Redhat

Openshift Container Platform

272 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Published 28.07.2025 18:16:07
  • Last modified 11.08.2025 19:03:36

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a co...

  • EPSS 0.02%
  • Published 14.07.2025 13:35:21
  • Last modified 11.08.2025 19:20:21

A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. T...

  • EPSS 0.06%
  • Published 10.07.2025 14:05:41
  • Last modified 27.08.2025 18:00:52

A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt m...

  • EPSS 0.1%
  • Published 10.07.2025 09:41:46
  • Last modified 06.10.2025 12:15:33

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL point...

  • EPSS 0.03%
  • Published 10.07.2025 08:05:26
  • Last modified 06.10.2025 12:15:33

A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate cont...

  • EPSS 0.1%
  • Published 10.07.2025 08:04:57
  • Last modified 06.10.2025 12:15:33

A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS wil...

  • EPSS 0.04%
  • Published 04.07.2025 08:16:47
  • Last modified 22.08.2025 13:50:58

A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading t...

  • EPSS 0.06%
  • Published 04.07.2025 06:01:27
  • Last modified 22.08.2025 14:01:21

A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and li...

  • EPSS 0.06%
  • Published 24.06.2025 14:15:30
  • Last modified 22.09.2025 20:15:39

A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and t...

  • EPSS 0.02%
  • Published 16.06.2025 15:24:05
  • Last modified 12.08.2025 13:04:06

A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow...