← Back

Redhat

redhat

5,674 CVEs • 537 products

Products (537)

Click to collapse
Toggle
Linux
linux
Satellite
satellite
Openstack
openstack
Openshift
openshift
Keycloak
keycloak
Fedora Core
fedora_core
Libvirt
libvirt
Ansible Tower
ansible_tower
Cloudforms
cloudforms
Ansible
ansible
Ceph Storage
ceph_storage
Linux Desktop
linux_desktop
Linux Server
linux_server
Jboss Fuse
jboss_fuse
Undertow
undertow
Storage
storage
Quay
quay
Fuse
fuse
Data Grid
data_grid
Resteasy
resteasy
Wildfly
wildfly
Jboss A Mq
jboss_a-mq
Ceph
ceph

CVEs (5,674)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Freeipa
May 6, 2026
Nov 3, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows remote attackers to cause a denial of service (crash) via a connection...Show more
The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) in FreeIPA before 3.2.0 allows remote attackers to cause a denial of service (crash) via a connection request without a username/dn, related to the 389 directory server.Show less
4Canonical
OpensuseRedhat+1 more
4Enterprise Linux
OpensuseRuby+1 more
May 6, 2026
Nov 3, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Ex...Show more
The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.Show less
2Redhat
Suse
5Manager
Manager ServerSatellite+2 more
May 6, 2026
Nov 3, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.5 and 5.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vecto...Show more
Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.5 and 5.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) kickstart/cobbler/CustomSnippetList.do, (2) channels/software/Entitlements.do, or (3) admin/multiorg/OrgUsers.do.Show less
5Canonical
DebianOpensuse+2 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+9 more
May 6, 2026
Nov 1, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
2Openstack
Redhat
2Nova
Openstack
May 6, 2026
Oct 31, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.
2Openstack
Redhat
2Nova
Openstack
May 6, 2026
Oct 31, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.
1Redhat
1Cloudforms 3.0 Management Engine
May 6, 2026
Oct 27, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitrary text into log files via unspecified vectors.
2Igniterealtime
Redhat
2Jboss Fuse
Smack Api
May 6, 2026
Oct 25, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName fi...Show more
The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.Show less
1Redhat
1Virtual Desktop Service Manager
May 6, 2026
Oct 22, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open.
1Redhat
1Shim
May 6, 2026
Oct 22, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.
1Redhat
1Shim
May 6, 2026
Oct 22, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."
1Redhat
1Shim
May 6, 2026
Oct 22, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.
1Redhat
1Enterprise Virtualization Manager
May 6, 2026
Oct 18, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which allows remote attackers to read arbitrary files or possibly have other...Show more
The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted XML/RSDL document, related to an XML External Entity (XXE) issue.Show less
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 16, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ permission to obtain the default value for the password field of a parameterized job by reading the DOM.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 16, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin...Show more
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.Show less
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 16, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to execute arbitrary code via a crafted packet to the CLI channel.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 16, 2014
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/CONFIGURE permission to bypass intended restrictions and create or destroy arbitrary jobs via unspecified vectors.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 16, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to enumerate user names via vectors related to login attempts.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 16, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to cause a denial of service (thread consumption) via vectors related to a CLI handshake.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.