← Back

Redhat

redhat

5,674 CVEs • 537 products

Products (537)

Click to collapse
Toggle
Linux
linux
Satellite
satellite
Openstack
openstack
Openshift
openshift
Keycloak
keycloak
Fedora Core
fedora_core
Libvirt
libvirt
Ansible Tower
ansible_tower
Cloudforms
cloudforms
Ansible
ansible
Ceph Storage
ceph_storage
Linux Desktop
linux_desktop
Linux Server
linux_server
Jboss Fuse
jboss_fuse
Undertow
undertow
Storage
storage
Quay
quay
Fuse
fuse
Data Grid
data_grid
Resteasy
resteasy
Wildfly
wildfly
Jboss A Mq
jboss_a-mq
Ceph
ceph

CVEs (5,674)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Jboss Operations Network
Apr 29, 2026
Oct 24, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
The server in Red Hat JBoss Operations Network (JON) 3.1.2 logs passwords in plaintext, which allows local users to obtain sensitive information by reading the log files.
2Feep
Redhat
2Enterprise Linux
Libtar
Apr 29, 2026
Oct 17, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) name or (2) link in...Show more
Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) name or (2) link in an archive, which triggers a heap-based buffer overflow.Show less
3Redhat
Ruby LangRubygems
3Enterprise Linux
RubyRubygems
Apr 29, 2026
Oct 17, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.1, 1.8.24 through 1.8.25, 2.0.x before 2.0.8, and 2.1.x before 2.1.0, as used in Ruby 1.9.0 throu...Show more
Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.1, 1.8.24 through 1.8.25, 2.0.x before 2.0.8, and 2.1.x before 2.1.0, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted gem version that triggers a large amount of backtracking in a regular expression.Show less
2Oracle
Redhat
8Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+5 more
Apr 29, 2026
Oct 16, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JavaFX 2.2.40 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confi...Show more
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JavaFX 2.2.40 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.Show less
3Canonical
OracleRedhat
8Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+5 more
Apr 29, 2026
Oct 16, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and...Show more
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-5850.Show less
3Canonical
OracleRedhat
9Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+6 more
Apr 29, 2026
Oct 16, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows r...Show more
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.Show less
3Canonical
OracleRedhat
8Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+5 more
Apr 29, 2026
Oct 16, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and...Show more
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-5809.Show less
5Canonical
DebianMariadb+2 more
7Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+4 more
Apr 29, 2026
Oct 16, 2013
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.x through 5.5.32 and 5.6.x through 5.6.12 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Replication.
5Canonical
DebianMariadb+2 more
7Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+4 more
Apr 29, 2026
Oct 16, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.70 and earlier, 5.5.32 and earlier, and 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.70 and earlier, 5.5.32 and earlier, and 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.Show less
2Condor Project
Redhat
2Condor
Enterprise Mrg
Apr 29, 2026
Oct 11, 2013
N/A· v4
N/A· v3
3.5 LOW· v2
The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attributes in a (1) PREEMPT, (2) SUSPEND, (3) CONTINUE, (4) WANT_VACATE, or (5) KILL policy that evaluate to an Unconfigured, U...Show more
The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attributes in a (1) PREEMPT, (2) SUSPEND, (3) CONTINUE, (4) WANT_VACATE, or (5) KILL policy that evaluate to an Unconfigured, Undefined, or Error state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.Show less
2Condor Project
Redhat
2Condor
Enterprise Mrg
Apr 29, 2026
Oct 11, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The policy definition evaluator in Condor before 7.4.2 does not properly handle attributes in a WANT_SUSPEND policy that evaluate to an UNDEFINED state, which allows remote authenticated users to cause a denial of servic...Show more
The policy definition evaluator in Condor before 7.4.2 does not properly handle attributes in a WANT_SUSPEND policy that evaluate to an UNDEFINED state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.Show less
3Fedoraproject
LinuxRedhat
4Enterprise Linux
Enterprise MrgFedora+1 more
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via multiple request...Show more
Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via multiple requests for small amounts of data, leading to improper management of the state of the consumed data.Show less
2Redhat
Xinetd
2Enterprise Linux
Xinetd
Apr 29, 2026
Oct 10, 2013
N/A· v4
N/A· v3
7.6 HIGH· v2
xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vul...Show more
xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.Show less
2Gnu
Redhat
2Enterprise Linux
Glibc
Apr 29, 2026
Oct 9, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of service (heap corruption) via a large value to the (1) pvall...Show more
Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of service (heap corruption) via a large value to the (1) pvalloc, (2) valloc, (3) posix_memalign, (4) memalign, or (5) aligned_alloc functions.Show less
1Redhat
1Enterprise Mrg
Apr 29, 2026
Oct 9, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Cumin, as used in Red Hat Enterprise MRG 2.4, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted Ajax update request.
4Canonical
OpensuseQemu+1 more
7Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+4 more
Apr 29, 2026
Oct 4, 2013
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
1Redhat
1Storage Server
Apr 29, 2026
Oct 4, 2013
N/A· v4
N/A· v3
3.6 LOW· v2
Red Hat Storage 2.0 allows local users to overwrite arbitrary files via a symlink attack on the (1) e, (2) local-bricks.list, (3) bricks.err, or (4) limits.conf files in /tmp.
2Lennart Poettering
Redhat
2Enterprise Linux
Rkit
Apr 29, 2026
Oct 3, 2013
N/A· v4
N/A· v3
4.6 MEDIUM· v2
RealtimeKit (aka rtkit) 0.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race cond...Show more
RealtimeKit (aka rtkit) 0.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.Show less
2Redhat
Spice Gtk Project
2Enterprise Linux
Spice Gtk
Apr 29, 2026
Oct 3, 2013
N/A· v4
N/A· v3
4.6 MEDIUM· v2
spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUni...Show more
spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.Show less
2Canonical
Redhat
3Enterprise Linux
LibvirtUbuntu Linux
Apr 29, 2026
Oct 3, 2013
N/A· v4
N/A· v3
4.6 MEDIUM· v2
libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck v...Show more
libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.Show less