redislabs records
26 published records for vendor redislabs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 3.8%
- Pre-auth RCE
- 3
- With a fix record
- 80.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-190 Integer Overflow or Wraparound6
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-476 NULL Pointer Dereference3
- CWE-787 Out-of-bounds Write3
- CWE-20 Improper Input Validation2
- CWE-121 Stack-based Buffer Overflow1
The weakness classes this vendor ships most often: where to look.
CWEAll records
26 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2018-11218Weaponized | Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 redislabs · redis · CWE-787 | Critical9.8 | — | 59.0% | Jun 17, 2018 |
43Plan | CVE-2016-8339No exploit | A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent.redislabs · redis · CWE-787 | Critical9.8 | — | 14.8% | Oct 28, 2016 |
43Plan | CVE-2015-4335No exploit | Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.redislabs · redis · CWE-17 | Critical10.0 | — | 9.5% | Jun 9, 2015 |
41Plan | CVE-2018-11219No exploit | An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x beforredislabs · redis · CWE-190 | Critical9.8 | — | 7.0% | Jun 17, 2018 |
40Plan | CVE-2017-15047No exploit | The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and applredislabs · redis · CWE-119 | Critical9.8 | — | 1.8% | Oct 6, 2017 |
39Monitor | CVE-2021-32761No exploit | Integer overflow issues with *BIT commands on 32-bit systemsredislabs · redis · CWE-125 | High7.5 | — | 31.2% | Jul 21, 2021 |
39Monitor | CVE-2023-47003No exploit | An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlocredislabs · redisgraph · CWE-476 | Critical9.8 | — | 1.1% | Nov 16, 2023 |
37Monitor | CVE-2018-12453Proof of concept | Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-seredislabs · redis · CWE-704 | High7.5 | — | 23.9% | Jun 16, 2018 |
36Monitor | CVE-2019-10192No exploit | A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.xredislabs · redis · CWE-122 | High7.2 | — | 26.0% | Jul 11, 2019 |
36Monitor | CVE-2021-21309No exploit | Integer overflow on 32-bit systemsredislabs · redis · CWE-190 | High8.8 | — | 4.8% | Feb 26, 2021 |
36Monitor | CVE-2021-32625No exploit | Redis vulnerability in STRALGO LCS on 32-bit systemsredislabs · redis · CWE-680 | High8.8 | — | 4.1% | Jun 2, 2021 |
36Monitor | CVE-2021-29477No exploit | Vulnerability in the STRALGO LCS commandredislabs · redis · CWE-190 | High8.8 | — | 4.0% | May 4, 2021 |
36Monitor | CVE-2021-29478No exploit | Vulnerability in the COPY command for large intsetsredislabs · redis · CWE-190 | High8.8 | — | 3.6% | May 4, 2021 |
35Monitor | CVE-2019-10193No exploit | A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.redislabs · redis · CWE-121 | High7.2 | — | 23.7% | Jul 11, 2019 |
35Monitor | CVE-2023-47004No exploit | Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code redislabs · redisgraph · CWE-787 | High8.8 | — | 1.0% | Nov 6, 2023 |
34Monitor | CVE-2018-12326Proof of concept | Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to highredislabs · redis · CWE-119 | High8.4 | — | 2.7% | Jun 17, 2018 |
31Monitor | CVE-2015-8080No exploit | Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackeredislabs · redis · CWE-190 | High7.5 | — | 4.6% | Apr 13, 2016 |
31Monitor | CVE-2020-14147No exploit | An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lredislabs · redis · CWE-190 | High7.7 | — | 3.1% | Jun 15, 2020 |
31Monitor | CVE-2020-7105No exploit | async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.redislabs · hiredis · CWE-476 | High7.5 | — | 2.7% | Jan 16, 2020 |
30Monitor | CVE-2016-10517No exploit | networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valiredislabs · redis · CWE-254 | High7.4 | — | 2.1% | Oct 24, 2017 |
30Monitor | CVE-2020-35668No exploit | RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as redislabs · redisgraph · CWE-476 | High7.5 | — | 1.6% | Dec 23, 2020 |
30Monitor | CVE-2020-21468No exploit | A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS).redislabs · redis | High7.5 | — | 1.2% | Sep 20, 2021 |
22Monitor | CVE-2013-0178No exploit | Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.redislabs · redis · CWE-20 | Medium5.5 | — | 0.4% | Nov 1, 2019 |
22Monitor | CVE-2013-0180No exploit | Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.redislabs · redis · CWE-20 | Medium5.5 | — | 0.3% | Nov 1, 2019 |
21Monitor | CVE-2021-3470No exploit | A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemredislabs · redis · CWE-119 | Medium5.3 | — | 1.1% | Mar 31, 2021 |
- CVE-2018-1121857Plan
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0
CriticalCVSS 9.8WeaponizedEPSS 59%redislabs · redisJun 17, 2018
- CVE-2016-833943Plan
A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent.
CriticalCVSS 9.8No exploitEPSS 15%redislabs · redisOct 28, 2016
- CVE-2015-433543Plan
Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.
CriticalCVSS 10.0No exploitEPSS 9%redislabs · redisJun 9, 2015
- CVE-2018-1121941Plan
An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x befor
CriticalCVSS 9.8No exploitEPSS 7%redislabs · redisJun 17, 2018
- CVE-2017-1504740Plan
The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and appl
CriticalCVSS 9.8No exploitEPSS 2%redislabs · redisOct 6, 2017
- CVE-2021-3276139Monitor
Integer overflow issues with *BIT commands on 32-bit systems
HighCVSS 7.5No exploitEPSS 31%redislabs · redisJul 21, 2021
- CVE-2023-4700339Monitor
An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBloc
CriticalCVSS 9.8No exploitEPSS 1%redislabs · redisgraphNov 16, 2023
- CVE-2018-1245337Monitor
Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-se
HighCVSS 7.5Proof of conceptEPSS 24%redislabs · redisJun 16, 2018
- CVE-2019-1019236Monitor
A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x
HighCVSS 7.2No exploitEPSS 26%redislabs · redisJul 11, 2019
- CVE-2021-2130936Monitor
Integer overflow on 32-bit systems
HighCVSS 8.8No exploitEPSS 5%redislabs · redisFeb 26, 2021
- CVE-2021-3262536Monitor
Redis vulnerability in STRALGO LCS on 32-bit systems
HighCVSS 8.8No exploitEPSS 4%redislabs · redisJun 2, 2021
- CVE-2021-2947736Monitor
Vulnerability in the STRALGO LCS command
HighCVSS 8.8No exploitEPSS 4%redislabs · redisMay 4, 2021
- CVE-2021-2947836Monitor
Vulnerability in the COPY command for large intsets
HighCVSS 8.8No exploitEPSS 4%redislabs · redisMay 4, 2021
- CVE-2019-1019335Monitor
A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.
HighCVSS 7.2No exploitEPSS 24%redislabs · redisJul 11, 2019
- CVE-2023-4700435Monitor
Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code
HighCVSS 8.8No exploitEPSS 1%redislabs · redisgraphNov 6, 2023
- CVE-2018-1232634Monitor
Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to high
HighCVSS 8.4Proof of conceptEPSS 3%redislabs · redisJun 17, 2018
- CVE-2015-808031Monitor
Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attacke
HighCVSS 7.5No exploitEPSS 5%redislabs · redisApr 13, 2016
- CVE-2020-1414731Monitor
An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run L
HighCVSS 7.7No exploitEPSS 3%redislabs · redisJun 15, 2020
- CVE-2020-710531Monitor
async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.
HighCVSS 7.5No exploitEPSS 3%redislabs · hiredisJan 16, 2020
- CVE-2016-1051730Monitor
networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not vali
HighCVSS 7.4No exploitEPSS 2%redislabs · redisOct 24, 2017
- CVE-2020-3566830Monitor
RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as
HighCVSS 7.5No exploitEPSS 2%redislabs · redisgraphDec 23, 2020
- CVE-2020-2146830Monitor
A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS).
HighCVSS 7.5No exploitEPSS 1%redislabs · redisSep 20, 2021
- CVE-2013-017822Monitor
Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.
MediumCVSS 5.5No exploitEPSS 0%redislabs · redisNov 1, 2019
- CVE-2013-018022Monitor
Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.
MediumCVSS 5.5No exploitEPSS 0%redislabs · redisNov 1, 2019
- CVE-2021-347021Monitor
A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jem
MediumCVSS 5.3No exploitEPSS 1%redislabs · redisMar 31, 2021