Search CVE reports


Toggle filters

41 – 50 of 86 results


CVE-2023-22458

Medium priority
Ignored

Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion...

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-35977

Medium priority

Some fixes available 5 of 7

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT(_RO)` commands can trigger an integer overflow, resulting with Redis attempting to allocate...

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Fixed Fixed Fixed
Show less packages

CVE-2022-3734

Medium priority
Ignored

A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Program Files/Redis/dbghelp.dll. The manipulation leads to uncontrolled search path....

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-3647

Medium priority
Ignored

** DISPUTED ** A vulnerability, which was classified as problematic, was found in Redis up to 6.2.7/7.0.5. Affected is the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial...

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-35951

Medium priority
Ignored

Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `XAUTOCLAIM` command on a stream key in a specific state, with a specially crafted...

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-31144

Medium priority
Ignored

Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions...

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-33105

Medium priority
Ignored

Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID.

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-24736

Medium priority
Vulnerable

Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the...

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2022-24735

Medium priority
Ignored

Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execute with...

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-0543

Medium priority
Fixed

It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

1 affected package

redis

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Fixed Not affected
Show less packages