Search CVE reports


Toggle filters

21 – 30 of 74 results


CVE-2023-28859

Medium priority
Vulnerable

redis-py before 4.4.4 and 4.5.x before 4.5.4 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request. (This could, for example,...

1 affected package

python-redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-redis Vulnerable Not affected Not affected Not affected
Show less packages

CVE-2023-28858

Medium priority
Vulnerable

redis-py before 4.5.3 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request in an off-by-one manner. NOTE: this CVE Record was...

1 affected package

python-redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-redis Vulnerable Not affected Not affected Not affected
Show less packages

CVE-2023-28856

Medium priority

Some fixes available 5 of 7

Redis is an open source, in-memory database that persists on disk. Authenticated users can use the `HINCRBYFLOAT` command to create an invalid hash field that will crash Redis on access in affected versions. This issue has been...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-28425

Medium priority
Ignored

Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX command to trigger a runtime assertion and termination of the Redis...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-25155

Medium priority

Some fixes available 5 of 7

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SRANDMEMBER`, `ZRANDMEMBER`, and `HRANDFIELD` commands can trigger an integer overflow, resulting in a runtime assertion and...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-22458

Medium priority
Ignored

Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-3734

Medium priority
Ignored

A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Program Files/Redis/dbghelp.dll. The manipulation leads to uncontrolled search path....

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-3647

Medium priority
Ignored

** DISPUTED ** A vulnerability, which was classified as problematic, was found in Redis up to 6.2.7/7.0.5. Affected is the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-36021

Medium priority

Some fixes available 5 of 7

Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like `SCAN` or `KEYS`) with a specially crafted pattern to trigger a denial-of-service attack on Redis, causing it to hang...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Fixed Fixed Fixed
Show less packages

CVE-2022-35977

Medium priority

Some fixes available 5 of 7

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT(_RO)` commands can trigger an integer overflow, resulting with Redis attempting to allocate...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Fixed Fixed Fixed
Show less packages