Skip to content
Noroxi

redislabs records

26 published records for vendor redislabs.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 3.8%
Pre-auth RCE
3
With a fix record
80.8%
Median publish → KEV
No record has entered KEV

All records

26 records
  • Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0

    CriticalCVSS 9.8WeaponizedEPSS 59%

    redislabs · redisJun 17, 2018

  • A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent.

    CriticalCVSS 9.8No exploitEPSS 15%

    redislabs · redisOct 28, 2016

  • Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.

    CriticalCVSS 10.0No exploitEPSS 9%

    redislabs · redisJun 9, 2015

  • An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x befor

    CriticalCVSS 9.8No exploitEPSS 7%

    redislabs · redisJun 17, 2018

  • The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and appl

    CriticalCVSS 9.8No exploitEPSS 2%

    redislabs · redisOct 6, 2017

  • Integer overflow issues with *BIT commands on 32-bit systems

    HighCVSS 7.5No exploitEPSS 31%

    redislabs · redisJul 21, 2021

  • An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBloc

    CriticalCVSS 9.8No exploitEPSS 1%

    redislabs · redisgraphNov 16, 2023

  • Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-se

    HighCVSS 7.5Proof of conceptEPSS 24%

    redislabs · redisJun 16, 2018

  • A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x

    HighCVSS 7.2No exploitEPSS 26%

    redislabs · redisJul 11, 2019

  • Integer overflow on 32-bit systems

    HighCVSS 8.8No exploitEPSS 5%

    redislabs · redisFeb 26, 2021

  • Redis vulnerability in STRALGO LCS on 32-bit systems

    HighCVSS 8.8No exploitEPSS 4%

    redislabs · redisJun 2, 2021

  • Vulnerability in the STRALGO LCS command

    HighCVSS 8.8No exploitEPSS 4%

    redislabs · redisMay 4, 2021

  • Vulnerability in the COPY command for large intsets

    HighCVSS 8.8No exploitEPSS 4%

    redislabs · redisMay 4, 2021

  • A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.

    HighCVSS 7.2No exploitEPSS 24%

    redislabs · redisJul 11, 2019

  • Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code

    HighCVSS 8.8No exploitEPSS 1%

    redislabs · redisgraphNov 6, 2023

  • Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to high

    HighCVSS 8.4Proof of conceptEPSS 3%

    redislabs · redisJun 17, 2018

  • CVE-2015-8080
    31Monitor

    Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attacke

    HighCVSS 7.5No exploitEPSS 5%

    redislabs · redisApr 13, 2016

  • An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run L

    HighCVSS 7.7No exploitEPSS 3%

    redislabs · redisJun 15, 2020

  • CVE-2020-7105
    31Monitor

    async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.

    HighCVSS 7.5No exploitEPSS 3%

    redislabs · hiredisJan 16, 2020

  • networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not vali

    HighCVSS 7.4No exploitEPSS 2%

    redislabs · redisOct 24, 2017

  • RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as

    HighCVSS 7.5No exploitEPSS 2%

    redislabs · redisgraphDec 23, 2020

  • A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS).

    HighCVSS 7.5No exploitEPSS 1%

    redislabs · redisSep 20, 2021

  • CVE-2013-0178
    22Monitor

    Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.

    MediumCVSS 5.5No exploitEPSS 0%

    redislabs · redisNov 1, 2019

  • CVE-2013-0180
    22Monitor

    Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.

    MediumCVSS 5.5No exploitEPSS 0%

    redislabs · redisNov 1, 2019

  • CVE-2021-3470
    21Monitor

    A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jem

    MediumCVSS 5.3No exploitEPSS 1%

    redislabs · redisMar 31, 2021