Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat Enterprise Linux (RHEL) 3 and 4, when PAM is used, allows remote attackers to cause a denial of service (memory consumption) via a large numbe...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux Fedora CoreLinux KernelApr 23, 2026 Jun 30, 2008 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Double free vulnerability in the utrace support in the Linux kernel, probably 2.6.18, in Red Hat Enterprise Linux (RHEL) 5 and Fedora Core 6 (FC6) allows local users to cause a denial of service (oops), as demonstrated b...Show more |
2Linux Redhat3Enterprise Linux Enterprise Linux DesktopLinux KernelApr 23, 2026 Jun 30, 2008 N/A· v4 N/A· v3 4.7 MEDIUM· v2 Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_A...Show more |
Untrusted search path vulnerability in a certain Red Hat build script for Standards Based Linux Instrumentation for Manageability (sblim) libraries before 1-13a.el4_6.1 in Red Hat Enterprise Linux (RHEL) 4, and before 1-...Show more |
4Apache CanonicalFedoraproject+1 more7Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+4 moreApr 23, 2026 Jun 13, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP server...Show more |
The default configuration of consolehelper in system-config-network before 1.5.10-1 on Fedora 8 lacks the USER=root directive, which allows local users of the workstation console to gain privileges and change the network...Show more |
2Apple Redhat3Enterprise Linux Mac Os XMac Os X ServerApr 23, 2026 Jun 2, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Enterprise Linux 5, and other operating systems omits some invalid character sequences during conversion of some character e...Show more |
1Redhat 5Desktop Enterprise LinuxEnterprise Linux Desktop+2 moreApr 23, 2026 May 23, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a long XSLT "transformati...Show more |
Cross-site scripting (XSS) vulnerability in the Red Hat Network channel search feature, as used in RHN and Red Hat Network Satellite before 5.0.2, allows remote attackers to inject arbitrary web script or HTML via unknow...Show more |
3Foresight Linux RedhatRpath4Appliance Platform Agent AppliancesEnterprise Linux+1 moreApr 23, 2026 May 22, 2008 N/A· v4 N/A· v3 7.1 HIGH· v2 Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of servi...Show more |
1Redhat 2Directory Server Fedora Directory ServerApr 23, 2026 May 12, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the regular expression handler in Red Hat Directory Server 8.0 and 7.1 before SP6 allows remote attackers to cause a denial of service (slapd crash) and possibly execute arbitrary code via a crafted LD...Show more |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 23, 2026 May 8, 2008 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Linux kernel 2.6.18, and possibly other versions, when running on AMD64 architectures, allows local users to cause a denial of service (crash) via certain ptrace calls. |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 23, 2026 May 8, 2008 N/A· v4 N/A· v3 7.1 HIGH· v2 The IPsec implementation in Linux kernel before 2.6.25 allows remote routers to cause a denial of service (crash) via a fragmented ESP packet in which the first fragment does not contain the entire ESP header and IV. |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 23, 2026 May 8, 2008 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Linux kernel before 2.4.21 allows local users to cause a denial of service (kernel panic) via asynchronous input or output on a FIFO special file. |
Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properly restrict access to CGI scripts, which allows remote attackers to perform administrative actions. |
1Redhat 2Directory Server Fedora Directory ServerApr 23, 2026 Apr 16, 2008 N/A· v4 N/A· v3 9.0 HIGH· v2 The replication monitor CGI script (repl-monitor-cgi.pl) in Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, allows remote attackers to execute arbitrary commands. |
The Replace function in the capp-lspp-config script in the (1) lspp-eal4-config-ibm and (2) capp-lspp-eal4-config-hp packages before 0.65-2 in Red Hat Enterprise Linux (RHEL) 5 uses lstat instead of stat to determine the...Show more |
Red Hat Directory Server 8.0, when running on Red Hat Enterprise Linux, uses insecure permissions for the redhat-idm-console script, which allows local users to execute arbitrary code by modifying the script. |
Red Hat Directory Server 7.1 before SP4 uses insecure permissions for certain directories, which allows local users to modify JAR files and execute arbitrary code via unknown vectors. |
The default IPSec ifup script in Red Hat Enterprise Linux 3 through 5 configures racoon to use aggressive IKE mode instead of main IKE mode, which makes it easier for remote attackers to conduct brute force attacks by sn...Show more |