Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file, related...Show more |
5Apache CanonicalDebian+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 23, 2026 Jul 10, 2009 N/A· v4 N/A· v3 7.1 HIGH· v2 The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU co...Show more |
5Apache CanonicalDebian+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 23, 2026 Jul 5, 2009 N/A· v4 N/A· v3 7.1 HIGH· v2 The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the...Show more |
4Debian FedoraprojectMozilla+1 more9Debian Linux Enterprise LinuxEnterprise Linux Desktop+6 moreApr 23, 2026 Jun 12, 2009 N/A· v4 7.5 HIGH· v3 9.3 HIGH· v2 Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transiti...Show more |
3Canonical OpensslRedhat3Openssl OpensslUbuntu LinuxApr 23, 2026 Jun 4, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS h...Show more |
3Canonical OpensslRedhat3Openssl OpensslUbuntu LinuxApr 23, 2026 Jun 4, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello. |
1Redhat 2Certificate System Dogtag Certificate SystemApr 23, 2026 May 27, 2009 N/A· v4 N/A· v3 6.5 MEDIUM· v2 agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitr...Show more |
4Branden Robinson DebianRedhat+1 more4Debian Linux FedoraLinux+1 moreApr 23, 2026 May 6, 2009 N/A· v4 N/A· v3 4.6 MEDIUM· v2 xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its...Show more |
Cross-site scripting (XSS) vulnerability in C2Net Stronghold 2.3 allows remote attackers to inject arbitrary web script or HTML via the URI. |
5Apple CanonicalFedoraproject+2 more9Enterprise Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 23, 2026 Apr 9, 2009 N/A· v4 N/A· v3 10.0 HIGH· v2 The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or p...Show more |
Buffer overflow in CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9 and Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (CPU consumption and memory corruption) via a cluster.conf fi...Show more |
2Fedoraproject Redhat5Cluster Project CmanFedora+2 moreApr 23, 2026 Mar 30, 2009 N/A· v4 N/A· v3 6.9 MEDIUM· v2 Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs...Show more |
1Redhat 1Jboss Enterprise Application Platform Apr 23, 2026 Mar 9, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL fi...Show more |
6Canonical DebianLinux+3 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreApr 23, 2026 Mar 6, 2009 N/A· v4 N/A· v3 3.6 LOW· v2 The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, whic...Show more |
4Net Snmp OpensuseRedhat+1 more4Enterprise Linux Linux EnterpriseNet Snmp+1 moreApr 23, 2026 Feb 12, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to...Show more |
1Redhat 2 Dogtag Certificate System Certificate SystemApr 23, 2026 Jan 30, 2009 N/A· v4 N/A· v3 6.0 MEDIUM· v2 The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate System 1.0 returns successfully even when token enrollment did not use t...Show more |
Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local...Show more |
Red Hat Certificate System 7.2 uses world-readable permissions for password.conf and unspecified other configuration files, which allows local users to discover passwords by reading these files. |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 23, 2026 Nov 27, 2008 N/A· v4 N/A· v3 6.8 MEDIUM· v2 tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to the OpenPegasus CIM server, which makes it easier for remote attackers t...Show more |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 23, 2026 Nov 27, 2008 N/A· v4 N/A· v3 6.0 MEDIUM· v2 A certain Red Hat patch for tog-pegasus in OpenGroup Pegasus 2.7.0 does not properly configure the PAM tty name, which allows remote authenticated users to bypass intended access restrictions and send requests to OpenPeg...Show more |