Red Hat / Gluster Storage
25 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-44142 | samba: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution | CRITICAL | 9.9 | Feb 21, 2022 |
| CVE-2020-25717 | samba: Active Directory (AD) domain user could become root on domain members | HIGH | 8.1 | Feb 18, 2022 |
| CVE-2016-2124 | samba: SMB1 client connections can be downgraded to plaintext authentication | MEDIUM | 6.8 | Feb 18, 2022 |
| CVE-2020-10763 | heketi: gluster-block volume password details available in logs | MEDIUM | 5.5 | Nov 24, 2020 |
| CVE-2019-3880 | samba: save registry file outside share as unprivileged user | MEDIUM | 5.4 | Apr 9, 2019 |
| CVE-2019-3831 | vdsm: privilege escalation to root via systemd_run | MEDIUM | 6.7 | Mar 25, 2019 |
| CVE-2016-2125 | samba: Unconditional privilege delegation to Kerberos servers in trusted realms | MEDIUM | 6.5 | Oct 31, 2018 |
| CVE-2018-14654 | glusterfs: "features/index" translator can create arbitrary, empty files | MEDIUM | 6.5 | Oct 31, 2018 |
| CVE-2018-14653 | glusterfs: Heap-based buffer overflow via "gf_getspec_req" RPC message | HIGH | 8.8 | Oct 31, 2018 |
| CVE-2018-14652 | glusterfs: Buffer overflow in "features/locks" translator allows for denial of service | MEDIUM | 6.5 | Oct 31, 2018 |
| CVE-2018-1000808 | pyOpenSSL: Failure to release memory before removing last reference in PKCS #12 Store | HIGH | 8.2 | Oct 8, 2018 |
| CVE-2018-1127 | tendrl-api: Improper cleanup of session token can allow attackers to hijack user sessions | HIGH | 8.1 | Sep 11, 2018 |
| CVE-2018-10928 | glusterfs: Improper resolution of symlinks allows for privilege escalation | HIGH | 8.8 | Sep 4, 2018 |
| CVE-2017-12150 | samba: Some code path don't enforce smb signing, when they should | HIGH | 7.4 | Jul 26, 2018 |
| CVE-2017-12163 | Samba: Server memory information leak over SMB1 | HIGH | 7.1 | Jul 26, 2018 |
| CVE-2017-7481 | ansible: Security issue with lookup return not tainting the jinja2 environment | CRITICAL | 9.3 | Jul 19, 2018 |
| CVE-2018-10875 | ansible: ansible.cfg is being read from current working directory allowing possible code execution | HIGH | 8.5 | Jul 13, 2018 |
| CVE-2018-1088 | glusterfs: Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled | HIGH | 8.1 | Apr 18, 2018 |
| CVE-2017-15087 | samba: Server memory information leak over SMB1 (incomplete fix for CVE-2017-12163) | HIGH | 7.5 | Nov 8, 2017 |
| CVE-2017-15086 | samba: SMB2 connections don't keep encryption across DFS redirects (incomplete fix of CVE-2017-12151) | HIGH | 7.4 | Nov 8, 2017 |
| CVE-2017-15085 | samba: Some code path don't enforce smb signing, when they should (incomplete fix of CVE-2017-12150) | HIGH | 8.1 | Nov 8, 2017 |
| CVE-2015-1795 | glusterfs: glusterfs-server %pretrans rpm script temporary file issue | HIGH | 7.8 | Jun 27, 2017 |
| CVE-2015-5242 | swiftonfile: use of insecure Python pickle for metadata serialization and storage | MEDIUM | 6.0 | Nov 25, 2015 |
| CVE-2014-0160 KEV | openssl: information disclosure in handling of TLS heartbeat extension packets | HIGH | 7.5 | Apr 7, 2014 |
| CVE-2011-3045 | libpng: buffer overflow in png_inflate caused by invalid type conversions | HIGH | 8.8 | Mar 22, 2012 |
Showing 1 to 25 of 25 CVEs