Redis

Redis

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 35.55%
  • Veröffentlicht 20.01.2023 19:15:14
  • Zuletzt bearbeitet 03.11.2025 22:15:59

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT(_RO)` commands can trigger an integer overflow, resulting with Redis attempting to allocate impossible amounts of memory and abor...

  • EPSS 0.49%
  • Veröffentlicht 28.10.2022 08:15:14
  • Zuletzt bearbeitet 21.11.2024 07:20:07

A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Program Files/Redis/dbghelp.dll. The manipulation leads to uncontrolled search path. The attack can be i...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 21.10.2022 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:19:57

** DISPUTED ** A vulnerability, which was classified as problematic, was found in Redis up to 6.2.7/7.0.5. Affected is the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial of service. The com...

  • EPSS 36.94%
  • Veröffentlicht 23.09.2022 04:15:11
  • Zuletzt bearbeitet 21.11.2024 07:12:02

Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `XAUTOCLAIM` command on a stream key in a specific state, with a specially crafted `COUNT` argument may...

  • EPSS 21.25%
  • Veröffentlicht 19.07.2022 21:15:15
  • Zuletzt bearbeitet 21.11.2024 07:03:59

Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch p...

Exploit
  • EPSS 2.85%
  • Veröffentlicht 23.06.2022 17:15:14
  • Zuletzt bearbeitet 21.11.2024 07:07:32

Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID.

Exploit
  • EPSS 1.73%
  • Veröffentlicht 27.04.2022 20:15:09
  • Zuletzt bearbeitet 21.11.2024 06:50:58

Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The ...

Exploit
  • EPSS 1.68%
  • Veröffentlicht 27.04.2022 20:15:09
  • Zuletzt bearbeitet 21.11.2024 06:50:58

Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execute with the (potentially highe...

Warnung Exploit
  • EPSS 94.4%
  • Veröffentlicht 18.02.2022 20:15:17
  • Zuletzt bearbeitet 10.11.2025 14:44:23

It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

  • EPSS 0.4%
  • Veröffentlicht 04.10.2021 18:15:09
  • Zuletzt bearbeitet 21.11.2024 06:25:27

Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the underlying string library can be used to corrupt the heap and potentially result with denial of service or remote code execution. The vulnerability invo...