Redhat

Openshift Container Platform

272 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 28.07.2025 18:16:07
  • Zuletzt bearbeitet 11.08.2025 19:03:36

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a co...

  • EPSS 0.02%
  • Veröffentlicht 14.07.2025 13:35:21
  • Zuletzt bearbeitet 11.08.2025 19:20:21

A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. T...

  • EPSS 0.06%
  • Veröffentlicht 10.07.2025 14:05:41
  • Zuletzt bearbeitet 27.08.2025 18:00:52

A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt m...

  • EPSS 0.1%
  • Veröffentlicht 10.07.2025 09:41:46
  • Zuletzt bearbeitet 07.10.2025 12:15:44

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an out-of-bounds (OOB) NULL point...

  • EPSS 0.03%
  • Veröffentlicht 10.07.2025 08:05:26
  • Zuletzt bearbeitet 06.10.2025 12:15:33

A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate cont...

  • EPSS 0.1%
  • Veröffentlicht 10.07.2025 08:04:57
  • Zuletzt bearbeitet 07.10.2025 12:15:43

A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS wil...

  • EPSS 0.04%
  • Veröffentlicht 04.07.2025 08:16:47
  • Zuletzt bearbeitet 22.08.2025 13:50:58

A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading t...

  • EPSS 0.06%
  • Veröffentlicht 04.07.2025 06:01:27
  • Zuletzt bearbeitet 22.08.2025 14:01:21

A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and li...

  • EPSS 0.06%
  • Veröffentlicht 24.06.2025 14:15:30
  • Zuletzt bearbeitet 22.09.2025 20:15:39

A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and t...

  • EPSS 0.02%
  • Veröffentlicht 16.06.2025 15:24:05
  • Zuletzt bearbeitet 12.08.2025 13:04:06

A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow...