Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the Pro...Show more |
dn2ancestor in the LDAP component in Fedora Directory Server 1.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via a ModDN operation with a DN that contains a large number of "," (comm...Show more |
Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memor...Show more |
Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders "allo...Show more |
initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with sudo permissions for /sbin/service to gain root privileges vi...Show more |
18Conectiva DebianEasy Software Products+15 more33Cups Debian LinuxEnterprise Linux+30 moreApr 16, 2026 Dec 31, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null derefer...Show more |
18Conectiva DebianEasy Software Products+15 more33Cups Debian LinuxEnterprise Linux+30 moreApr 16, 2026 Dec 31, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated usi...Show more |
18Conectiva DebianEasy Software Products+15 more33Cups Debian LinuxEnterprise Linux+30 moreApr 16, 2026 Dec 31, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDe...Show more |
2Gnu Redhat4Enterprise Linux Enterprise Linux DesktopLinux Advanced Workstation+1 moreApr 16, 2026 Dec 31, 2005 N/A· v4 N/A· v3 2.6 LOW· v2 The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files v...Show more |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 16, 2026 Dec 22, 2005 N/A· v4 N/A· v3 4.6 MEDIUM· v2 udev does not properly set permissions on certain files in /dev/input, which allows local users to obtain sensitive data that is entered at the console, such as user passwords. |
4Apache CanonicalFedoraproject+1 more6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+3 moreApr 16, 2026 Oct 25, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transa...Show more |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 16, 2026 Oct 25, 2005 N/A· v4 N/A· v3 2.1 LOW· v2 The rw_vm function in usercopy.c in the 4GB split patch for the Linux kernel in Red Hat Enterprise Linux 4 does not perform proper bounds checking, which allows local users to cause a denial of service (crash). |
sysreport before 1.3.7 allows local users to obtain sensitive information via a symlink attack on a temporary directory. |
3Canonical LinuxRedhat3Enterprise Linux Linux KernelUbuntu LinuxApr 16, 2026 Sep 14, 2005 N/A· v4 N/A· v3 3.6 LOW· v2 The raw_sendmsg function in the Linux kernel 2.6 before 2.6.13.1 allows local users to cause a denial of service (change hardware state) or read from arbitrary memory via crafted input. |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 16, 2026 Sep 1, 2005 N/A· v4 N/A· v3 7.2 HIGH· v2 init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 does not properly clear controlling tty's in multi-threaded applications, which allows local users to cause a denial of service (crash) a...Show more |
3Apache DebianRedhat5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreApr 16, 2026 Aug 5, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that c...Show more |
1Redhat 4Enterprise Linux Enterprise Linux DesktopLinux Advanced Workstation+1 moreApr 16, 2026 Jun 13, 2005 N/A· v4 N/A· v3 7.5 HIGH· v2 sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges. |
5Gentoo LblMandrakesoft+2 more5Fedora Core LinuxMandrake Linux+2 moreApr 16, 2026 Jun 10, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packe...Show more |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 16, 2026 May 18, 2005 N/A· v4 N/A· v3 2.1 LOW· v2 The xattr file system code, as backported in Red Hat Enterprise Linux 3 on 64-bit systems, does not properly handle certain offsets, which allows local users to cause a denial of service (system crash) via certain action...Show more |
1Redhat 3Enterprise Linux Enterprise Linux DesktopLinux Advanced WorkstationApr 16, 2026 May 4, 2005 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2004-1287. |