← Back

Redhat

redhat

5,899 CVEs • 544 products

Products (544)

Click to collapse
Toggle
Satellite
satellite
Linux
linux
Openstack
openstack
Openshift
openshift
Keycloak
keycloak
Fedora Core
fedora_core
Libvirt
libvirt
Ansible Tower
ansible_tower
Cloudforms
cloudforms
Ansible
ansible
Ceph Storage
ceph_storage
Linux Desktop
linux_desktop
Linux Server
linux_server
Jboss Fuse
jboss_fuse
Undertow
undertow
Quay
quay
Storage
storage
Fuse
fuse
Data Grid
data_grid
Resteasy
resteasy
Wildfly
wildfly
Jboss A Mq
jboss_a-mq
Ceph
ceph

CVEs (5,899)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Redhat
Rubyonrails
3Enterprise Linux
RailsRuby On Rails
Apr 29, 2026
Mar 19, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial...Show more
The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.Show less
2Linux
Redhat
2Enterprise Mrg
Linux Kernel
Apr 29, 2026
Mar 15, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect length value during a copy operation, which allows local u...Show more
The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect length value during a copy operation, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability.Show less
2Linux
Redhat
2Enterprise Mrg
Linux Kernel
Apr 29, 2026
Mar 15, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 does not initialize certain structure members, which allows local users to o...Show more
The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 does not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability.Show less
2Linux
Redhat
2Enterprise Mrg
Linux Kernel
Apr 29, 2026
Mar 15, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
The report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect C library function for copying strings, which allows local users to obtain sensitive information from kernel stack m...Show more
The report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect C library function for copying strings, which allows local users to obtain sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN capability.Show less
2Linux
Redhat
2Enterprise Linux
Linux Kernel
Apr 29, 2026
Mar 15, 2013
N/A· v4
N/A· v3
1.9 LOW· v2
The udf_encode_fh function in fs/udf/namei.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted a...Show more
The udf_encode_fh function in fs/udf/namei.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application.Show less
2Linux
Redhat
2Enterprise Linux
Linux Kernel
Apr 29, 2026
Mar 15, 2013
N/A· v4
N/A· v3
1.9 LOW· v2
The ATM implementation in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
2Linux
Redhat
2Enterprise Linux
Linux Kernel
Apr 29, 2026
Mar 15, 2013
N/A· v4
N/A· v3
1.9 LOW· v2
The Bluetooth RFCOMM implementation in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel memory via a crafted application.
2Linux
Redhat
2Enterprise Linux
Linux Kernel
Apr 29, 2026
Mar 15, 2013
N/A· v4
N/A· v3
1.9 LOW· v2
The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application tha...Show more
The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that targets the (1) L2CAP or (2) HCI implementation.Show less
2Linux
Redhat
2Enterprise Linux
Linux Kernel
Apr 29, 2026
Mar 15, 2013
N/A· v4
N/A· v3
1.9 LOW· v2
The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 has an incorrect return value in certain circumstances, which allows local users to obtain sensitive information from kernel stack memory via...Show more
The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 has an incorrect return value in certain circumstances, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that leverages an uninitialized pointer argument.Show less
2Linux
Redhat
2Enterprise Linux
Linux Kernel
Apr 29, 2026
Mar 15, 2013
N/A· v4
N/A· v3
1.9 LOW· v2
The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive information from kernel heap m...Show more
The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability.Show less
2Linux
Redhat
2Enterprise Linux
Linux Kernel
Apr 29, 2026
Mar 15, 2013
N/A· v4
N/A· v3
1.9 LOW· v2
net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability.
2Condor Project
Redhat
2Condor
Enterprise Mrg
Apr 29, 2026
Mar 14, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
aviary/jobcontrol.py in Condor, as used in Red Hat Enterprise MRG 2.3, when removing a job, allows remote attackers to cause a denial of service (condor_schedd restart) via square brackets in the cproc option.
1Redhat
1Enterprise Virtualization Manager
Apr 29, 2026
Mar 12, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The MoveDisk command in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier does not properly check permissions on storage domains, which allows remote authenticated storage admins to cause a denial of ser...Show more
The MoveDisk command in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier does not properly check permissions on storage domains, which allows remote authenticated storage admins to cause a denial of service (free space consumption of other storage domains) via unspecified vectors.Show less
1Redhat
1Enterprise Virtualization Manager
Apr 29, 2026
Mar 12, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
The domain management tool (rhevm-manage-domains) in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier, when the validate action is enabled, logs the administrative password to a world-readable log file,...Show more
The domain management tool (rhevm-manage-domains) in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier, when the validate action is enabled, logs the administrative password to a world-readable log file, which allows local users to obtain sensitive information by reading this file.Show less
1Redhat
1Automatic Bug Reporting Tool
Apr 29, 2026
Mar 12, 2013
N/A· v4
N/A· v3
6.9 MEDIUM· v2
abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the di...Show more
abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes."Show less
1Redhat
1Automatic Bug Reporting Tool
Apr 29, 2026
Mar 12, 2013
N/A· v4
N/A· v3
3.7 LOW· v2
Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute arbitrary Python modules by mod...Show more
Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute arbitrary Python modules by modifying the PYTHONPATH environment variable to reference a malicious Python module.Show less
1Redhat
2Jboss Enterprise Application Platform
Jboss Enterprise Web Platform
Apr 29, 2026
Mar 12, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote at...Show more
The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.Show less
1Redhat
1Aeolus Conductor
Apr 29, 2026
Mar 12, 2013
N/A· v4
N/A· v3
5.5 MEDIUM· v2
The Administer tab in Aeolus Conductor allows remote authenticated users to bypass intended quota restrictions by updating the Maximum Running Instances quota user setting.
1Redhat
1Cloudforms Cloud Engine
Apr 29, 2026
Mar 12, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext password...Show more
Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.Show less
1Redhat
1Cloudforms Cloud Engine
Apr 29, 2026
Mar 12, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
aeolus-configserver-setup in the Aeolas Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for a temporary file in /tmp, which allows local users to read creden...Show more
aeolus-configserver-setup in the Aeolas Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for a temporary file in /tmp, which allows local users to read credentials by reading this file.Show less