Redhat
redhat
5,676 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,676)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Jasper Project Redhat2Enterprise Linux JasperMay 6, 2026 Dec 24, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profi...Show more |
4Bsd Mailx Project HeirloomOracle+1 more4Bsd Mailx Enterprise LinuxLinux+1 moreMay 6, 2026 Dec 24, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address. |
4Canonical MageiaOpensuse+1 more8Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+5 moreMay 6, 2026 Dec 19, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unsp...Show more |
The storageVolUpload function in storage/storage_driver.c in libvirt before 1.2.11 does not check a certain return value, which allows local users to cause a denial of service (NULL pointer dereference and daemon crash)...Show more |
3Apache AppleRedhat6Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+3 moreMay 6, 2026 Dec 18, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request for a UR...Show more |
4Apache AppleDebian+1 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+5 moreMay 6, 2026 Dec 18, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT requ...Show more |
6Canonical GoogleLinux+3 more6Android Enterprise Linux EusEvergreen+3 moreMay 6, 2026 Dec 17, 2014 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET inst...Show more |
7Canonical DebianFedoraproject+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreMay 6, 2026 Dec 16, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial...Show more |
6Fedoraproject MariadbOpensuse+3 more11Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+8 moreMay 6, 2026 Dec 16, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero...Show more |
2Qemu Redhat7Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+4 moreMay 6, 2026 Dec 12, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via a crafted (1) offset or (2) length value in savevm data. |
The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of servic...Show more |
1Redhat 1Jboss Enterprise Portal Platform May 6, 2026 Dec 11, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in JBoss RichFaces, as used in JBoss Portal 6.1.1, allows remote attackers to inject arbitrary web script or HTML via crafted URL, which is not properly handled in a CSS file. |
3Debian OpensuseRedhat6Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+3 moreMay 6, 2026 Dec 8, 2014 N/A· v4 N/A· v3 4.6 MEDIUM· v2 lib/handle.c in Hivex before 1.3.11 allows local users to execute arbitrary code and gain privileges via a small hive files, which triggers an out-of-bounds read or write. |
Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia a crafted PPP packet. |
The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listi...Show more |
OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration option when generating the nova.conf configuration, which causes the fi...Show more |
4Debian OpensuseRedhat+1 more5Debian Linux Enterprise LinuxEnterprise Linux Desktop+2 moreMay 6, 2026 Dec 1, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a de...Show more |
Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Windows, allows remote attackers to read arbitrary files via a .. (dot dot) i...Show more |
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks vi...Show more |
2Jqueryui Redhat5Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+2 moreMay 6, 2026 Nov 24, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title...Show more |