Redhat
redhat
5,655 CVEs • 536 products
Products (536)
Click to collapseToggle
Products (536)
Click to collapse
CVEs (5,655)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to tric...Show more |
Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin...Show more |
The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPermission method instead of throwing an exception in certain circumstances...Show more |
3Linux RedhatVmware3Enterprise Mrg EsxLinux KernelApr 29, 2026 Jan 11, 2011 N/A· v4 N/A· v3 7.1 HIGH· v2 Race condition in the sctp_icmp_proto_unreachable function in net/sctp/input.c in Linux kernel 2.6.11-rc2 through 2.6.33 allows remote attackers to cause a denial of service (panic) via an ICMP unreachable message to a s...Show more |
Integer overflow in the TFM font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the...Show more |
Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (applica...Show more |
Array index error in the VF font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted fo...Show more |
Array index error in the PK font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted fo...Show more |
1Redhat 3Jboss Enterprise Application Platform Jboss Enterprise Web PlatformJboss RemotingApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 2.6 LOW· v2 The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in the JMX Console in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 allows remote attackers to hijack the authentication of a...Show more |
1Redhat 3Jboss Enterprise Application Platform Jboss Enterprise Web PlatformJboss RemotingApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 2.6 LOW· v2 The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform...Show more |
1Redhat 2Jboss Enterprise Application Platform Jboss Enterprise Soa PlatformApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 7.5 HIGH· v2 The serialization implementation in JBoss Drools in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 and JBoss Enterprise SOA Platform 4.2 and 4.3 supports the embedding of cla...Show more |
2Linux Redhat2Enterprise Linux Linux KernelApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The udp_queue_rcv_skb function in net/ipv4/udp.c in a certain Red Hat build of the Linux kernel 2.6.18 in Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (deadlock and system hang) by send...Show more |
3Linux RedhatSuse6Enterprise Linux Server Enterprise Linux WorkstationLinux Kernel+3 moreApr 29, 2026 Dec 23, 2010 N/A· v4 N/A· v3 2.1 LOW· v2 arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on t...Show more |
IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which allows remote attackers to obtain sensitive information including (1)...Show more |
1Redhat 2Enterprise Virtualization Manager Spice ActivexApr 29, 2026 Dec 8, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain priv...Show more |
The installation documentation for Red Hat Enterprise Messaging, Realtime and Grid (MRG) 1.3 recommends that Condor should be configured so that the MRG Management Console (cumin) can submit jobs for users, which creates...Show more |
10Apache AppleDebian+7 more17Chrome Debian LinuxEnterprise Linux Desktop+14 moreApr 29, 2026 Dec 7, 2010 N/A· v4 N/A· v3 7.5 HIGH· v2 Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impac...Show more |
6Canonical LinuxOpensuse+3 more8Enterprise Linux EsxiLinux Enterprise Desktop+5 moreApr 21, 2026 Dec 6, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allo...Show more |
1Redhat 2Certificate System Dogtag Certificate SystemApr 29, 2026 Nov 17, 2010 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System allow remote authenticated users to generate an arbitrary number of certificates by replaying a single SCEP one-time PIN. |