Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Jboss Community Application Server Jboss Enterprise Application PlatformApr 29, 2026 Aug 13, 2012 N/A· v4 N/A· v3 2.1 LOW· v2 twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments. |
2Redhat Todd Miller2Enterprise Linux SudoApr 29, 2026 Aug 8, 2012 N/A· v4 N/A· v3 5.6 MEDIUM· v2 A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file. |
The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) v...Show more |
The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or e...Show more |
The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) a...Show more |
5Apache CanonicalDebian+2 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreApr 29, 2026 Aug 6, 2012 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitr...Show more |
4Debian Opensuse ProjectPostgresql+1 more11Debian Linux Desktop WorkstationEnterprise Linux+8 moreApr 29, 2026 Jul 18, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host...Show more |
3Mariadb OracleRedhat6Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+3 moreApr 29, 2026 Jul 17, 2012 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier, and 5.5.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer. |
3Mariadb OracleRedhat6Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+3 moreApr 29, 2026 Jul 17, 2012 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier, and 5.5.22 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer. |
3Mariadb OracleRedhat6Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+3 moreApr 29, 2026 Jul 17, 2012 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier and 5.5.23 and earlier allows remote authenticated users to affect availability, related to GIS Extension. |
Integer signedness error in attach.c in dtach 0.8 allows remote attackers to obtain sensitive information from daemon stack memory in opportunistic circumstances by reading application data after an improper connection-c...Show more |
6Canonical DebianLibexpat Project+3 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreApr 29, 2026 Jul 3, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU co...Show more |
2Fedoraproject Redhat2389 Directory Server Directory ServerApr 29, 2026 Jul 3, 2012 N/A· v4 N/A· v3 2.1 LOW· v2 389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which...Show more |
2Fedoraproject Redhat2389 Directory Server Directory ServerApr 29, 2026 Jul 3, 2012 N/A· v4 N/A· v3 1.2 LOW· v2 389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext...Show more |
The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option i...Show more |
The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging inform...Show more |
3Apache LibwpdRedhat4Enterprise Linux Optional Productivity Applications Enterprise Linux DesktopLibwpd+1 moreApr 29, 2026 Jun 21, 2012 N/A· v4 N/A· v3 7.5 HIGH· v2 The WPXContentListener::_closeTableRow function in WPXContentListener.cpp in libwpd 0.8.8, as used by OpenOffice.org (OOo) before 3.4, allows remote attackers to execute arbitrary code via a crafted Wordperfect .WPD docu...Show more |
5Apache DebianFedoraproject+2 more10Debian Linux Enterprise LinuxEnterprise Linux Desktop+7 moreApr 29, 2026 Jun 21, 2012 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly ex...Show more |
libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and mi...Show more |
6Apache DebianFedoraproject+3 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+10 moreApr 29, 2026 Jun 17, 2012 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via...Show more |