Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian OracleRedhat5Debian Linux Enterprise LinuxJdk+2 moreMay 6, 2026 Jul 17, 2014 N/A· v4 N/A· v3 9.3 HIGH· v2 Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a d...Show more |
The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, relate...Show more |
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentiall...Show more |
1Redhat 1Cloudforms 3.0 Management Engine May 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 lib/util/miq-password.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 uses a hard-coded salt, which makes it easier for remote attackers to guess passwords via a brute force attack. |
1Redhat 1Cloudforms 3.0 Management Engine May 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allow local users to execute arbitrary...Show more |
1Redhat 1Jboss Enterprise Application Platform May 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified...Show more |
1Redhat 3Jboss Enterprise Application Platform Jboss Enterprise Web PlatformJboss Web Framework KitMay 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute ar...Show more |
1Redhat 1Cloudforms 3.0 Management Engine May 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 logs the root password when deploying a VM, which allows local users to obtain sensitive information by reading the evm.log file. |
1Redhat 1Cloudforms 3.0 Management Engine May 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The wait_for_task function in app/controllers/application_controller.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allows remote attackers to cause a denial of service (infinite loop and CPU consum...Show more |
1Redhat 1Cloudforms 3.0 Management Engine May 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in application/panel_control in CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2Apache Redhat2Cxf Jboss Enterprise Application PlatformMay 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext,...Show more |
2Apache Redhat2Cxf Jboss Enterprise Application PlatformMay 6, 2026 Jul 7, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token. |
5Canonical FedoraprojectLibreoffice+2 more7Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+4 moreMay 6, 2026 Jul 3, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx. |
4Canonical LinuxRedhat+1 more9Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+6 moreMay 6, 2026 Jul 3, 2014 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allow local users to cause a denial of service by leveraging /dev/snd/controlCX access, related to (...Show more |
4Canonical LinuxRedhat+1 more6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+3 moreMay 6, 2026 Jul 3, 2014 N/A· v4 N/A· v3 1.9 LOW· v2 Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allows local users to obtain sensitive in...Show more |
5Canonical F5Linux+2 more26Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+23 moreMay 6, 2026 Jun 23, 2014 N/A· v4 N/A· v3 2.3 LOW· v2 The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from r...Show more |
cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a Source-Url ending with a (1) .tar.gz, (2) .zip, (3) .tgz,...Show more |
3Ppc64 Diag Project RedhatSuse3Enterprise Linux Server Linux Enterprise ServerPpc64 DiagMay 6, 2026 Jun 17, 2014 N/A· v4 N/A· v3 2.1 LOW· v2 ppc64-diag 2.6.1 uses 0775 permissions for /tmp/diagSEsnap and does not properly restrict permissions for /tmp/diagSEsnap/snapH.tar.gz, which allows local users to obtain sensitive information by reading files in this ar...Show more |
3Ppc64 Diag Project RedhatSuse3Enterprise Linux Server Linux Enterprise ServerPpc64 DiagMay 6, 2026 Jun 17, 2014 N/A· v4 N/A· v3 4.4 MEDIUM· v2 ppc64-diag 2.6.1 allows local users to overwrite arbitrary files via a symlink attack related to (1) rtas_errd/diag_support.c and /tmp/get_dt_files, (2) scripts/ppc64_diag_mkrsrc and /tmp/diagSEsnap/snapH.tar.gz, or (3)...Show more |
A certain tomcat7 package for Apache Tomcat 7 in Red Hat Enterprise Linux (RHEL) 7 allows remote attackers to cause a denial of service (CPU consumption) via a crafted request. NOTE: this vulnerability exists because of...Show more |