← Back

Redhat

redhat

5,678 CVEs • 537 products

Products (537)

Click to collapse
Toggle
Linux
linux
Satellite
satellite
Openstack
openstack
Openshift
openshift
Keycloak
keycloak
Fedora Core
fedora_core
Libvirt
libvirt
Ansible Tower
ansible_tower
Cloudforms
cloudforms
Ansible
ansible
Ceph Storage
ceph_storage
Linux Desktop
linux_desktop
Linux Server
linux_server
Jboss Fuse
jboss_fuse
Undertow
undertow
Storage
storage
Quay
quay
Fuse
fuse
Data Grid
data_grid
Resteasy
resteasy
Wildfly
wildfly
Jboss A Mq
jboss_a-mq
Ceph
ceph

CVEs (5,678)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
7Canonical
DebianFedoraproject+4 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+9 more
May 6, 2026
Feb 8, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have uns...Show more
The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.Show less
4Canonical
GoogleOpensuse+1 more
8Chrome
Enterprise Linux DesktopEnterprise Linux Eus+5 more
May 6, 2026
Feb 6, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android allow attackers to cause a denial of service or possibly have other impact via un...Show more
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android allow attackers to cause a denial of service or possibly have other impact via unknown vectors.Show less
4Canonical
GoogleOpensuse+1 more
8Chrome
Enterprise Linux DesktopEnterprise Linux Eus+5 more
May 6, 2026
Feb 6, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host.cc in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android does no...Show more
The OriginCanAccessServiceWorkers function in content/browser/service_worker/service_worker_dispatcher_host.cc in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android does not properly restrict the URI scheme during a ServiceWorker registration, which allows remote attackers to gain privileges via a filesystem: URI.Show less
4Canonical
GoogleOpensuse+1 more
8Chrome
Enterprise Linux DesktopEnterprise Linux Eus+5 more
May 6, 2026
Feb 6, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 o...Show more
The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, does not properly consider frame access restrictions during the throwing of an exception, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.Show less
4Canonical
GoogleOpensuse+1 more
8Chrome
Enterprise Linux DesktopEnterprise Linux Eus+5 more
May 6, 2026
Feb 6, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.111 on Windo...Show more
Use-after-free vulnerability in the VisibleSelection::nonBoundaryShadowTreeRootNode function in core/editing/VisibleSelection.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and before 40.0.2214.109 on Android, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers improper handling of a shadow-root anchor.Show less
3Canonical
MageiaRedhat
7Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Server+4 more
May 6, 2026
Jan 29, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDo...Show more
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface.Show less
7Apple
DebianGnu+4 more
18Communications Application Session Controller
Communications Eagle Application ProcessorCommunications Eagle Lnp Application Processor+15 more
May 6, 2026
Jan 28, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostb...Show more
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."Show less
4Debian
Jasper ProjectOpensuse+1 more
4Debian Linux
Enterprise LinuxJasper+1 more
May 6, 2026
Jan 26, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image.
4Debian
Jasper ProjectOpensuse+1 more
4Debian Linux
Enterprise LinuxJasper+1 more
May 6, 2026
Jan 26, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which trig...Show more
Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overflow.Show less
2Openstack
Redhat
2Image Registry And Delivery Service (glance)
Openstack
May 6, 2026
Jan 23, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.
5Canonical
ChromiumGoogle+2 more
8Chrome
ChromiumEnterprise Linux Desktop Supplementary+5 more
May 6, 2026
Jan 22, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
5Canonical
ChromiumGoogle+2 more
8Chrome
ChromiumEnterprise Linux Desktop Supplementary+5 more
May 6, 2026
Jan 22, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unkn...Show more
The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.Show less
4Chromium
GoogleOpensuse+1 more
7Chrome
ChromiumEnterprise Linux Desktop Supplementary+4 more
May 6, 2026
Jan 22, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an incorrect data type for a certain length value, which allows remote attacke...Show more
The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an incorrect data type for a certain length value, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted X11 data.Show less
4Chromium
GoogleOpensuse+1 more
7Chrome
ChromiumEnterprise Linux Desktop Supplementary+4 more
May 6, 2026
Jan 22, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to...Show more
Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header.Show less
6Canonical
GoogleIcu Project+3 more
9Chrome
Communications Messaging ServerEnterprise Linux Desktop Supplementary+6 more
May 6, 2026
Jan 22, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corr...Show more
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a zero-length quantifier.Show less
6Canonical
GoogleIcu Project+3 more
9Chrome
Communications Messaging ServerEnterprise Linux Desktop Supplementary+6 more
May 6, 2026
Jan 22, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corr...Show more
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a look-behind expression.Show less
7Canonical
DebianFedoraproject+4 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+11 more
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DDL : Foreign Key.
6Canonical
DebianNovell+3 more
8Debian Linux
Enterprise LinuxJdk+5 more
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS.
6Canonical
DebianFedoraproject+3 more
8Communications Policy Management
Debian LinuxEnterprise Linux+5 more
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Server : Security...Show more
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Server : Security : Encryption.Show less
6Canonical
DebianNovell+3 more
9Debian Linux
Enterprise LinuxJdk+6 more
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affe...Show more
Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security.Show less