Redhat
redhat
5,653 CVEs • 536 products
Products (536)
Click to collapseToggle
Products (536)
Click to collapse
CVEs (5,653)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Certificate System Dogtag Certificate SystemApr 23, 2026 May 27, 2009 N/A· v4 N/A· v3 6.5 MEDIUM· v2 agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitr...Show more |
4Branden Robinson DebianRedhat+1 more4Debian Linux FedoraLinux+1 moreApr 23, 2026 May 6, 2009 N/A· v4 N/A· v3 4.6 MEDIUM· v2 xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its...Show more |
Cross-site scripting (XSS) vulnerability in C2Net Stronghold 2.3 allows remote attackers to inject arbitrary web script or HTML via the URI. |
5Apple CanonicalFedoraproject+2 more9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 23, 2026 Apr 9, 2009 N/A· v4 N/A· v3 10.0 HIGH· v2 The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or p...Show more |
Buffer overflow in CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9 and Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (CPU consumption and memory corruption) via a cluster.conf fi...Show more |
2Fedoraproject Redhat5Cluster Project CmanFedora+2 moreApr 23, 2026 Mar 30, 2009 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 23, 2026 Mar 9, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL fi...Show more |
6Canonical DebianLinux+3 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreApr 23, 2026 Mar 6, 2009 N/A· v4 N/A· v3 3.6 LOW· v2 The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, whic...Show more |
4Net Snmp OpensuseRedhat+1 more4Enterprise Linux Linux EnterpriseNet Snmp+1 moreApr 23, 2026 Feb 12, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to...Show more |
1Redhat 2 Dogtag Certificate System Certificate SystemApr 23, 2026 Jan 30, 2009 N/A· v4 N/A· v3 6.0 MEDIUM· v2 The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate System 1.0 returns successfully even when token enrollment did not use t...Show more |
Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local...Show more |
Red Hat Certificate System 7.2 uses world-readable permissions for password.conf and unspecified other configuration files, which allows local users to discover passwords by reading these files. |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 23, 2026 Nov 27, 2008 N/A· v4 N/A· v3 6.8 MEDIUM· v2 tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to the OpenPegasus CIM server, which makes it easier for remote attackers t...Show more |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 23, 2026 Nov 27, 2008 N/A· v4 N/A· v3 6.0 MEDIUM· v2 A certain Red Hat patch for tog-pegasus in OpenGroup Pegasus 2.7.0 does not properly configure the PAM tty name, which allows remote authenticated users to bypass intended access restrictions and send requests to OpenPeg...Show more |
A certain Fedora patch for the utrace subsystem in the Linux kernel before 2.6.26.5-28 on Fedora 8, and before 2.6.26.5-45 on Fedora 9, allows local users to cause a denial of service (NULL pointer dereference and system...Show more |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 23, 2026 Oct 3, 2008 N/A· v4 N/A· v3 4.4 MEDIUM· v2 pam_krb5 2.2.14 in Red Hat Enterprise Linux (RHEL) 5 and earlier, when the existing_ticket option is enabled, uses incorrect privileges when reading a Kerberos credential cache, which allows local users to gain privilege...Show more |
2Jasper Project Redhat2Enterprise Virtualization JasperApr 23, 2026 Oct 2, 2008 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelApr 23, 2026 Sep 29, 2008 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allo...Show more |
The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file. |
rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary files via a symlink attack on a file or directory under (1) /var/lock or (2) /var/run. |