Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Avaya Redhat4Cvlan Enterprise LinuxEnterprise Linux Desktop+1 moreApr 16, 2026 Nov 23, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI. |
3Linux RedhatTrustix3Fedora Core Linux KernelSecure LinuxApr 16, 2026 Nov 23, 2004 N/A· v4 N/A· v3 2.1 LOW· v2 Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory. |
244d AppleAvaya+21 more65Aaa Server Access RegistrarApache Based Web Server+62 moreApr 16, 2026 Nov 23, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a de...Show more |
234d AppleAvaya+20 more66Aaa Server Access RegistrarApache Based Web Server+63 moreApr 16, 2026 Nov 23, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool. |
234d AppleAvaya+20 more66Aaa Server Access RegistrarApache Based Web Server+63 moreApr 16, 2026 Nov 23, 2004 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference. |
1Redhat 2Enterprise Linux Enterprise Linux DesktopApr 16, 2026 Oct 20, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Unknown vulnerability in redhat-config-nfs before 1.0.13, when shares are exported to multiple hosts, can produce incorrect permissions and prevent the all_squash option from being applied. |
3Mozilla RedhatSgi7Enterprise Linux Enterprise Linux DesktopFedora Core+4 moreApr 16, 2026 Oct 18, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a nu...Show more |
6Apple ConectivaCyrus+3 more8Fedora Core LinuxMac Os X+5 moreApr 16, 2026 Oct 7, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary cod...Show more |
3Debian MitRedhat5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreApr 16, 2026 Sep 28, 2004 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Double free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code. |
3Debian MitRedhat5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreApr 16, 2026 Sep 28, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to...Show more |
9Conectiva EnlightenmentImagemagick+6 more14Enterprise Linux Enterprise Linux DesktopFedora Core+11 moreApr 16, 2026 Sep 16, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malf...Show more |
8Apache DebianGentoo+5 more12Debian Linux Enterprise LinuxEnterprise Linux Desktop+9 moreApr 16, 2026 Sep 16, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access. |
5Conectiva MozillaNetscape+2 more10Enterprise Linux Enterprise Linux DesktopFedora Core+7 moreApr 16, 2026 Sep 14, 2004 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and...Show more |
4Libpng OpenpkgRedhat+1 more6Enterprise Linux Enterprise Linux DesktopLibpng+3 moreApr 16, 2026 Aug 18, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creatin...Show more |
8Clearswift F SecureRarlab+5 more13Cgpmcafee F Secure Anti VirusF Secure For Firewalls+10 moreApr 16, 2026 Aug 18, 2004 N/A· v4 N/A· v3 6.4 MEDIUM· v2 Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double...Show more |
8Clearswift F SecureRarlab+5 more13Cgpmcafee F Secure Anti VirusF Secure For Firewalls+10 moreApr 16, 2026 Aug 18, 2004 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long dir...Show more |
3Mandrakesoft RedhatSuse4Fedora Core Mandrake LinuxMandrake Linux Corporate Server+1 moreApr 16, 2026 Aug 6, 2004 N/A· v4 N/A· v3 2.1 LOW· v2 Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service. |
4Conectiva GentooRedhat+1 more6Enterprise Linux Enterprise Linux DesktopFedora Core+3 moreApr 16, 2026 Aug 6, 2004 N/A· v4 N/A· v3 10.0 HIGH· v2 Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields. |
6Avaya ConectivaGentoo+3 more18Converged Communications Server Enterprise LinuxIntuity Audix+15 moreApr 16, 2026 Aug 6, 2004 N/A· v4 N/A· v3 2.1 LOW· v2 Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions,...Show more |
6Avaya ConectivaGentoo+3 more18Converged Communications Server Enterprise LinuxIntuity Audix+15 moreApr 16, 2026 Aug 6, 2004 N/A· v4 N/A· v3 7.2 HIGH· v2 Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool. |