Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Enterprise Virtualization KvmApr 29, 2026 Aug 24, 2010 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2, and KVM 83, when the Intel VT-x extension is enabled, allows guest OS users to cause a denial of service (NULL pointer dereference and...Show more |
1Redhat 2Enterprise Virtualization KvmApr 29, 2026 Aug 24, 2010 N/A· v4 N/A· v3 6.6 MEDIUM· v2 QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly validate guest QXL driver pointers, which allows guest OS users to cause a denial of...Show more |
1Redhat 2Enterprise Virtualization QspiceApr 29, 2026 Aug 24, 2010 N/A· v4 N/A· v3 6.6 MEDIUM· v2 libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly restrict the addresses upon which memory-management actions are pe...Show more |
1Redhat 2Enterprise Virtualization QspiceApr 29, 2026 Aug 24, 2010 N/A· v4 N/A· v3 6.6 MEDIUM· v2 libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly validate guest QXL driver pointers, which allows guest OS users to...Show more |
The (1) setup-ds.pl and (2) setup-ds-admin.pl setup scripts for Red Hat Directory Server 8 before 8.2 use world-readable permissions when creating cache files, which allows local users to obtain sensitive information inc...Show more |
1Redhat 1Jboss Enterprise Soa Platform Apr 29, 2026 Aug 10, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The default configuration of the deployment descriptor (aka web.xml) in picketlink-sts.war in (1) the security_saml quickstart, (2) the webservice_proxy_security quickstart, (3) the web-console application, (4) the http-...Show more |
1Redhat 2Jboss Enterprise Service Bus Jboss Enterprise Soa PlatformApr 29, 2026 Aug 10, 2010 N/A· v4 N/A· v3 3.5 LOW· v2 JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain...Show more |
2Netapp Redhat4Jboss Enterprise Application Platform Oncommand BalanceOncommand Insight+1 moreApr 22, 2026 Aug 5, 2010 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to exe...Show more |
LibTIFF in Red Hat Enterprise Linux (RHEL) 3 on x86_64 platforms, as used in tiff2rgba, attempts to process image data even when the required compression functionality is not configured, which allows remote attackers to...Show more |
1Redhat 1Enterprise Virtualization Manager Apr 29, 2026 Jun 24, 2010 N/A· v4 N/A· v3 2.1 LOW· v2 The snapshot merging functionality in Red Hat Enterprise Virtualization Manager (aka RHEV-M) before 2.2 does not properly pass the postzero parameter during operations on deleted volumes, which allows guest OS users to o...Show more |
1Redhat 1Enterprise Virtualization Hypervisor Apr 29, 2026 Jun 24, 2010 N/A· v4 N/A· v3 2.1 LOW· v2 Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a virtual machine's data...Show more |
4Apple FedoraprojectRedhat+1 more7Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+4 moreApr 29, 2026 Jun 22, 2010 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number. |
yum-rhn-plugin in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Enterprise Linux (RHEL) 5 and Fedora uses world-readable permissions for the /var/spool/up2date/loginAuth.pkl file, which allows local user...Show more |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 29, 2026 May 12, 2010 N/A· v4 N/A· v3 2.6 LOW· v2 The MMIO instruction decoder in the Xen hypervisor in the Linux kernel 2.6.18 in Red Hat Enterprise Linux (RHEL) 5 allows guest OS users to cause a denial of service (32-bit guest OS crash) via vectors that trigger an un...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 29, 2026 Apr 28, 2010 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request t...Show more |
1Redhat 1Jboss Enterprise Application Platform Aug 14, 2026 Apr 28, 2010 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST met...Show more |
1Redhat 1Jboss Enterprise Application Platform Aug 14, 2026 Apr 28, 2010 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST metho...Show more |
A certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 4 on the ia64 platform allows local users to use ptrace on an arbitrary process, and consequently gain privileges, via vectors related to a...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelApr 29, 2026 Mar 16, 2010 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The gfs2_lock function in the Linux kernel before 2.6.34-rc1-next-20100312, and the gfs_lock function in the Linux kernel on Red Hat Enterprise Linux (RHEL) 5 and 6, does not properly remove POSIX locks on files that are...Show more |
4Apple CanonicalFedoraproject+1 more10Cups Enterprise LinuxEnterprise Linux Desktop+7 moreApr 29, 2026 Mar 5, 2010 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows rem...Show more |