redhat

5,768 tracked vulnerabilities.

CVE-2016-6338 MEDIUM
ovirt-engine-webadmin - Privilege Escalation
Apr 20, 2017
CVSS 6.8
EPSS 0.01
CVE-2016-5409 HIGH
Red Hat OpenShift Enterprise 2 - Exposure of Sensitive Information via Missing HTTPOnly Flag in GEARID Cookie
Apr 20, 2017
CVSS 7.5
EPSS 0.01
CVE-2016-5410 MEDIUM
firewalld < 0.4.3.3 - Unauthenticated Firewall Configuration Modification via D-Bus API
Apr 19, 2017
CVSS 5.5
EPSS 0.00
CVE-2016-7060 MEDIUM
Red Hat QuickStart Cloud Installer 1.0 - Unauthorized Password Exposure via Unmasked Web Interface
Apr 14, 2017
CVSS 4.6
EPSS 0.00
CVE-2016-6489 HIGH
Nettle - Info Disclosure
Apr 14, 2017
CVSS 7.5
EPSS 0.05
CVE-2016-4455 LOW
Red Hat Enterprise Linux Subscription Manager < 1.17.7-1 - Information Disclosure via Weak Cache Directory Permissions
Apr 14, 2017
CVSS 3.3
EPSS 0.00
CVE-2016-4970 HIGH
Netty 4.0.20-4.0.36 - Denial of Service via Infinite Loop in OpenSslEngine
Apr 13, 2017
CVSS 7.5
EPSS 0.11
CVE-2016-2104 MEDIUM
Red Hat Satellite 5 - Stored Cross-Site Scripting via Multiple Parameters
Apr 13, 2017
CVSS 6.1
EPSS 0.01
CVE-2016-6348 MEDIUM
RESTEasy - Cross-Site Scripting in JacksonJsonpInterceptor
Apr 12, 2017
CVSS 6.1
EPSS 0.01
CVE-2016-4459 HIGH
mod_cluster - Stack-based Buffer Overflow in mod_manager/node.c
Apr 12, 2017
CVSS 7.5
EPSS 0.03
CVE-2016-4989 HIGH
setroubleshoot - Command Injection via Crafted File Name or XML Document
Apr 11, 2017
CVSS 7.0
EPSS 0.00
CVE-2016-4446 HIGH
setroubleshoot - Command Injection via Crafted Filename in allow_execstack Plugin
Apr 11, 2017
CVSS 7.0
EPSS 0.00
CVE-2016-4445 HIGH
setroubleshoot <3.2.23 - Privilege Escalation
Apr 11, 2017
CVSS 7.0
EPSS 0.00
CVE-2016-4444 HIGH
setroubleshoot <3.2.23 - Command Injection
Apr 11, 2017
CVSS 7.0
EPSS 0.00
CVE-2016-1908 CRITICAL
OpenSSH <7.2 - Privilege Escalation
Apr 11, 2017
CVSS 9.8
EPSS 0.14
CVE-2016-5011 MEDIUM
util-linux < 2.28 - Denial of Service via Crafted MSDOS Partition Table
Apr 11, 2017
CVSS 4.6
EPSS 0.00
CVE-2016-8735 CRITICAL KEVNUCLEI
Apache Tomcat , 7.x , 8.x , 8.5.x , 9.x <6.0.48 <7.0.73 <8.0.39 <8.5.7 - Remote Code Execution
Apr 06, 2017
CVSS 9.8
EPSS 0.90
CVE-2016-7797 HIGH
Pacemaker < 1.1.15 - Unauthenticated Denial of Service via Remote Node Disconnection
Mar 24, 2017
CVSS 7.5
EPSS 0.03
CVE-2016-7103 MEDIUM
jQuery UI < 1.12.0 - Cross-Site Scripting via Dialog closeText Parameter
Mar 15, 2017
CVSS 6.1
EPSS 0.23
CVE-2016-9560 HIGH
JasPer < 1.900.30 - Stack-based Buffer Overflow in jpc_tsfb_getbands2
Feb 15, 2017
CVSS 7.8
EPSS 0.03
CVE-2016-3616 HIGH
libjpeg-turbo - Denial of Service via NULL Pointer Dereference in cjpeg
Feb 13, 2017
CVSS 8.8
EPSS 0.04
CVE-2016-2568 HIGH
polkit - Local Privilege Escalation via TIOCSTI ioctl Call
Feb 13, 2017
CVSS 7.8
EPSS 0.00
CVE-2016-10165 HIGH
Little CMS < 2.11 - Out-of-bounds Read via Crafted ICC Profile
Feb 03, 2017
CVSS 7.1
EPSS 0.03
CVE-2016-2518 MEDIUM
NTP < 4.2.8p9 and 4.3.x < 4.3.92 - Out-of-bounds Read via addpeer Request with Large hmode Value
Jan 30, 2017
CVSS 5.3
EPSS 0.15
CVE-2016-9636 CRITICAL
GStreamer < 1.10.2 - Remote Code Execution via FLIC Decoder Heap Overflow
Jan 27, 2017
CVSS 9.8
EPSS 0.09