Redhat
redhat
5,682 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,682)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FasterxmlNetapp+1 more8Debian Linux E Series Santricity Os ControllerE Series Santricity Web Services Proxy+5 moreAug 27, 2025 Jan 10, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending malic...Show more |
In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and p...Show more |
1Redhat 6Hibernate Validator Jboss Enterprise Application PlatformSatellite+3 moreNov 21, 2024 Jan 10, 2018 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernat...Show more |
2Adobe Redhat4Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+1 moreNov 21, 2024 Jan 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data that is past the end of the target buffer. The use of an invalid (out-o...Show more |
2Freedesktop Redhat2Enterprise Linux Xdg User DirsNov 21, 2024 Jan 9, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped...Show more |
4Canonical FedoraprojectLinux+1 more20Enterprise Linux Enterprise Linux Compute Node EusEnterprise Linux Desktop+17 moreNov 21, 2024 Jan 9, 2018 N/A· v4 4.7 MEDIUM· v3 4.9 MEDIUM· v2 A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it...Show more |
3Fedoraproject NumpyRedhat3Enterprise Linux FedoraNumpyNov 21, 2024 Jan 8, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary f...Show more |
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified...Show more |
9Arista CanonicalDebian+6 more29Arx Caas PlatformCloud Magnum Orchestration+26 moreJan 3, 2025 Jan 3, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or poss...Show more |
3Fedoraproject Netcf ProjectRedhat3Enterprise Linux FedoraNetcfMay 13, 2026 Dec 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions. |
2Hawt Redhat2Hawtio Jboss FuseMay 13, 2026 Dec 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter. |
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf server, as demonstrated...Show more |
2Linux Redhat2Enterprise Linux Linux KernelMay 13, 2026 Dec 29, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leveraging failure to disable APEI error injecti...Show more |
2Fedoraproject Redhat2Ceph FedoraMay 13, 2026 Dec 20, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an inval...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HTML via vectors related to task name html inputs. |
2Heketi Project Redhat2Enterprise Linux HeketiMay 13, 2026 Dec 18, 2017 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file. |
2Heketi Project Redhat2Enterprise Linux HeketiMay 13, 2026 Dec 18, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as...Show more |
2Gnu Redhat4Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+1 moreMay 13, 2026 Dec 18, 2017 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGIN for a privileged (setuid or AT_SECURE) program, which allows local users to gain privileges via a...Show more |
3Debian RedhatRuby Lang8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Dec 15, 2017 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the "|" pipe...Show more |
2Adobe Redhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreMay 13, 2026 Dec 13, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A regression affecting Adobe Flash Player version 27.0.0.187 (and earlier versions) causes the unintended reset of the global settings preference file when a user clears browser data. |