← Back

Redhat

redhat

5,679 CVEs • 537 products

Products (537)

Click to collapse
Toggle
Linux
linux
Satellite
satellite
Openstack
openstack
Openshift
openshift
Keycloak
keycloak
Fedora Core
fedora_core
Libvirt
libvirt
Ansible Tower
ansible_tower
Cloudforms
cloudforms
Ansible
ansible
Ceph Storage
ceph_storage
Linux Desktop
linux_desktop
Linux Server
linux_server
Jboss Fuse
jboss_fuse
Undertow
undertow
Storage
storage
Quay
quay
Fuse
fuse
Data Grid
data_grid
Resteasy
resteasy
Wildfly
wildfly
Jboss A Mq
jboss_a-mq
Ceph
ceph

CVEs (5,679)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Satellite
May 6, 2026
Apr 14, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the list_1680466951_oldfilterval parameter to systems/PhysicalList.do or (2...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the list_1680466951_oldfilterval parameter to systems/PhysicalList.do or (2) unspecified vectors involving systems/VirtualSystemsList.do.Show less
4Debian
FedoraprojectLibpng+1 more
7Debian Linux
Enterprise Linux Desktop SupplementaryEnterprise Linux Hpc Node+4 more
May 6, 2026
Apr 14, 2016
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote atta...Show more
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.Show less
1Redhat
2Satellite
Spacewalk Java
May 6, 2026
Apr 14, 2016
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving...Show more
Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.Show less
5Canonical
DebianFedoraproject+2 more
5Debian Linux
Enterprise LinuxFedora+2 more
May 6, 2026
Apr 13, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attacker...Show more
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."Show less
6Debian
FedoraprojectMercurial+3 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+11 more
May 6, 2026
Apr 13, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.
6Debian
FedoraprojectMercurial+3 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+11 more
May 6, 2026
Apr 13, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
2Redhat
Xen
2Enterprise Linux
Xen
May 26, 2026
Apr 13, 2016
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists because of an incompl...Show more
Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0777.Show less
4Debian
OpensuseRedhat+1 more
5Debian Linux
LeapOpenstack+2 more
May 6, 2026
Apr 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of servi...Show more
Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow.Show less
4Canonical
Git ProjectOpensuse+1 more
4Git
OpensuseSoftware Collections+1 more
May 6, 2026
Apr 13, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might al...Show more
The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.Show less
4Canonical
DebianQemu+1 more
11Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+8 more
May 6, 2026
Apr 12, 2016
N/A· v4
8.4 HIGH· v3
3.6 LOW· v2
The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.
3Debian
QemuRedhat
4Debian Linux
OpenstackQemu+1 more
May 6, 2026
Apr 12, 2016
N/A· v4
8.8 HIGH· v3
6.9 MEDIUM· v2
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHC...Show more
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHCI Native Command Queuing (NCQ) AIO command.Show less
2Kubernetes
Redhat
2Kubernetes
Openshift
May 6, 2026
Apr 11, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Kubernetes before 1.2.0-alpha.5 allows remote attackers to read arbitrary pod logs via a container name.
1Redhat
2Cloudforms
Cloudforms Management Engine
May 6, 2026
Apr 11, 2016
N/A· v4
5.1 MEDIUM· v3
1.9 LOW· v2
Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend PostgreSQL database, which might allow local users to obtain sensitive d...Show more
Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend PostgreSQL database, which might allow local users to obtain sensitive data and consequently gain privileges by leveraging access to (1) database exports or (2) log files.Show less
1Redhat
1Openstack
May 6, 2026
Apr 11, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured RabbitMQ credentials, which makes it easier for remote attackers to obta...Show more
The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured RabbitMQ credentials, which makes it easier for remote attackers to obtain access to services in deployed overclouds by leveraging knowledge of the default credentials.Show less
1Redhat
1Libvirt
May 6, 2026
Apr 11, 2016
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage/storage_backend_fs.c in libvirt, when fine-grained Access Control Lists (ACL) are in effect, allows local users with stora...Show more
Directory traversal vulnerability in the virStorageBackendFileSystemVolCreate function in storage/storage_backend_fs.c in libvirt, when fine-grained Access Control Lists (ACL) are in effect, allows local users with storage_vol:create ACL but not domain:write permission to write to arbitrary files via a .. (dot dot) in a volume name.Show less
2Redhat
Theforeman
2Foreman
Satellite
May 6, 2026
Apr 11, 2016
N/A· v4
4.2 MEDIUM· v3
6.0 MEDIUM· v2
Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary hosts or (2) remote au...Show more
Foreman before 1.8.4 and 1.9.x before 1.9.1 do not properly apply view_hosts permissions, which allows (1) remote authenticated users with the view_reports permission to read reports from arbitrary hosts or (2) remote authenticated users with the destroy_reports permission to delete reports from arbitrary hosts via direct access to the (a) individual report show/delete pages or (b) APIs.Show less
1Redhat
8Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+5 more
May 6, 2026
Apr 8, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash...Show more
The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors.Show less
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Apr 7, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Apr 7, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force approach.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Apr 7, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.