Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Apache AppleCanonical+2 more9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+6 moreMay 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credent...Show more |
1Redhat 2Jboss Enterprise Application Platform ResteasyMay 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter...Show more |
1Redhat 1Jboss Enterprise Application Platform May 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote a...Show more |
1Redhat 1Jboss Enterprise Application Platform May 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 5.5 MEDIUM· v2 The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which a...Show more |
3Debian MitRedhat6Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+3 moreMay 6, 2026 Aug 14, 2014 N/A· v4 N/A· v3 7.8 HIGH· v2 The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer deref...Show more |
3Debian MitRedhat6Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+3 moreMay 6, 2026 Aug 14, 2014 N/A· v4 N/A· v3 7.6 HIGH· v2 Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a d...Show more |
The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's disk, which allows remote authenticated u...Show more |
3Canonical RedhatSamba3Enterprise Linux SambaUbuntu LinuxMay 6, 2026 Aug 6, 2014 N/A· v4 N/A· v3 7.9 HIGH· v2 NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on...Show more |
2Opensuse Redhat4Enterprise Linux Enterprise VirtualizationLibvirt+1 moreMay 6, 2026 Aug 3, 2014 N/A· v4 N/A· v3 1.2 LOW· v2 libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction wi...Show more |
2Opensuse Redhat4Enterprise Linux Enterprise VirtualizationLibvirt+1 moreMay 6, 2026 Aug 3, 2014 N/A· v4 N/A· v3 1.9 LOW· v2 libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity refere...Show more |
4Canonical LinuxRedhat+1 more8Enterprise Linux Eus Enterprise Linux Server AusEnterprise Linux Server Tus+5 moreMay 6, 2026 Aug 1, 2014 N/A· v4 N/A· v3 7.1 HIGH· v2 The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by...Show more |
2Linux Redhat4Enterprise Linux Eus Enterprise Linux Server AusEnterprise Linux Server Tus+1 moreMay 6, 2026 Aug 1, 2014 N/A· v4 N/A· v3 6.2 MEDIUM· v2 The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain reference count during attempts to use the umount system call in conjunction with a symlink, which allows...Show more |
1Redhat 1Jboss Enterprise Application Platform May 6, 2026 Jul 22, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 5.2.0 and 6.2.4, expands entity references, which allows remote...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Portal Platform+1 moreMay 6, 2026 Jul 22, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Portal Platform 5.2.2, and Red Hat JBoss SOA Platform 5.3.1, does not pro...Show more |
3Debian MitRedhat7Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+4 moreMay 6, 2026 Jul 20, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer dereference, and application crash) by injecting invalid tokens into a G...Show more |
4Debian FedoraprojectMit+1 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreMay 6, 2026 Jul 20, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session. |
4Apache DebianOracle+1 more6Debian Linux Enterprise Manager Ops CenterHttp Server+3 moreMay 6, 2026 Jul 20, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or ex...Show more |
3Apache DebianRedhat3Debian Linux Http ServerJboss Enterprise Application PlatformMay 6, 2026 Jul 20, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resourc...Show more |
5Debian LinuxOpensuse+2 more6Debian Linux Enterprise Linux Server AusLinux Enterprise Desktop+3 moreMay 6, 2026 Jul 19, 2014 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket. |
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of service (inaccessible page) via a non-ASCII character in the name of a lin...Show more |