Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Mariadb OracleRedhat6Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+3 moreApr 29, 2026 Apr 17, 2013 N/A· v4 N/A· v3 3.5 LOW· v2 Unspecified vulnerability in Oracle MySQL 5.1.63 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Types. |
3Mariadb OracleRedhat7Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+4 moreApr 29, 2026 Apr 17, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language. |
3Mariadb OracleRedhat7Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+4 moreApr 29, 2026 Apr 17, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Information Schema. |
3Mariadb OracleRedhat7Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+4 moreApr 29, 2026 Apr 17, 2013 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Server Privilege...Show more |
3Mariadb OracleRedhat7Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+4 moreApr 29, 2026 Apr 17, 2013 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Unspecified vulnerability in Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Server Locking. |
3Mariadb OracleRedhat7Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+4 moreApr 29, 2026 Apr 17, 2013 N/A· v4 N/A· v3 2.8 LOW· v2 Unspecified vulnerability in Oracle MySQL 5.1.67 and earlier, 5.5.29 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Locking. |
1Redhat 1Jboss Enterprise Portal Platform Apr 29, 2026 Apr 12, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 allows remote attackers to read arbitrary files via a crafted external XML entity in an XML document, aka an XML Entity Expansion (XEE) att...Show more |
1Redhat 1Jboss Enterprise Portal Platform Apr 29, 2026 Apr 12, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, which allows remote attackers to modify site contents, remove the site, or...Show more |
1Redhat 1Jboss Enterprise Portal Platform Apr 29, 2026 Apr 12, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in the GateIn Portal component in JBoss Enterprise Portal Platform 5.2.2 and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown...Show more |
1Redhat 3Openstack Essex Openstack FolsomPackstackApr 30, 2026 Apr 10, 2013 N/A· v4 6.1 MEDIUM· v3 4.4 MEDIUM· v2 A flaw was found in PackStack. This vulnerability allows a local user to modify deployed systems by changing the answer file, which is created in insecure directories such as /tmp or the current working directory. This i...Show more |
1Redhat 2Openstack Essex Openstack FolsomApr 29, 2026 Apr 10, 2013 N/A· v4 N/A· v3 2.1 LOW· v2 Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files. |
2Gluster Redhat4Glusterfs Storage Management ConsoleStorage Native Client+1 moreApr 29, 2026 Apr 9, 2013 N/A· v4 N/A· v3 2.1 LOW· v2 The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/v...Show more |
4Canonical MozillaOracle+1 more12Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+9 moreApr 29, 2026 Apr 3, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMo...Show more |
The default configuration for IPA servers in Red Hat Enterprise Linux 6, when revoking a certificate from an Identity Management replica, does not properly update another Identity Management replica, which causes inconsi...Show more |
Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field. |
2Candlepinproject Redhat2Candlepin Subscription Asset ManagerApr 29, 2026 Apr 2, 2013 N/A· v4 N/A· v3 2.1 LOW· v2 Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests. |
7Canonical DebianMariadb+4 more9Debian Linux Enterprise LinuxLinux Enterprise Desktop+6 moreApr 29, 2026 Mar 28, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of...Show more |
libvirt 1.0.2 and earlier sets the group owner to kvm for device files, which allows local users to write to these files via unspecified vectors. |
2Redhat Rubyonrails3Enterprise Linux RailsRuby On RailsApr 29, 2026 Mar 19, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly han...Show more |
2Redhat Rubyonrails3Enterprise Linux RailsRuby On RailsApr 29, 2026 Mar 19, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly...Show more |