Vulnerability index

Browse CVEs

25 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Redisgraph CRITICAL 9.8
CVE-2023-47003

An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlock_ItemIsD…

No fix yet
Fix from $2,300 2023-11-16
Redisgraph HIGH 8.8
CVE-2023-47004

Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code via the c…

Fix: 2.12.9+
Fix from $1,950 2023-11-06
Redis HIGH 7.5
CVE-2020-21468

A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS). NOTE: the vendor cannot reproduce this issue in…

No fix yet
Fix from $1,950 2021-09-20
Redis HIGH 7.5
CVE-2021-32761EPSS 31%

Redis is an in-memory database that persists on disk. A vulnerability involving out-of-bounds read and integer overflow to buffer overflow exists sta…

Fix: 5.0.13 / 6.0.15+
Fix from $1,950 2021-07-21
Redis HIGH 8.8
CVE-2021-32625

Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Red…

Fix: 6.0.14 / 6.2.4+
Fix from $1,950 2021-06-02
Redis HIGH 8.8
CVE-2021-29477

Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Red…

Fix: 6.0.13 / 6.2.3+
Fix from $1,950 2021-05-04
Redis HIGH 8.8
CVE-2021-29478

Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Red…

Fix: 6.2.3+
Fix from $1,950 2021-05-04
Redis MEDIUM 5.3
CVE-2021-3470

A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemalloc or …

Fix: 5.0.10 / 6.0.9+
Fix from $1,600 2021-03-31
Redis HIGH 8.8
CVE-2021-21309

Redis is an open-source, in-memory database that persists on disk. In affected versions of Redis an integer overflow bug in 32-bit Redis version 4.0 …

Fix: 5.0.11 / 6.0.11+
Fix from $1,950 2021-02-26
Redisgraph HIGH 7.5
CVE-2020-35668

RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as an alias …

Fix: 2.2.11+
Fix from $1,950 2020-12-23
Redis HIGH 7.7
CVE-2020-14147

An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code i…

Fix: 5.0.9 / 6.0.3+
Fix from $1,950 2020-06-15
Hiredis HIGH 7.5
CVE-2020-7105

async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.

Fix: after 0.14.0
Fix from $1,950 2020-01-16
Redis MEDIUM 5.5
CVE-2013-0178

Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.

Fix: 2.6.0+
Fix from $1,600 2019-11-01
Redis MEDIUM 5.5
CVE-2013-0180

Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.

Patch available
Fix from $1,600 2019-11-01
Redis HIGH 7.2
CVE-2019-10192EPSS 26%

A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5…

Fix: 3.2.13 / 4.0.14+
Fix from $1,950 2019-07-11
Redis HIGH 7.2
CVE-2019-10193EPSS 24%

A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before …

Fix: 3.2.13 / 4.0.14+
Fix from $1,950 2019-07-11
Redis CRITICAL 9.8
CVE-2018-11218EPSS 59%

Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 becau…

Fix: 3.2.12 / 4.0.10+
Fix from $2,300 2018-06-17
Redis CRITICAL 9.8
CVE-2018-11219EPSS 7%

An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2…

Fix: 3.2.12 / 4.0.10+
Fix from $2,300 2018-06-17
Redis HIGH 8.4
CVE-2018-12326

Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privil…

Fix: 4.0.10+
Fix from $1,950 2018-06-17
Redis HIGH 7.5
CVE-2018-12453EPSS 24%

Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via…

Fix: 5.0+
Fix from $1,950 2018-06-16
Redis HIGH 7.4
CVE-2016-10517

networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the …

Fix: 3.2.7+
Fix from $1,950 2017-10-24
Redis CRITICAL 9.8
CVE-2017-15047

The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and application c…

Patch available
Fix from $2,300 2017-10-06
Redis CRITICAL 9.8
CVE-2016-8339EPSS 15%

A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability …

Patch available
Fix from $2,300 2016-10-28
Redis HIGH 7.5
CVE-2015-8080

Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with p…

Fix: 2.8.24 / 3.0.6+
Fix from $1,950 2016-04-13
Redis HIGH 10.0
CVE-2015-4335EPSS 10%

Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.

Fix: after 2.8.20
Fix from $1,950 2015-06-09