← Back

Redhat

redhat

5,653 CVEs • 533 products

Products (533)

Click to collapse
Toggle
Linux
linux
Satellite
satellite
Openstack
openstack
Openshift
openshift
Keycloak
keycloak
Fedora Core
fedora_core
Libvirt
libvirt
Ansible Tower
ansible_tower
Cloudforms
cloudforms
Ansible
ansible
Ceph Storage
ceph_storage
Linux Desktop
linux_desktop
Linux Server
linux_server
Jboss Fuse
jboss_fuse
Undertow
undertow
Storage
storage
Quay
quay
Fuse
fuse
Data Grid
data_grid
Resteasy
resteasy
Wildfly
wildfly
Jboss A Mq
jboss_a-mq
Ceph
ceph

CVEs (5,653)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Freeradius
Redhat
3Enterprise Linux
Fedora CoreFreeradius
Apr 16, 2026
Feb 9, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.
6Openpkg
OracleRedhat+3 more
7Enterprise Linux
Enterprise Linux DesktopMysql+4 more
Apr 16, 2026
Feb 9, 2005
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow th...Show more
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.Show less
7Ibm
Larry WallRedhat+4 more
9Aix
Enterprise LinuxEnterprise Linux Desktop+6 more
Apr 16, 2026
Feb 7, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose...Show more
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.Show less
5Conectiva
GentooRedhat+2 more
8Enterprise Linux
Enterprise Linux DesktopFedora Core+5 more
Apr 16, 2026
Jan 27, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) charac...Show more
The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.Show less
6Gentoo
OpenpkgRedhat+3 more
6Fedora Core
LinuxOpenpkg+3 more
Apr 16, 2026
Jan 27, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length f...Show more
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.Show less
4Conectiva
MozillaRedhat+1 more
9Enterprise Linux
Enterprise Linux DesktopFedora Core+6 more
Apr 16, 2026
Jan 27, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code...Show more
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.Show less
4Conectiva
MozillaRedhat+1 more
9Enterprise Linux
Enterprise Linux DesktopFedora Core+6 more
Apr 16, 2026
Jan 27, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbi...Show more
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII hostname.Show less
11Debian
Easy Software ProductsGentoo+8 more
16Cups
Debian LinuxEnterprise Linux+13 more
Apr 16, 2026
Jan 27, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilit...Show more
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.Show less
11Debian
Easy Software ProductsGentoo+8 more
16Cups
Debian LinuxEnterprise Linux+13 more
Apr 16, 2026
Jan 27, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code,...Show more
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.Show less
9Apple
KdeLibtiff+6 more
13Enterprise Linux
Enterprise Linux DesktopFedora Core+10 more
Apr 16, 2026
Jan 27, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
4Conectiva
RedhatSamba+1 more
7Enterprise Linux
Enterprise Linux DesktopFedora Core+4 more
Apr 16, 2026
Jan 27, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.
4Gnu
RedhatSgi+1 more
4Enscript
Fedora CorePropack+1 more
Apr 16, 2026
Jan 21, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.
2Linux
Redhat
2Enterprise Linux
Linux Kernel
Apr 16, 2026
Jan 21, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Multiple drivers in Linux kernel 2.4.19 and earlier do not properly mark memory with the VM_IO flag, which causes incorrect reference counts and may lead to a denial of service (kernel panic) when accessing freed kernel...Show more
Multiple drivers in Linux kernel 2.4.19 and earlier do not properly mark memory with the VM_IO flag, which causes incorrect reference counts and may lead to a denial of service (kernel panic) when accessing freed kernel pages.Show less
2Easy Software Products
Redhat
2Cups
Fedora Core
Apr 16, 2026
Jan 10, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows loc...Show more
lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.Show less
2Easy Software Products
Redhat
2Cups
Fedora Core
Apr 16, 2026
Jan 10, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.
2Easy Software Products
Redhat
2Cups
Fedora Core
Apr 16, 2026
Jan 10, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local users to corrupt the file by filling the associated file system and triggering the write errors.
2Easy Software Products
Redhat
2Cups
Fedora Core
Apr 16, 2026
Jan 10, 2005
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.
3Kde
MandrakesoftRedhat
3Fedora Core
KdeMandrake Linux
Apr 16, 2026
Jan 10, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user's .desktop file, which m...Show more
KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user's .desktop file, which may be created with world-readable permissions, which could allow local users to obtain usernames and passwords for remote resources such as SMB shares.Show less
3Kde
MandrakesoftRedhat
3Fedora Core
KonquerorMandrake Linux
Apr 16, 2026
Jan 10, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a differe...Show more
Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.Show less
4Redhat
SambaSuse+1 more
4Fedora Core
SambaSecure Linux+1 more
Apr 16, 2026
Jan 10, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request...Show more
Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.Show less