← Back

Redhat

redhat

5,678 CVEs • 537 products

Products (537)

Click to collapse
Toggle
Linux
linux
Satellite
satellite
Openstack
openstack
Openshift
openshift
Keycloak
keycloak
Fedora Core
fedora_core
Libvirt
libvirt
Ansible Tower
ansible_tower
Cloudforms
cloudforms
Ansible
ansible
Ceph Storage
ceph_storage
Linux Desktop
linux_desktop
Linux Server
linux_server
Jboss Fuse
jboss_fuse
Undertow
undertow
Storage
storage
Quay
quay
Fuse
fuse
Data Grid
data_grid
Resteasy
resteasy
Wildfly
wildfly
Jboss A Mq
jboss_a-mq
Ceph
ceph

CVEs (5,678)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 16, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1812...Show more
Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1812.Show less
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 16, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1813...Show more
Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1813.Show less
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 16, 2015
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The HudsonPrivateSecurityRealm class in Jenkins before 1.600 and LTS before 1.596.1 does not restrict access to reserved names when using the "Jenkins' own user database" setting, which allows remote attackers to gain pr...Show more
The HudsonPrivateSecurityRealm class in Jenkins before 1.600 and LTS before 1.596.1 does not restrict access to reserved names when using the "Jenkins' own user database" setting, which allows remote attackers to gain privileges by creating a reserved name.Show less
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 16, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users to cause a denial of service (improper plug-in and tool installation) via crafted update center data.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 16, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
Directory traversal vulnerability in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with certain permissions to read arbitrary files via a symlink, related to building artifacts.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 16, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unsp...Show more
The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.Show less
4Adobe
OpensuseRedhat+1 more
10Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+7 more
Apr 22, 2026
Oct 15, 2015
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in...Show more
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.Show less
3Fedoraproject
OpensuseRedhat
7Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Server+4 more
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via...Show more
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.Show less
3Fedoraproject
OpensuseRedhat
7Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Server+4 more
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute...Show more
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.Show less
4Debian
NtpOracle+1 more
6Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+3 more
May 6, 2026
Oct 6, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attac...Show more
The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it easier for remote attackers to spoof restricted packets, and read or write to the runtime state, by leveraging the ability to reach the ntpd machine's network interface with a packet from the ::1 address.Show less
4Debian
NtpOracle+1 more
6Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+3 more
May 6, 2026
Oct 6, 2015
N/A· v4
N/A· v3
5.8 MEDIUM· v2
ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process memory or cause a denial of service (daemon crash) via a packet...Show more
ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process memory or cause a denial of service (daemon crash) via a packet containing an extension field with an invalid value for the length of its value field.Show less
1Redhat
1Openshift
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to the Broker.
1Redhat
1Openshift Origin
May 6, 2026
Sep 8, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The API server in OpenShift Origin 1.0.5 allows remote attackers to cause a denial of service (master process crash) via crafted JSON data.
2Redhat
Spice Project
6Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+3 more
May 6, 2026
Sep 8, 2015
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arb...Show more
Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors.Show less
1Redhat
1Enterprise Virtualization
May 6, 2026
Sep 8, 2015
N/A· v4
N/A· v3
3.7 LOW· v2
The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view.
2Linux
Redhat
2Enterprise Linux Server Aus
Linux Kernel
May 6, 2026
Aug 31, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 provide inappropriate -EAGAIN return values, which allows remote attackers to cause a denial of service (EPOLLET epoll application read...Show more
The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 provide inappropriate -EAGAIN return values, which allows remote attackers to cause a denial of service (EPOLLET epoll application read outage) via an incorrect checksum in a UDP packet, a different vulnerability than CVE-2015-5364.Show less
4Canonical
DebianLinux+1 more
4Debian Linux
Enterprise Linux Server AusLinux Kernel+1 more
May 6, 2026
Aug 31, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 do not properly consider yielding a processor, which allows remote attackers to cause a denial of service (system hang) via incorrect c...Show more
The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 do not properly consider yielding a processor, which allows remote attackers to cause a denial of service (system hang) via incorrect checksums within a UDP packet flood.Show less
2Linux
Redhat
6Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Server+3 more
May 6, 2026
Aug 31, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during userspace execution, which might allow local users to gain privileges by tr...Show more
arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during userspace execution, which might allow local users to gain privileges by triggering an NMI.Show less
6Arista
DebianLenovo+3 more
19Debian Linux
Emc Px12 400r IvxEmc Px12 450r Ivx+16 more
May 6, 2026
Aug 31, 2015
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host O...Show more
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.Show less
1Redhat
1Openshift
May 6, 2026
Aug 24, 2015
N/A· v4
N/A· v3
8.5 HIGH· v2
Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute arbitrary shell commands with root permissions on arbitrary build pods v...Show more
Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute arbitrary shell commands with root permissions on arbitrary build pods via unspecified vectors.Show less