← Back

Redhat

redhat

5,899 CVEs • 544 products

Products (544)

Click to collapse
Toggle
Satellite
satellite
Linux
linux
Openstack
openstack
Openshift
openshift
Keycloak
keycloak
Fedora Core
fedora_core
Libvirt
libvirt
Ansible Tower
ansible_tower
Cloudforms
cloudforms
Ansible
ansible
Ceph Storage
ceph_storage
Linux Desktop
linux_desktop
Linux Server
linux_server
Jboss Fuse
jboss_fuse
Undertow
undertow
Quay
quay
Storage
storage
Fuse
fuse
Data Grid
data_grid
Resteasy
resteasy
Wildfly
wildfly
Jboss A Mq
jboss_a-mq
Ceph
ceph

CVEs (5,899)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Infoblox
IscMandrakesoft+2 more
11Dhcpd
Dns One ApplianceFedora Core+8 more
Apr 16, 2026
Aug 6, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, w...Show more
The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and possibly execute arbitrary code.Show less
5Infoblox
IscMandrakesoft+2 more
11Dhcpd
Dns One ApplianceFedora Core+8 more
Apr 16, 2026
Aug 6, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via multi...Show more
Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via multiple hostname options in (1) DISCOVER, (2) OFFER, (3) REQUEST, (4) ACK, or (5) NAK messages, which can generate a long string when writing to a log file.Show less
4Avaya
PhpRedhat+1 more
8Converged Communications Server
Fedora CoreIntegrated Management+5 more
Apr 16, 2026
Jul 27, 2004
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web bro...Show more
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulnerabilities.Show less
3Apache
DebianRedhat
4Debian Linux
Enterprise Linux ServerEnterprise Linux Workstation+1 more
Apr 16, 2026
Jul 7, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client...Show more
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.Show less
3Gnome
RedhatSgi
5Enterprise Linux
Gdk PixbufGdkpixbuf+2 more
Apr 16, 2026
Apr 15, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.
3Redhat
SgiSysstat
3Propack
SysstatSysstat
Apr 16, 2026
Apr 15, 2004
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107.
3Redhat
SgiSysstat
3Propack
SysstatSysstat
Apr 16, 2026
Apr 15, 2004
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.
3Metamail Corporation
RedhatSgi
4Enterprise Linux
Linux Advanced WorkstationMetamail+1 more
Apr 16, 2026
Mar 3, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.
3Metamail Corporation
RedhatSgi
4Enterprise Linux
Linux Advanced WorkstationMetamail+1 more
Apr 16, 2026
Mar 3, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.
4Linux
NetwosixRedhat+1 more
7Bigmem Kernel
KernelKernel Doc+4 more
Apr 16, 2026
Mar 3, 2004
N/A· v4
N/A· v3
7.2 HIGH· v2
The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors i...Show more
The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.Show less
1Redhat
2Linux
Tcpdump
Apr 16, 2026
Feb 17, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.
1Redhat
1Kernel
Apr 16, 2026
Feb 17, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
The C-Media PCI sound driver in Linux before 2.4.22 does not use the get_user function to access userspace in certain conditions, which crosses security boundaries and may facilitate the exploitation of vulnerabilities,...Show more
The C-Media PCI sound driver in Linux before 2.4.22 does not use the get_user function to access userspace in certain conditions, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0699.Show less
2Redhat
Suse
2Enterprise Linux
Suse Linux
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
2.1 LOW· v2
Unspecified vulnerability in xscreensaver 4.12, and possibly other versions, allows attackers to cause xscreensaver to crash via unspecified vectors "while verifying the user-password."
2Linux
Redhat
2Enterprise Linux
Linux Kernel
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
1.7 LOW· v2
Various routines for the ppc64 architecture on Linux kernel 2.6 prior to 2.6.2 and 2.4 prior to 2.4.24 do not use the copy_from_user function when copying data from userspace to kernelspace, which crosses security bounda...Show more
Various routines for the ppc64 architecture on Linux kernel 2.6 prior to 2.6.2 and 2.4 prior to 2.4.24 do not use the copy_from_user function when copying data from userspace to kernelspace, which crosses security boundaries and allows local users to cause a denial of service.Show less
1Redhat
1Enterprise Linux
Apr 16, 2026
Dec 31, 2003
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The (1) ipq_read and (2) ipulog_read functions in iptables allow local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
4Andrew Tridgell
EngardelinuxRedhat+1 more
5Rsync
RsyncSecure Community+2 more
Apr 16, 2026
Dec 15, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.
5Gnu
IntelQuagga+2 more
7Enterprise Linux
GlibcIa64+4 more
Apr 16, 2026
Dec 15, 2003
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
1Redhat
1Interchange
Apr 16, 2026
Oct 27, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET...Show more
The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page configured, via a GET request containing a double slash (//).Show less
1Redhat
1Enterprise Linux
Apr 16, 2026
Oct 20, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can...Show more
The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.Show less
6Compaq
FreebsdOpenbsd+3 more
6Freebsd
IrixOpenbsd+3 more
Apr 16, 2026
Oct 20, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an...Show more
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.Show less