Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 1Enterprise Virtualization Manager Apr 29, 2026 Jan 4, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading deployUtil.py and vds_bootstrap.py, which prevents SSL certificates from...Show more |
1Redhat 1Enterprise Virtualization Manager Apr 29, 2026 Jan 4, 2013 N/A· v4 N/A· v3 6.2 MEDIUM· v2 Multiple untrusted search path vulnerabilities in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, allow local users to gain privileges via a Trojan horse (1) deployUtil.py or (2) vds_bo...Show more |
1Redhat 1Enterprise Virtualization Manager Apr 29, 2026 Jan 4, 2013 N/A· v4 N/A· v3 3.7 LOW· v2 Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, in certain unspecified conditions, does not lock the desktop screen between SPICE sessions, which allows local users with access to a virtual machine to gain...Show more |
Cross-site request forgery (CSRF) vulnerability in the management console (openshift-console/app/controllers/application_controller.rb) in OpenShift 0.0.5 allows remote attackers to hijack the authentication of arbitrary...Show more |
3Mariadb OracleRedhat7Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+4 moreApr 29, 2026 Dec 3, 2012 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXM...Show more |
7Canonical DebianOpensuse+4 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+10 moreApr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 7.2 HIGH· v2 Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers t...Show more |
1Redhat 1Jboss Enterprise Data Services Platform Apr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The Teiid Java Database Connectivity (JDBC) socket, as used in JBoss Enterprise Data Services Platform before 5.3.0, does not encrypt login messages by default contrary to documentation and specification, which allows re...Show more |
1Redhat 3Jboss Enterprise Brms Platform Jboss Enterprise Portal PlatformJboss Enterprise Soa PlatformApr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 3.3 LOW· v2 JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Soa Platform+1 moreApr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to...Show more |
RESTEasy before 2.3.1 allows remote attackers to read arbitrary files via an external entity reference in a DOM document, aka an XML external entity (XXE) injection attack. |
The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, a...Show more |
1Redhat 5Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Portal Platform+2 moreApr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 7.5 HIGH· v2 The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2.0.CP05 and 4.3.0.CP05, Portal Platform...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss Enterprise Brms PlatformJboss Enterprise Portal Platform+1 moreApr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the...Show more |
1Redhat 3Jboss Enterprise Brms Platform Jboss Enterprise Portal PlatformJboss Enterprise Soa PlatformApr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.0 before roll up patch1, and SOA Platform 5.3.0 allows remote authentic...Show more |
1Redhat 1Jboss Enterprise Portal Platform Apr 29, 2026 Nov 23, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 5.2.2 and other products, when using block ciphers in cipher-block chaining (CBC) mode, al...Show more |
6Canonical DebianMozilla+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+11 moreApr 29, 2026 Nov 21, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow re...Show more |
5Canonical MozillaOpensuse+2 more13Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+10 moreApr 29, 2026 Nov 21, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 implement cross-origin wrappers with a filtering behavior that does no...Show more |
5Canonical MozillaOpensuse+2 more13Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+10 moreApr 29, 2026 Nov 21, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey b...Show more |
5Canonical MozillaOpensuse+2 more13Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+10 moreApr 29, 2026 Nov 21, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 Heap-based buffer overflow in the gfxShapedWord::CompressedGlyph::IsClusterStart function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and...Show more |
5Canonical MozillaOpensuse+2 more13Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+10 moreApr 29, 2026 Nov 21, 2012 N/A· v4 N/A· v3 10.0 HIGH· v2 Integer overflow in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to...Show more |