Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections. |
2Redhat Theforeman2Katello Network SatelliteMay 6, 2026 Apr 17, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account...Show more |
3Mariadb OracleRedhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 5.1 MEDIUM· v2 Unspecified vulnerability in the MySQL Client component in Oracle MySQL 5.5.36 and earlier and 5.6.16 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. |
3Mariadb OracleRedhat8Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+5 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via unknown vectors related to Replication. |
3Mariadb OracleRedhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to RBR. |
3Mariadb OracleRedhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 2.8 LOW· v2 Unspecified vulnerability Oracle the MySQL Server component 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via unknown vectors related to Federated. |
3Mariadb OracleRedhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 2.6 LOW· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote attackers to affect availability via unknown vectors related to Options. |
3Mariadb OracleRedhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote authenticated users to affect availability via unknown vectors related to Performance Schema. |
3Mariadb OracleRedhat9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition. |
3Mariadb OracleRedhat8Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+5 moreMay 6, 2026 Apr 16, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via vectors related to XML. |
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitr...Show more |
1Redhat 3Network Proxy SatelliteSpacewalk JavaMay 6, 2026 Apr 15, 2014 N/A· v4 N/A· v3 6.0 MEDIUM· v2 The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with permissions to admi...Show more |
5Apache AppleCanonical+2 more15Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+12 moreMay 6, 2026 Apr 15, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the...Show more |
1Redhat 3Jboss Bpm Suite Jboss DroolsJboss Enterprise Brms PlatformMay 6, 2026 Apr 10, 2014 N/A· v4 N/A· v3 6.5 MEDIUM· v2 JBoss Drools, Red Hat JBoss BRMS before 6.0.1, and Red Hat JBoss BPM Suite before 6.0.1 allows remote authenticated users to execute arbitrary Java code via a (1) MVFLEX Expression Language (MVEL) or (2) Drools expressio...Show more |
13Broadcom CanonicalDebian+10 more28Application Processing Engine Firmware Cp 1543 1 FirmwareDebian Linux+25 moreApr 21, 2026 Apr 7, 2014 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted pa...Show more |
1Redhat 1Jboss Enterprise Application Platform May 6, 2026 Apr 3, 2014 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be granted the java.securi...Show more |
CRLF injection vulnerability in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 5.6 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site...Show more |
Red Hat JBoss Operations Network (JON) before 3.0.1 uses 0777 permissions for the root directory when installing a remote client, which allows local users to read or modify subdirectories and files within the root direct...Show more |
Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce "modify resource" permissions for remote authenticated users when deleting a plug-in configuration update from the group connection properties...Show more |
3Qemu RedhatXen3Enterprise Linux QemuXenMay 6, 2026 Apr 1, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted S...Show more |