Redis Labs Redis vulnerabilities
4 known vulnerabilities affecting redis_labs/redis.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2013-0178MEDIUMCVSS 5.5vbefore 2.62019-11-01
CVE-2013-0178 [MEDIUM] CWE-20 CVE-2013-0178: Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.
Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.
cvelistv5nvd
CVE-2013-0180MEDIUMCVSS 5.5v2.62019-11-01
CVE-2013-0180 [MEDIUM] CWE-20 CVE-2013-0180: Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.
Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.
cvelistv5nvd
CVE-2019-10192HIGHCVSS 7.2v3.x before 3.2.13v4.x before 4.0.14+1 more2019-07-11
CVE-2019-10192 [HIGH] CWE-122 CVE-2019-10192: A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x
A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command, an attacker could trick Redis interpretation of dense HLL encoding to write up to 3 bytes beyond the end of a heap-allocated buffer.
cvelistv5nvd
CVE-2019-10193HIGHCVSS 7.2v3.x before 3.2.13v4.x before 4.0.14+1 more2019-07-11
CVE-2019-10193 [HIGH] CWE-121 CVE-2019-10193: A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x
A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could cause Redis to perform controlled increments of up to 12 bytes past the end of a stack-allocated buffer.
cvelistv5nvd