Search CVE reports


Toggle filters

41 – 50 of 74 results


CVE-2021-32765

Medium priority
Vulnerable

Hiredis is a minimalistic C client library for the Redis database. In affected versions Hiredis is vulnurable to integer overflow if provided maliciously crafted or corrupted `RESP` `mult-bulk` protocol data. When parsing...

1 affected package

hiredis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
hiredis Not affected Not affected Not affected Not affected
Show less packages

CVE-2021-32762

Negligible priority
Needs evaluation

Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to integer overflow when parsing specially crafted large multi-bulk network replies....

7 affected packages

discque, hiredis, nginx, python-hiredis, redis...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
discque Not in release Not in release Not in release Not in release
hiredis Not affected Not affected Not affected Not affected
nginx Not affected Not affected Not affected Not affected
python-hiredis Not affected Not affected Not affected Not affected
redis Not affected Not affected Not affected Not affected
rspamd Not affected Not affected Not affected Not in release
webdis Not affected Not affected Not affected Not in release
Show all 7 packages Show less packages

CVE-2021-32761

Medium priority

Some fixes available 4 of 5

Redis is an in-memory database that persists on disk. A vulnerability involving out-of-bounds read and integer overflow to buffer overflow exists starting with version 2.2 and prior to versions 5.0.13, 6.0.15, and 6.2.5. On 32-bit...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Fixed
Show less packages

CVE-2021-32687

Medium priority

Some fixes available 4 of 6

Redis is an open source, in-memory database that persists on disk. An integer overflow bug affecting all versions of Redis can be exploited to corrupt the heap and potentially be used to leak arbitrary contents of the heap or...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Fixed Fixed
Show less packages

CVE-2021-32675

Medium priority

Some fixes available 4 of 6

Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis Standard Protocol (RESP) request, Redis allocates memory according to user-specified values which determine the number of elements...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Fixed Fixed
Show less packages

CVE-2021-32672

Medium priority

Some fixes available 2 of 4

Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This issue...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Fixed Fixed
Show less packages

CVE-2021-32628

Medium priority

Some fixes available 4 of 6

Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the ziplist data structure used by all versions of Redis can be exploited to corrupt the heap and potentially result with remote code...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Fixed Fixed
Show less packages

CVE-2021-32627

Medium priority

Some fixes available 2 of 4

Redis is an open source, in-memory database that persists on disk. In affected versions an integer overflow bug in Redis can be exploited to corrupt the heap and potentially result with remote code execution. The vulnerability...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Fixed Fixed
Show less packages

CVE-2021-32626

Medium priority

Some fixes available 4 of 6

Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for this...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Fixed Fixed
Show less packages

CVE-2021-32625

Medium priority
Vulnerable

Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis version 6.0 or newer, could be exploited using the STRALGO LCS command to...

1 affected package

redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
redis Not affected Not affected Not affected Not affected
Show less packages