Redhat
17,638 known vulnerabilities
Top Products
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at l
A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results i
Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corrup
RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects
Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affec
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprin
The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The r
A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" object has been free
Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corrup
A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. T
The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to beh
A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the
A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elemen
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing an
Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corrup
A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while stil
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the do
When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This re
A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these
A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where
A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the discon
The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page sour
A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still
A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely l
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary
Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes
A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a po
A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. Th
A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer h
Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed eviden
When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar.
An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while t
An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations. This vulnerability
An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data
A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages du
A use-after-free vulnerability with content viewer listeners that results in a potentially exploitable crash. This vulne
A use-after-free vulnerability during video control operations when a "<track>" element holds a reference to an older wi
A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This results in a potenti
A use-after-free vulnerability with the frameloader during tree reconstruction while regenerating CSS layout when attemp
Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corrup
Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affect
A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping
If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, trigger
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for other
During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessib
A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses
A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability
A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started