Redhat
redhat
5,678 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,678)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an account defined in the users.properties file. |
4Adobe OpensuseRedhat+1 more11Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+8 moreApr 21, 2026 Jul 8, 2015 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 o...Show more |
2Openssl Redhat2Enterprise Linux OpensslMay 6, 2026 Jul 7, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1.0.1e-25.el7 in Red Hat Enterprise Linux (RHEL) 7 and other products, all...Show more |
6Canonical DebianHaproxy+3 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 6, 2026 Jul 6, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninit...Show more |
3Ibm RedhatSuse8Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+5 moreMay 27, 2026 Jul 2, 2015 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors rela...Show more |
2Async Http Client Project Redhat2Async Http Client Jboss FuseMay 6, 2026 Jun 24, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-...Show more |
2Async Http Client Project Redhat2Async Http Client Jboss FuseMay 6, 2026 Jun 24, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Async Http Client (aka AHC or async-http-client) before 1.9.0 skips X.509 certificate verification unless both a keyStore location and a trustStore location are explicitly set, which allows man-in-the-middle attackers to...Show more |
4Oracle RedhatRuby Lang+1 more4Enterprise Linux RubyRubygems+1 moreMay 6, 2026 Jun 24, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains v...Show more |
5Adobe HpOpensuse+2 more15Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+12 moreApr 21, 2026 Jun 23, 2015 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspec...Show more |
3Opensuse RedhatW1.fi7Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+4 moreMay 6, 2026 Jun 15, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (cras...Show more |
8Arista CanonicalDebian+5 more18Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+15 moreMay 6, 2026 Jun 15, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set. |
3Apple PhpRedhat8Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+5 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property is a string, which allows remote attackers to obtain sensitive informat...Show more |
3Apple PhpRedhat8Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+5 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The SoapClient::__call method in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that __default_headers is an array, which allows remote attackers to execute arbitrary co...Show more |
3Apple PhpRedhat9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote attackers to bypass intended extension res...Show more |
3Apple PhpRedhat9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and ac...Show more |
5Apple HpOracle+2 more12Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+9 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU...Show more |
3Apple PhpRedhat9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, lead...Show more |
3Apple PhpRedhat9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+6 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 does not verify that the first character of a filename is different from the \0 character, which allows...Show more |
4Apple OraclePhp+1 more11Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+8 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of se...Show more |
4Apple OraclePhp+1 more11Enterprise Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+8 moreMay 6, 2026 Jun 9, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted len...Show more |