CVE-2023-25155
- EPSS 0.9%
- Veröffentlicht 02.03.2023 04:15:10
- Zuletzt bearbeitet 21.11.2024 07:49:12
Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SRANDMEMBER`, `ZRANDMEMBER`, and `HRANDFIELD` commands can trigger an integer overflow, resulting in a runtime assertion and termination of the Redis...
CVE-2022-36021
- EPSS 59.71%
- Veröffentlicht 01.03.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 07:12:12
Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like `SCAN` or `KEYS`) with a specially crafted pattern to trigger a denial-of-service attack on Redis, causing it to hang and consume 100% CP...
CVE-2023-22458
- EPSS 71.98%
- Veröffentlicht 20.01.2023 19:15:17
- Zuletzt bearbeitet 21.11.2024 07:44:50
Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affe...
CVE-2022-35977
- EPSS 13.45%
- Veröffentlicht 20.01.2023 19:15:14
- Zuletzt bearbeitet 03.11.2025 22:15:59
Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT(_RO)` commands can trigger an integer overflow, resulting with Redis attempting to allocate impossible amounts of memory and abor...
CVE-2022-3734
- EPSS 0.62%
- Veröffentlicht 28.10.2022 08:15:14
- Zuletzt bearbeitet 21.11.2024 07:20:07
A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Program Files/Redis/dbghelp.dll. The manipulation leads to uncontrolled search path. The attack can be i...
CVE-2022-3647
- EPSS 0.59%
- Veröffentlicht 21.10.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:19:57
** DISPUTED ** A vulnerability, which was classified as problematic, was found in Redis up to 6.2.7/7.0.5. Affected is the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial of service. The com...
CVE-2022-35951
- EPSS 3.01%
- Veröffentlicht 23.09.2022 04:15:11
- Zuletzt bearbeitet 21.11.2024 07:12:02
Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `XAUTOCLAIM` command on a stream key in a specific state, with a specially crafted `COUNT` argument may...
CVE-2022-31144
- EPSS 3.15%
- Veröffentlicht 19.07.2022 21:15:15
- Zuletzt bearbeitet 21.11.2024 07:03:59
Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch p...
CVE-2022-33105
- EPSS 3.13%
- Veröffentlicht 23.06.2022 17:15:14
- Zuletzt bearbeitet 21.11.2024 07:07:32
Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID.
CVE-2022-24736
- EPSS 1.5%
- Veröffentlicht 27.04.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:50:58
Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The ...