CVEs (73)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 6Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server Aus+3 moreMay 13, 2026 Sep 19, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leverag...Show more |
1Redhat 3Enterprise Linux Enterprise MrgKernel RtMay 13, 2026 Sep 14, 2017 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2, when the nfnetlink_log module is loaded, allows local users to cause a denial of service (panic) by creating netlink soc...Show more |
2Linux Redhat3Enterprise Mrg LinuxLinux KernelMay 6, 2026 Oct 7, 2016 N/A· v4 7.4 HIGH· v3 6.9 MEDIUM· v2 The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted c...Show more |
4Linux NovellOracle+1 more14Enterprise Linux Enterprise Linux DesktopEnterprise Linux For Real Time+11 moreMay 6, 2026 Jun 27, 2016 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash)...Show more |
2Linux Redhat3Enterprise Linux Enterprise MrgLinux KernelMay 6, 2026 May 2, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of servic...Show more |
5Debian FedoraprojectLinux+2 more6Debian Linux Enterprise MrgFedora+3 moreMay 6, 2026 May 27, 2015 N/A· v4 N/A· v3 3.3 LOW· v2 The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit settin...Show more |
8Canonical DebianLinux+5 more12Debian Linux Enterprise MrgEvergreen+9 moreMay 6, 2026 Nov 10, 2014 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks tha...Show more |
7Canonical DebianLinux+4 more10Debian Linux Enterprise LinuxEnterprise Mrg+7 moreMay 6, 2026 Nov 10, 2014 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c...Show more |
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of service (inaccessible page) via a non-ASCII character in the name of a lin...Show more |
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentiall...Show more |
2Linux Redhat3Enterprise Linux Enterprise MrgLinux KernelMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations,...Show more |
3Linux RedhatSuse4Enterprise Linux Enterprise MrgLinux Enterprise Desktop+1 moreMay 6, 2026 Jun 5, 2014 N/A· v4 N/A· v3 3.3 LOW· v2 kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a deni...Show more |
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier for attackers to obtain sensitive information via a brute-force attack...Show more |
3Condor Project FedoraprojectRedhat3Condor Enterprise MrgFedoraApr 29, 2026 Feb 10, 2014 N/A· v4 N/A· v3 4.4 MEDIUM· v2 Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_s...Show more |
SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL commands via vectors related to the "filtering table operator." |
Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to inject arbitrary web script or HTML via the "Max allowance" field in the "Set limit" f...Show more |
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allow remote attackers to hijack the authentication of cumin users for unspecified requests. |
cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restrictions and obtain sensitive information or perform privileged operation...Show more |
2Condor Project Redhat2Condor Enterprise MrgApr 29, 2026 Oct 11, 2013 N/A· v4 N/A· v3 3.5 LOW· v2 The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attributes in a (1) PREEMPT, (2) SUSPEND, (3) CONTINUE, (4) WANT_VACATE, or (5) KILL policy that evaluate to an Unconfigured, U...Show more |
2Condor Project Redhat2Condor Enterprise MrgApr 29, 2026 Oct 11, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The policy definition evaluator in Condor before 7.4.2 does not properly handle attributes in a WANT_SUSPEND policy that evaluate to an UNDEFINED state, which allows remote authenticated users to cause a denial of servic...Show more |