Redhat
redhat
5,682 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,682)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 1Mobile Application Platform May 13, 2026 Sep 29, 2017 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources, and access restricted endpoints. |
1Redhat 1Mobile Application Platform May 13, 2026 Sep 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was discovered in the file editor of millicore, affecting versions before 3.19.0 and 4.x before 4.5.0, which allows files to be executed as well as created. An attacker could use this flaw to compromise other user...Show more |
selinux-policy as packaged in Red Hat OpenShift 2 allows attackers to obtain process listing information via a privilege escalation attack. |
1Redhat 1Enterprise Virtualization Manager May 13, 2026 Sep 25, 2017 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in t...Show more |
1Redhat 2Amq Jboss Enterprise Web ServerMay 13, 2026 Sep 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Console: CORS headers set to allow all in Red Hat AMQ. |
1Redhat 3Amq Jboss A MqJboss Enterprise Web ServerMay 13, 2026 Sep 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ. |
Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ. |
The JBoss console in A-MQ allows remote attackers to execute arbitrary JavaScript. |
1Redhat 1Feedhenry Enterprise Mobile Application Platform May 13, 2026 Sep 20, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Reflected file download vulnerability in Red Hat Feedhenry Enterprise Mobile Application Platform. |
1Redhat 1Jboss Enterprise Application Platform May 13, 2026 Sep 19, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 AdvancedLdapLodinMogule in Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.1 allows attackers to obtain sensitive information via vectors involving logging the LDAP bind credential password when TRACE logg...Show more |
1Redhat 6Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server Aus+3 moreMay 13, 2026 Sep 19, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leverag...Show more |
eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files. |
3Apache NetappRedhat227 Mode Transition Tool Enterprise Linux DesktopEnterprise Linux Eus+19 moreApr 21, 2026 Sep 19, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a speci...Show more |
1Redhat 3Enterprise Linux Enterprise MrgKernel RtMay 13, 2026 Sep 14, 2017 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2, when the nfnetlink_log module is loaded, allows local users to cause a denial of service (panic) by creating netlink soc...Show more |
Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization |
3Debian RedhatTcpdump5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreMay 13, 2026 Sep 14, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements(). |
3Debian RedhatTcpdump5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreMay 13, 2026 Sep 14, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions. |
3Debian RedhatTcpdump5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreMay 13, 2026 Sep 14, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print(). |
3Debian RedhatTcpdump5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreMay 13, 2026 Sep 14, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print(). |
1Redhat 1Jboss Enterprise Application Platform May 13, 2026 Sep 13, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Red Hat JBoss EAP version 3.0.7 through before 4.0.0.Beta1 is vulnerable to a server-side cache poisoning or CORS requests in the JAX-RS component resulting in a moderate impact. |