Redhat
redhat
5,681 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,681)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 1Jboss Operations Network May 6, 2026 Sep 27, 2016 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 The server in Red Hat JBoss Operations Network (JON), when SSL authentication is not configured for JON server / agent communication, allows remote attackers to execute arbitrary code via a crafted HTTP request, related...Show more |
2Apache Redhat3Activemq Artemis ArtemisJboss Enterprise Application PlatformJun 15, 2026 Sep 27, 2016 N/A· v4 7.2 HIGH· v3 6.0 MEDIUM· v2 The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with...Show more |
1Redhat 1Jboss Enterprise Application Platform May 6, 2026 Sep 26, 2016 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to a...Show more |
1Redhat 2Jboss Enterprise Application Platform Jboss Wildfly Application ServerMay 6, 2026 Sep 26, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and con...Show more |
2Fedoraproject Redhat3Fedora Jboss Enterprise Application PlatformJboss Enterprise Web ServerMay 6, 2026 Sep 26, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate el...Show more |
1Redhat 1Quickstart Cloud Installer May 6, 2026 Sep 22, 2016 N/A· v4 8.4 HIGH· v3 2.1 LOW· v2 The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force attack. |
1Redhat 1Quickstart Cloud Installer May 6, 2026 Sep 22, 2016 N/A· v4 8.4 HIGH· v3 7.2 HIGH· v2 Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password for the deployed system by reading the file. |
3Libarchive OracleRedhat9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+6 moreMay 6, 2026 Sep 21, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file. |
4Debian FedoraprojectRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 6, 2026 Sep 21, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write. |
3Libarchive OracleRedhat10Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+7 moreMay 6, 2026 Sep 21, 2016 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file. |
3Libarchive OracleRedhat10Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+7 moreMay 6, 2026 Sep 21, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file. |
3Libarchive OracleRedhat9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+6 moreMay 6, 2026 Sep 21, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large...Show more |
2Libarchive Redhat8Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+5 moreMay 6, 2026 Sep 21, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary. |
2Libarchive Redhat8Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+5 moreMay 6, 2026 Sep 21, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, w...Show more |
5Debian MariadbOracle+2 more12Debian Linux Enterprise LinuxEnterprise Linux Desktop+9 moreMay 6, 2026 Sep 20, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5...Show more |
1Redhat 1Jboss Operations Network May 6, 2026 Sep 7, 2016 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, which allows remote authenticated users to gain admin privileges via a cr...Show more |
The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query strings, which makes easier for remote attackers to (1) bypass CSRF prot...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors. |
RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs. |