Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianIcoutils Project+2 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 Nov 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a...Show more |
4Fedoraproject OpensusePhp Gettext Project+1 more4Enterprise Linux FedoraLeap+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code. |
3Fedoraproject RedhatReviewboard4Djblets Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories. |
1Redhat 3Enterprise Virtualization StorageVirtual Desktop Server ManagerNov 21, 2024 Nov 4, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Insecure temporary file vulnerability in RedHat vsdm 4.9.6. |
3Debian RedhatSudo Project4Debian Linux Enterprise LinuxShadow+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into...Show more |
JBoss AeroGear has reflected XSS via the password field |
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates |
CloudForms stores user passwords in recoverable format |
3Isc OpensuseRedhat19Dhcpd Enterprise LinuxEnterprise Linux Desktop+16 moreJun 17, 2026 Nov 1, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but t...Show more |
3Debian OpenstackRedhat4Compute Debian LinuxKeystone+1 moreNov 21, 2024 Nov 1, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates. |
1Redhat 2Cloudforms Manageiq Enterprise Virtualization ManagerNov 21, 2024 Nov 1, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp. |
2Apache Redhat2Jboss Enterprise Web Server StrutsNov 21, 2024 Nov 1, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. |
3Fedoraproject RedhatSensiolabs3Enterprise Linux FedoraSymfonyNov 21, 2024 Nov 1, 2019 N/A· v4 8.1 HIGH· v3 4.9 MEDIUM· v2 php-symfony2-Validator has loss of information during serialization |
4Debian GnomeOpensuse+1 more4Debian Linux Enterprise LinuxEvince+1 moreNov 21, 2024 Nov 1, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 evince is missing a check on number of pages which can lead to a segmentation fault |
4Debian OpensusePython+1 more7Debian Linux Enterprise LinuxEnterprise Linux Eus+4 moreJun 17, 2026 Oct 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial o...Show more |
IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services. |
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files. |
1Redhat 1Jboss Operations Network Nov 21, 2024 Oct 30, 2019 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the pri...Show more |