← Back

Redhat

redhat

5,899 CVEs • 544 products

Products (544)

Click to collapse
Toggle
Satellite
satellite
Linux
linux
Openstack
openstack
Openshift
openshift
Keycloak
keycloak
Fedora Core
fedora_core
Libvirt
libvirt
Ansible Tower
ansible_tower
Cloudforms
cloudforms
Ansible
ansible
Ceph Storage
ceph_storage
Linux Desktop
linux_desktop
Linux Server
linux_server
Jboss Fuse
jboss_fuse
Undertow
undertow
Quay
quay
Storage
storage
Fuse
fuse
Data Grid
data_grid
Resteasy
resteasy
Wildfly
wildfly
Jboss A Mq
jboss_a-mq
Ceph
ceph

CVEs (5,899)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Opensuse
RedhatSun+1 more
4Enterprise Linux
OpensuseSunos+1 more
Apr 29, 2026
Aug 16, 2012
N/A· v4
N/A· v3
3.3 LOW· v2
The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (...Show more
The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a zero-length message.Show less
4Adobe
OpensuseRedhat+1 more
6Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+3 more
Apr 22, 2026
Aug 15, 2012
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application cra...Show more
Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted SWF content, as exploited in the wild in August 2012 with SWF content in a Word document.Show less
5Canonical
DebianLibpng+2 more
5Debian Linux
LibpngLibpng+2 more
Apr 29, 2026
Aug 13, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (out-of-bounds read) via...Show more
The png_push_read_zTXt function in pngpread.c in libpng 1.0.x before 1.0.58, 1.2.x before 1.2.48, 1.4.x before 1.4.10, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large avail_in field value in a PNG image.Show less
1Redhat
2Certificate System
Dogtag Certificate System
Apr 29, 2026
Aug 13, 2012
N/A· v4
N/A· v3
5.5 MEDIUM· v2
Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the web interface, which allows remote attackers with permissions to revok...Show more
Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the web interface, which allows remote attackers with permissions to revoke end entity certificates to revoke the Certificate Authority (CA) certificate.Show less
1Redhat
2Certificate System
Dogtag Certificate System
Apr 29, 2026
Aug 13, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System allow remote attackers to inject arbitrary web script or HTML via unspecified parameters...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to the (1) System Agent or (2) End Entity pages.Show less
1Redhat
2Jboss Community Application Server
Jboss Enterprise Application Platform
Apr 29, 2026
Aug 13, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.
2Redhat
Todd Miller
2Enterprise Linux
Sudo
Apr 29, 2026
Aug 8, 2012
N/A· v4
N/A· v3
5.6 MEDIUM· v2
A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file.
1Redhat
1Libvirt
Apr 29, 2026
Aug 7, 2012
N/A· v4
N/A· v3
3.5 LOW· v2
The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) v...Show more
The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.Show less
1Redhat
1Icedtea Web
Apr 29, 2026
Aug 7, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or e...Show more
The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.Show less
1Redhat
1Icedtea Web
Apr 29, 2026
Aug 7, 2012
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) a...Show more
The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.Show less
5Apache
CanonicalDebian+2 more
11Debian Linux
Enterprise LinuxEnterprise Linux Desktop+8 more
Apr 29, 2026
Aug 6, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitr...Show more
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.Show less
4Debian
Opensuse ProjectPostgresql+1 more
11Debian Linux
Desktop WorkstationEnterprise Linux+8 more
Apr 29, 2026
Jul 18, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host...Show more
PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters.Show less
3Mariadb
OracleRedhat
6Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+3 more
Apr 29, 2026
Jul 17, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier, and 5.5.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
3Mariadb
OracleRedhat
6Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+3 more
Apr 29, 2026
Jul 17, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier, and 5.5.22 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
3Mariadb
OracleRedhat
6Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+3 more
Apr 29, 2026
Jul 17, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.1.62 and earlier and 5.5.23 and earlier allows remote authenticated users to affect availability, related to GIS Extension.
1Redhat
1Dtach
Apr 29, 2026
Jul 3, 2012
N/A· v4
N/A· v3
2.6 LOW· v2
Integer signedness error in attach.c in dtach 0.8 allows remote attackers to obtain sensitive information from daemon stack memory in opportunistic circumstances by reading application data after an improper connection-c...Show more
Integer signedness error in attach.c in dtach 0.8 allows remote attackers to obtain sensitive information from daemon stack memory in opportunistic circumstances by reading application data after an improper connection-close request, as demonstrated by running an IRC client in dtach.Show less
6Canonical
DebianLibexpat Project+3 more
11Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+8 more
Apr 29, 2026
Jul 3, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU co...Show more
The XML parser (xmlparse.c) in expat before 2.1.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML file with many identifiers with the same value.Show less
2Fedoraproject
Redhat
2389 Directory Server
Directory Server
Apr 29, 2026
Jul 3, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which...Show more
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which allows remote authenticated users to read the password.Show less
2Fedoraproject
Redhat
2389 Directory Server
Directory Server
Apr 29, 2026
Jul 3, 2012
N/A· v4
N/A· v3
1.2 LOW· v2
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext...Show more
389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers to read the plaintext password via the unhashed#user#password attribute.Show less
1Redhat
1Automatic Bug Reporting Tool
Apr 29, 2026
Jul 3, 2012
N/A· v4
N/A· v3
1.9 LOW· v2
The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option i...Show more
The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.Show less