📦 Software Collections

by Redhat

🔍 What is Software Collections?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-5869

HIGH CVSS 8.8 Dec 10, 2023

This CVE-2023-5869 vulnerability in PostgreSQL allows authenticated database users to execute arbitrary code on the server through an integer overflow when modifying SQL arrays. Attackers can write ar...

CVE-2023-39417

HIGH CVSS 7.5 Aug 11, 2023

This SQL injection vulnerability in PostgreSQL allows attackers with database-level CREATE privilege to execute arbitrary code as the bootstrap superuser when exploiting improperly quoted extension sc...

CVE-2023-2454

HIGH CVSS 7.2 Jun 9, 2023

CVE-2023-2454 is a PostgreSQL vulnerability where the schema_element function can bypass protective search_path changes, allowing authenticated attackers with elevated database privileges to execute a...

CVE-2022-4904

HIGH CVSS 8.6 Mar 6, 2023

CVE-2022-4904 is a stack buffer overflow vulnerability in the c-ares DNS library's ares_set_sortlist function. Attackers can trigger denial of service or potentially execute arbitrary code by providin...

CVE-2021-3656

HIGH CVSS 8.8 Mar 4, 2022

This vulnerability in KVM's AMD SVM nested virtualization allows a malicious L1 guest to disable security intercepts for L2 guests, potentially enabling L2 guests to read/write host physical memory. T...

CVE-2021-23214

HIGH CVSS 8.1 Mar 4, 2022

CVE-2021-23214 is a SQL injection vulnerability in PostgreSQL that allows man-in-the-middle attackers to inject arbitrary SQL queries during initial connection establishment, even when SSL certificate...

CVE-2022-0711

HIGH CVSS 7.5 Mar 2, 2022

CVE-2022-0711 is a denial-of-service vulnerability in HAProxy where specially crafted HTTP responses containing Set-Cookie2 headers can trigger an infinite loop, causing the service to become unrespon...

CVE-2021-41819

HIGH CVSS 7.5 Jan 1, 2022

This vulnerability in Ruby's CGI::Cookie.parse function mishandles security prefixes in cookie names, allowing attackers to bypass cookie security mechanisms. It affects Ruby versions through 2.6.8 an...

CVE-2021-41817

HIGH CVSS 7.5 Jan 1, 2022

CVE-2021-41817 is a regular expression denial of service (ReDoS) vulnerability in Ruby's date gem. Attackers can cause denial of service by sending specially crafted long strings to Date.parse methods...

CVE-2021-4104

HIGH CVSS 7.5 Dec 14, 2021

CVE-2021-4104 is a deserialization vulnerability in Log4j 1.2's JMSAppender that allows remote code execution when attackers can modify Log4j configuration files. This affects systems running Log4j 1....

CVE-2021-20270

HIGH CVSS 7.5 Mar 23, 2021

This vulnerability in Pygments' SMLLexer causes an infinite loop when processing Standard ML source files containing only the 'exception' keyword, leading to denial of service. It affects systems usin...

CVE-2023-0056

MEDIUM CVSS 6.5 Mar 23, 2023

An uncontrolled resource consumption vulnerability in HAProxy could allow an authenticated remote attacker to crash the service by running a specially crafted malicious server in an OpenShift cluster....