improper Privilege Management vulnerability in multiple products
A flaw was found in cifs-utils in versions before 6.13.
local
high complexity
samba redhat fedoraproject CWE-269
6.1
2021-04-19 CVE-2021-3505 Insufficient Entropy vulnerability in multiple products
A flaw was found in libtpms in versions before 0.8.0.
5.5
2021-04-08 CVE-2021-3482 Out-of-bounds Write vulnerability in multiple products
A flaw was found in Exiv2 in versions before and including 0.27.4-RC1.
network
low complexity
exiv2 redhat fedoraproject debian CWE-787
6.5
2021-04-08 CVE-2021-3448 A flaw was found in dnsmasq in versions before 2.85.
network
high complexity
thekelleys redhat fedoraproject oracle
4.0
2021-04-08 CVE-2021-3413 Information Exposure vulnerability in multiple products
A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0.
network
low complexity
theforeman redhat CWE-200
6.3
2021-04-01 CVE-2021-3447 Information Exposure Through Log Files vulnerability in multiple products
A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the controller node when run in verbose mode.
local
low complexity
redhat fedoraproject CWE-532
5.5
2021-04-01 CVE-2021-20291 Improper Locking vulnerability in multiple products
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1.
network
low complexity
storage-project redhat fedoraproject CWE-667
6.5
2021-04-01 CVE-2021-3393 Information Exposure Through an Error Message vulnerability in multiple products
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11.
network
low complexity
postgresql redhat CWE-209
4.3