Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Condor Project FedoraprojectRedhat3Condor Enterprise MrgFedoraApr 29, 2026 Feb 10, 2014 N/A· v4 N/A· v3 4.4 MEDIUM· v2 Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_s...Show more |
2Redhat Zeroclipboard Project2Openshift ZeroclipboardApr 29, 2026 Feb 8, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by Jon Rohan and James M. Greene, allow remote attackers to inject arbitrary web script or HTML via ve...Show more |
2Matthew Booth Redhat2Enterprise Linux Virt V2vApr 29, 2026 Feb 8, 2014 N/A· v4 N/A· v3 4.4 MEDIUM· v2 virt-v2v before 0.8.4 does not preserve the VNC console password when converting a guest, which allows local users to bypass the intended VNC authentication by connecting without a password. |
5Canonical DebianOpensuse+2 more6Debian Linux LeapLibyaml+3 moreApr 29, 2026 Feb 6, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code vi...Show more |
7Canonical DebianFedoraproject+4 more17Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+14 moreApr 29, 2026 Feb 6, 2014 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitiv...Show more |
7Canonical DebianFedoraproject+4 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreApr 29, 2026 Feb 6, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to execute arbitrary c...Show more |
7Canonical DebianFedoraproject+4 more17Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+14 moreApr 29, 2026 Feb 6, 2014 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitra...Show more |
7Canonical DebianFedoraproject+4 more17Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+14 moreApr 29, 2026 Feb 6, 2014 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native...Show more |
7Canonical DebianFedoraproject+4 more17Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+14 moreApr 29, 2026 Feb 6, 2014 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent certain cloning operations, which allows remo...Show more |
7Canonical DebianFedoraproject+4 more17Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+14 moreApr 29, 2026 Feb 6, 2014 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to cause a denial of serv...Show more |
3Canonical OpensuseRedhat3Icedtea Web OpensuseUbuntu LinuxApr 29, 2026 Feb 5, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended...Show more |
1Redhat 2Network Proxy SatelliteApr 29, 2026 Feb 5, 2014 N/A· v4 4.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-RPC call fails, causing cleartext user passwords to be included in error messages. Remote administrat...Show more |
1Redhat 2Network Satellite SpacewalkApr 29, 2026 Feb 5, 2014 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Spacewalk. A remote attacker can exploit a cross-site scripting (XSS) vulnerability in the Lookup Login/Password form by injecting arbitrary web script or HTML via the URI. This can lead to informatio...Show more |
1Redhat 2Network Satellite SpacewalkApr 29, 2026 Feb 5, 2014 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Spacewalk and Red Hat Network Satellite. This vulnerability, known as cross-site scripting (XSS), allows remote attackers to inject malicious web scripts or HTML into web pages viewed by other users....Show more |
1Redhat 2Network Satellite SpacewalkApr 29, 2026 Feb 5, 2014 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitrary web script or HTML into web pages through various input fields, such...Show more |
Cross-site scripting (XSS) vulnerability in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allows remote attackers to inject arbitrary web script or HTML via the QueryString to the SystemGroupList.do page. |
1Redhat 2Network Satellite SpacewalkApr 29, 2026 Feb 5, 2014 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. Th...Show more |
5Adobe GoogleOpensuse+2 more9Chrome Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 21, 2026 Feb 5, 2014 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unsp...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 29, 2026 Feb 2, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (...Show more |
The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffin...Show more |