Search CVE reports


Toggle filters

51 – 60 of 74 results


CVE-2021-31294

Medium priority
Needs evaluation

Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command (specifically, a SET command). NOTE: this was fixed for Redis 6.2.x and 7.x in 2021. Versions before...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-29478

Low priority
Ignored

Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis 6.2 before 6.2.3 could be exploited to corrupt the heap and potentially result...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected
Show less packages

CVE-2021-29477

Medium priority
Ignored

Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis version 6.0 or newer could be exploited using the `STRALGO LCS` command to...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected
Show less packages

CVE-2021-29469

Medium priority
Needs evaluation

Node-redis is a Node.js Redis client. Before version 3.1.1, when a client is in monitoring mode, the regex begin used to detected monitor messages could cause exponential backtracking on some strings. This issue could lead to a...

1 affected package

node-redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-redis Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-21309

Medium priority

Some fixes available 2 of 3

Redis is an open-source, in-memory database that persists on disk. In affected versions of Redis an integer overflow bug in 32-bit Redis version 4.0 or newer could be exploited to corrupt the heap and potentially result with...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Fixed
Show less packages

CVE-2020-7105

Medium priority

Some fixes available 1 of 5

async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.

1 affected package

hiredis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
hiredis Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2020-21468

Negligible priority
Ignored

A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS). NOTE: the vendor cannot reproduce this issue in a released version, such as 5.0.7

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected Not affected
Show less packages

CVE-2020-14147

Medium priority
Vulnerable

An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Vulnerable Not affected
Show less packages

CVE-2019-10193

Medium priority
Fixed

A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected
Show less packages

CVE-2019-10192

Medium priority

Some fixes available 3 of 4

A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command,...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Fixed
Show less packages