CVE Tools

Redislabs

9 CVEs tracked since 2015. Since Jun 2015, none of them reached CISA KEV.

Redislabs CVEs per month

Jun 2015 to Jun 2018. Point at a month, or focus the strip and use the arrow keys.
Redislabs CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2015-0610
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-0410
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-1010
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-1020
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-0640

Products

The products that kept showing up in Redislabs's monthly top three, with their CVEs summed over those months.

  1. Redis95 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Redislabs.

  1. CVE-2023-47003An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlock_ItemIsDeleted.9.8
  2. CVE-2023-47004Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code via the code logic after valid authentication.8.8
  3. CVE-2020-21468A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS). NOTE: the vendor cannot reproduce this issue in a released version, such as 5.0.7.7.5
  4. CVE-2021-32761Integer overflow issues with *BIT commands on 32-bit systems7.5
  5. CVE-2021-32625Redis vulnerability in STRALGO LCS on 32-bit systems7.5
  6. CVE-2021-29478Vulnerability in the COPY command for large intsets7.5
  7. CVE-2021-29477Vulnerability in the STRALGO LCS command7.5
  8. CVE-2021-3470A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemalloc or glibc's malloc, leading to potential out of boun...5.3
  9. CVE-2021-21309Integer overflow on 32-bit systems5.4
  10. CVE-2020-35668RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as an alias that has not yet been introduced.7.5
  11. CVE-2020-14147An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (...7.7
  12. CVE-2020-7105async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.7.5
  13. CVE-2013-0180Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.5.5
  14. CVE-2013-0178Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.5.5
  15. CVE-2019-10192A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog usin...7.2

The record

Peak rank
#98 in Jun 2018
Busiest month shown
Jun 2018, 4 CVEs
Months with a KEV entry
0 since Jun 2015
Monthly snapshots
5 since 2015
Redislabs's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store