Redhat
redhat
5,653 CVEs • 536 products
Products (536)
Click to collapseToggle
Products (536)
Click to collapse
CVEs (5,653)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Jboss Enterprise Service Bus Jboss Enterprise Soa PlatformApr 29, 2026 Aug 10, 2010 N/A· v4 N/A· v3 3.5 LOW· v2 JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain...Show more |
2Netapp Redhat4Jboss Enterprise Application Platform Oncommand BalanceOncommand Insight+1 moreApr 22, 2026 Aug 5, 2010 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to exe...Show more |
LibTIFF in Red Hat Enterprise Linux (RHEL) 3 on x86_64 platforms, as used in tiff2rgba, attempts to process image data even when the required compression functionality is not configured, which allows remote attackers to...Show more |
1Redhat 1Enterprise Virtualization Manager Apr 29, 2026 Jun 24, 2010 N/A· v4 N/A· v3 2.1 LOW· v2 The snapshot merging functionality in Red Hat Enterprise Virtualization Manager (aka RHEV-M) before 2.2 does not properly pass the postzero parameter during operations on deleted volumes, which allows guest OS users to o...Show more |
1Redhat 1Enterprise Virtualization Hypervisor Apr 29, 2026 Jun 24, 2010 N/A· v4 N/A· v3 2.1 LOW· v2 Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a virtual machine's data...Show more |
4Apple FedoraprojectRedhat+1 more7Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+4 moreApr 29, 2026 Jun 22, 2010 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number. |
yum-rhn-plugin in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Enterprise Linux (RHEL) 5 and Fedora uses world-readable permissions for the /var/spool/up2date/loginAuth.pkl file, which allows local user...Show more |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 29, 2026 May 12, 2010 N/A· v4 N/A· v3 2.6 LOW· v2 The MMIO instruction decoder in the Xen hypervisor in the Linux kernel 2.6.18 in Red Hat Enterprise Linux (RHEL) 5 allows guest OS users to cause a denial of service (32-bit guest OS crash) via vectors that trigger an un...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 29, 2026 Apr 28, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request t...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 22, 2026 Apr 28, 2010 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST met...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 22, 2026 Apr 28, 2010 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST metho...Show more |
A certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 4 on the ia64 platform allows local users to use ptrace on an arbitrary process, and consequently gain privileges, via vectors related to a...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelApr 29, 2026 Mar 16, 2010 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The gfs2_lock function in the Linux kernel before 2.6.34-rc1-next-20100312, and the gfs_lock function in the Linux kernel on Red Hat Enterprise Linux (RHEL) 5 and 6, does not properly remove POSIX locks on files that are...Show more |
4Apple CanonicalFedoraproject+1 more10Cups Enterprise LinuxEnterprise Linux Desktop+7 moreApr 29, 2026 Mar 5, 2010 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows rem...Show more |
2Linux Redhat6Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+3 moreApr 29, 2026 Jan 27, 2010 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (deadlock) via crafted packets that force collisions in th...Show more |
2Linux Redhat2Enterprise Linux Linux KernelApr 29, 2026 Jan 27, 2010 N/A· v4 N/A· v3 1.9 LOW· v2 A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the...Show more |
Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors t...Show more |
6Adium FedoraprojectOpensuse+3 more7Adium Enterprise LinuxFedora+4 moreApr 23, 2026 Jan 9, 2010 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emo...Show more |
2Condor Project Redhat2Condor Enterprise MrgApr 23, 2026 Dec 23, 2009 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as an arbitrary user, and thereby gain privileges, by using a Con...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 23, 2026 Dec 15, 2009 N/A· v4 N/A· v3 2.1 LOW· v2 Twiddle in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 writes the JMX password, and other command-line arguments, to the twiddle.log file, which...Show more |