Vulnerabilities > Redhat > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-03-08 CVE-2020-27838 Improper Authentication vulnerability in Redhat Keycloak and Single Sign-On
A flaw was found in keycloak in versions prior to 13.0.0.
network
low complexity
redhat CWE-287
6.5
2021-03-04 CVE-2020-25639 NULL Pointer Dereference vulnerability in multiple products
A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC.
local
low complexity
linux fedoraproject redhat CWE-476
4.4
2021-03-03 CVE-2021-20225 Out-of-bounds Write vulnerability in multiple products
A flaw was found in grub2 in versions prior to 2.06.
local
low complexity
gnu redhat fedoraproject netapp CWE-787
6.7
2021-03-03 CVE-2020-27749 Stack-based Buffer Overflow vulnerability in multiple products
A flaw was found in grub2 in versions prior to 2.06.
local
low complexity
gnu redhat fedoraproject netapp CWE-121
6.7
2021-02-23 CVE-2021-20256 Information Exposure vulnerability in Redhat Satellite 6.0
A flaw was found in Red Hat Satellite.
local
low complexity
redhat CWE-200
5.3
2021-02-23 CVE-2021-20252 Improper Input Validation vulnerability in Redhat 3Scale API Management 2.0
A flaw was found in Red Hat 3scale API Management Platform 2.
network
low complexity
redhat CWE-20
6.5
2021-02-23 CVE-2021-20229 Incorrect Authorization vulnerability in multiple products
A flaw was found in PostgreSQL in versions before 13.2.
network
low complexity
postgresql redhat fedoraproject CWE-863
4.3
2021-02-23 CVE-2021-20220 HTTP Request Smuggling vulnerability in multiple products
A flaw was found in Undertow.
network
high complexity
redhat netapp CWE-444
4.8
2021-01-29 CVE-2019-25014 NULL Pointer Dereference vulnerability in multiple products
A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0.
network
low complexity
istio redhat CWE-476
6.5
2021-01-28 CVE-2020-1725 Incorrect Authorization vulnerability in Redhat Keycloak
A flaw was found in keycloak before version 13.0.0.
network
low complexity
redhat CWE-863
5.4