Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Redhat2Debian Linux LibvirtNov 21, 2024 Apr 18, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886. |
3Debian FedoraprojectRedhat3389 Directory Server Debian LinuxEnterprise LinuxJun 17, 2026 Apr 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests....Show more |
It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use...Show more |
4Canonical DebianLinux+1 more16Codeready Linux Builder Debian LinuxEnterprise Linux+13 moreJun 17, 2026 Apr 11, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1. |
4Canonical DebianLinux+1 more16Codeready Linux Builder Debian LinuxEnterprise Linux+13 moreJun 17, 2026 Apr 11, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1. |
A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious use...Show more |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Apr 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.9 MEDIUM· v2 It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unprivileged multi-threaded userspace application calling recvmsg() for the same network socket in para...Show more |
3Jenkins OracleRedhat3Communications Cloud Native Core Automated Test Suite JenkinsOpenshift Container PlatformJun 17, 2026 Apr 10, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable...Show more |
3Jenkins OracleRedhat3Communications Cloud Native Core Automated Test Suite JenkinsOpenshift Container PlatformJun 17, 2026 Apr 10, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Apr 9, 2019 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XD...Show more |
1Redhat 3Enterprise Linux Server Aus Enterprise Linux Server EusEnterprise Linux Server TusNov 21, 2024 Apr 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response. |
2Redhat Theforeman2Foreman SatelliteJun 17, 2026 Apr 9, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to the disclosure of the plaintext password or token for the affected compute resource. A malicious user...Show more |
4Canonical FedoraprojectLinux+1 more11Enterprise Linux Enterprise Linux EusEnterprise Linux For Real Time+8 moreJun 17, 2026 Apr 9, 2019 N/A· v4 5.6 MEDIUM· v3 4.7 MEDIUM· v2 A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via L2 guest, when 'virtu...Show more |
5Debian FedoraprojectOpensuse+2 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 Apr 9, 2019 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permission...Show more |
3Microsoft Mono ProjectRedhat8.net Core Sdk Enterprise LinuxEnterprise Linux Eus+5 moreJun 17, 2026 Apr 9, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'...Show more |
8Apache CanonicalDebian+5 more27Communications Session Report Manager Communications Session Route ManagerDebian Linux+24 moreJun 17, 2026 Apr 8, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) cou...Show more |
8Apache CanonicalDebian+5 more14Clustered Data Ontap Debian LinuxEnterprise Linux+11 moreJun 17, 2026 Apr 8, 2019 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing config...Show more |
5Canonical FedoraprojectOpensuse+2 more5Fedora JinjaLeap+2 moreJun 17, 2026 Apr 7, 2019 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape. |
2Openstack Redhat2Neutron OpenstackJun 17, 2026 Apr 5, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutro...Show more |
3Fedoraproject OpensuseRedhat3Fedora LeapLibvirtJun 17, 2026 Apr 4, 2019 N/A· v4 5.4 MEDIUM· v3 4.8 MEDIUM· v2 An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information...Show more |