Redhat
redhat
5,653 CVEs • 536 products
Products (536)
Click to collapseToggle
Products (536)
Click to collapse
CVEs (5,653)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 1Jboss Enterprise Application Platform Apr 23, 2026 Dec 15, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in the Web Console in the Application Server in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2.0 before 4.2.0.CP08, 4.2.2GA, 4.3 before 4.3....Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 23, 2026 Dec 15, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in JMX-Console in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 allows remote attackers to inje...Show more |
7Canonical DebianLinux+4 more13Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+10 moreApr 23, 2026 Nov 20, 2009 N/A· v4 N/A· v3 7.2 HIGH· v2 Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an...Show more |
5Apple CanonicalDebian+2 more7Cups Debian LinuxEnterprise Linux+4 moreApr 23, 2026 Nov 20, 2009 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a de...Show more |
7Avaya CanonicalDebian+4 more18Aura Application Enablement Services Aura Communication ManagerAura Session Manager+15 moreApr 23, 2026 Nov 16, 2009 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file. |
8Canonical FedoraprojectLinux+5 more14Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+11 moreApr 23, 2026 Nov 4, 2009 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous...Show more |
2Qemu Redhat3Enterprise Linux Server Enterprise Linux WorkstationQemuApr 23, 2026 Oct 23, 2009 N/A· v4 9.9 CRITICAL· v3 8.5 HIGH· v2 Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1...Show more |
6Canonical FedoraprojectLinux+3 more8Fedora Linux Enterprise DebuginfoLinux Enterprise Desktop+5 moreApr 23, 2026 Oct 22, 2009 N/A· v4 7.8 HIGH· v3 4.9 MEDIUM· v2 The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointe...Show more |
6Canonical FedoraprojectLinux+3 more13Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+10 moreApr 23, 2026 Oct 20, 2009 N/A· v4 N/A· v3 2.1 LOW· v2 arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier...Show more |
3Canonical LinuxRedhat6Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+3 moreApr 23, 2026 Oct 19, 2009 N/A· v4 N/A· v3 2.1 LOW· v2 The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members,...Show more |
6Canonical FedoraprojectLinux+3 more12Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+9 moreApr 23, 2026 Aug 27, 2009 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereferen...Show more |
8Canonical FedoraprojectLinux+5 more12Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+9 moreApr 23, 2026 Aug 18, 2009 N/A· v4 N/A· v3 5.9 MEDIUM· v2 The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibl...Show more |
4Debian LinuxRedhat+1 more8Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+5 moreApr 23, 2026 Aug 14, 2009 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference...Show more |
11Apple CanonicalDebian+8 more19Chrome Debian LinuxEnterprise Linux+16 moreApr 23, 2026 Aug 11, 2009 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notatio...Show more |
The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file, related...Show more |
5Apache CanonicalDebian+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 23, 2026 Jul 10, 2009 N/A· v4 N/A· v3 7.1 HIGH· v2 The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU co...Show more |
5Apache CanonicalDebian+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 23, 2026 Jul 5, 2009 N/A· v4 N/A· v3 7.1 HIGH· v2 The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the...Show more |
4Debian FedoraprojectMozilla+1 more9Debian Linux Enterprise LinuxEnterprise Linux Desktop+6 moreApr 23, 2026 Jun 12, 2009 N/A· v4 7.5 HIGH· v3 9.3 HIGH· v2 Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transiti...Show more |
3Canonical OpensslRedhat3Openssl OpensslUbuntu LinuxApr 23, 2026 Jun 4, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS h...Show more |
3Canonical OpensslRedhat3Openssl OpensslUbuntu LinuxApr 23, 2026 Jun 4, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello. |