Redhat
17,638 known vulnerabilities
Top Products
A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oV
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and inv
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the dif
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker ex
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable t
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib
JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressio
JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language
An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10,
openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificat
Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be
389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persisten
m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.
In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result
In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_ch
Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An att
routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which c
Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbi
Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbi
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues inclu
A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of d
It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a use
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of
Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects
Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thu
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks,
The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injec
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for th
A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a
A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This result
Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed eviden
A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerab
Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume tha
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parame
Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-s
When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially expl
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages
A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentiall
Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corrup
If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to sc
A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, res
A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This resul
A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potent
A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that h
A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script conte
A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is m
A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exp
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started