Redislabs
Redislabs Redis: vulnerabilidades y CVE
Redislabs Redis tiene 22 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-21468 | Alta (7.5) | 1.2% | — | 20 sept 2021 | A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS). NOTE: the vendor cannot reproduce this issue in a released version, such as 5.0.7. |
| CVE-2021-32761 | Alta (7.5) | 38% | — | 21 jul 2021 | Redis is an in-memory database that persists on disk. A vulnerability involving out-of-bounds read and integer overflow to buffer overflow exists starting with version 2.2 and prior to versions 5.0.13, 6.0.15, and… |
| CVE-2021-32625 | Alta (8.8) | 4.1% | — | 2 jun 2021 | Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis version 6.0 or newer, could be exploited using the STRALGO LCS… |
| CVE-2021-29478 | Alta (8.8) | 3.6% | — | 4 may 2021 | Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis 6.2 before 6.2.3 could be exploited to corrupt the heap and… |
| CVE-2021-29477 | Alta (8.8) | 4.0% | — | 4 may 2021 | Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis version 6.0 or newer could be exploited using the `STRALGO LCS`… |
| CVE-2021-3470 | Media (5.3) | 1.1% | — | 31 mar 2021 | A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemalloc or glibc's malloc, leading to potential out of bound write or process… |
| CVE-2021-21309 | Alta (8.8) | 4.8% | — | 26 feb 2021 | Redis is an open-source, in-memory database that persists on disk. In affected versions of Redis an integer overflow bug in 32-bit Redis version 4.0 or newer could be exploited to corrupt the heap and potentially result… |
| CVE-2020-14147 | Alta (7.7) | 3.1% | — | 15 jun 2020 | An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and… |
| CVE-2013-0180 | Media (5.5) | 0.32% | — | 1 nov 2019 | Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds. |
| CVE-2013-0178 | Media (5.5) | 0.41% | — | 1 nov 2019 | Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm. |
| CVE-2019-10193 | Alta (7.2) | 24% | — | 11 jul 2019 | A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an… |
| CVE-2019-10192 | Alta (7.2) | 26% | — | 11 jul 2019 | A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE… |
| CVE-2018-11219 | Crítica (9.8) | 7.0% | — | 17 jun 2018 | An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking. |
| CVE-2018-11218 | Crítica (9.8) | 59% | — | 17 jun 2018 | Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows. |
| CVE-2018-12326 | Alta (8.4) | 2.7% | — | 17 jun 2018 | Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command line. NOTE: It is unclear whether there are… |
| CVE-2018-12453 | Alta (7.5) | 24% | — | 16 jun 2018 | Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via an XGROUP command in which the key is not a stream. |
| CVE-2016-10517 | Alta (7.4) | 2.1% | — | 24 oct 2017 | networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP… |
| CVE-2017-15047 | Crítica (9.8) | 1.8% | — | 6 oct 2017 | The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and application crash) or possibly have unspecified other impact by leveraging "limited… |
| CVE-2016-8339 | Crítica (9.8) | 15% | — | 28 oct 2016 | A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the client-output-buffer-limit option during… |
| CVE-2013-7458 | Baja (3.3) | 0.48% | — | 10 ago 2016 | linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file. |
| CVE-2015-8080 | Alta (7.5) | 4.6% | — | 13 abr 2016 | Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of… |
| CVE-2015-4335 | Alta (10) | 9.5% | — | 9 jun 2015 | Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command. |