Redhat
redhat
5,681 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,681)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
8Debian DrupalFedoraproject+5 more13Communications User Data Repository Debian LinuxDrupal+10 moreMay 6, 2026 Jul 19, 2016 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, whi...Show more |
2Debian Redhat2Debian Linux LibvirtMay 6, 2026 Jul 13, 2016 N/A· v4 9.8 CRITICAL· v3 4.3 MEDIUM· v2 libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to...Show more |
1Redhat 7Ceph Ceph Storage MonCeph Storage Osd+4 moreMay 6, 2026 Jul 12, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix. |
2Canonical Redhat2Openstack Openstack IronicMay 6, 2026 Jul 12, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address o...Show more |
3Debian OpenstackRedhat3Debian Linux HorizonOpenstackMay 6, 2026 Jul 12, 2016 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS templ...Show more |
2Isc Redhat2Bind Enterprise LinuxMay 6, 2026 Jul 6, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary DNS server crash) via a large AXFR response, and possibly allows IXFR se...Show more |
2Openvswitch Redhat2Openshift OpenvswitchMay 6, 2026 Jul 3, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long stri...Show more |
5Canonical GoogleNovell+2 more8Chrome Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 6, 2026 Jul 3, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.103 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. |
The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) director (aka overcloud-full) use a default root password o...Show more |
1Redhat 2Jboss Enterprise Application Platform JgroupsMay 6, 2026 Jun 30, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability t...Show more |
4Fedoraproject LinuxRedhat+1 more11Enterprise Linux FedoraLinux Enterprise Debuginfo+8 moreMay 6, 2026 Jun 27, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by...Show more |
4Linux NovellOracle+1 more14Enterprise Linux Enterprise Linux DesktopEnterprise Linux For Real Time+11 moreMay 6, 2026 Jun 27, 2016 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash)...Show more |
3Linux NovellRedhat4Enterprise Linux For Real Time Enterprise Linux For Real Time For NfvLinux Kernel Rt+1 moreMay 6, 2026 Jun 27, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before 3.10.0-327.22.1 in Red Hat Enterprise Linux for Real Time 7 and other p...Show more |
3Canonical LinuxRedhat9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+6 moreMay 6, 2026 Jun 27, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data. |
4Adobe OpensuseRedhat+1 more7Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+4 moreApr 21, 2026 Jun 16, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016. |
4Adobe OpensuseRedhat+1 more8Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+5 moreMay 6, 2026 Jun 16, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different...Show more |
4Adobe OpensuseRedhat+1 more8Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+5 moreMay 6, 2026 Jun 16, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different...Show more |
4Adobe OpensuseRedhat+1 more8Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+5 moreMay 6, 2026 Jun 16, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different...Show more |
4Adobe OpensuseRedhat+1 more8Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+5 moreMay 6, 2026 Jun 16, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different...Show more |
4Adobe OpensuseRedhat+1 more8Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+5 moreMay 6, 2026 Jun 16, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different...Show more |