redhat

5,768 tracked vulnerabilities.

CVE-2013-4364 HIGH
Red Hat OpenShift Enterprise 1 and 2 - Symlink Attack via Temporary File in /tmp
Jan 08, 2018
CVSS 7.8
EPSS 0.00
CVE-2013-6465 MEDIUM
JBPM KIE Workbench 6.0.x - Authenticated Cross-Site Scripting via Task Name HTML Input
Dec 19, 2017
CVSS 5.4
EPSS 0.01
CVE-2013-3734 MEDIUM
JBoss Application Server < 1.2 - Cleartext Password Exposure in Embedded Jopr HTML Responses
Oct 24, 2017
CVSS 6.6
EPSS 0.02
CVE-2013-7398
Async Http Client <1.9.0 - Man-in-the-Middle
Jun 24, 2015
EPSS 0.01
CVE-2013-7397
Async Http Client <1.9.0 - Man-in-the-Middle
Jun 24, 2015
EPSS 0.01
CVE-2013-7423
GNU C Library <2.20 - Use After Free
Feb 24, 2015
EPSS 0.06
CVE-2013-4399
libvirt < 1.1.3 - Denial of Service via Event Handler Use-After-Free
Dec 12, 2014
EPSS 0.02
CVE-2013-0336
FreeIPA < 3.2.0 - Denial of Service via Missing Username in Connection Request
Nov 03, 2014
EPSS 0.03
CVE-2013-6496
Red Hat Conga 0.12.2 - Exposure of Sensitive Information via Luci Extension Requests
Oct 06, 2014
EPSS 0.02
CVE-2013-6470
Red Hat OpenStack Platform 4.0 - Unauthenticated Qpid Access via Default Configuration
Jun 02, 2014
EPSS 0.02
CVE-2013-0199
FreeIPA < 3.1.2 - Unauthenticated Cross-Realm Kerberos Trust Key Exposure via LDAP ACIs
May 29, 2014
EPSS 0.02
CVE-2013-7336
libvirt < 1.1.3 - Denial of Service via SPICE Migration Monitor Race Condition
May 07, 2014
EPSS 0.00
CVE-2013-6445
Red Hat Enterprise MRG 2.5 - Weak Password Hashing via DES-based crypt Function
Apr 30, 2014
EPSS 0.01
CVE-2013-6469
JBoss Overlord Run Time Governance 1.0 - Authenticated Remote Code Execution via MVFLEX Expression Language Injection
Apr 22, 2014
EPSS 0.02
CVE-2013-2143
Red Hat Satellite and Katello < 1.5.0-14 - Authenticated Privilege Escalation via users/update_roles
Apr 17, 2014
EPSS 0.48
CVE-2013-6456
libvirt 1.0.1-1.2.1 - Local Privilege Escalation and Denial of Service via Symlink Attacks on /dev
Apr 15, 2014
EPSS 0.01
CVE-2013-5704
Apache HTTP Server 2.2.22 - Auth Bypass
Apr 15, 2014
EPSS 0.60
CVE-2013-6468
Red Hat JBoss BPM Suite and BRMS < 6.0.1 - Authenticated Remote Code Execution via MVFLEX or Drools Expression
Apr 10, 2014
EPSS 0.02
CVE-2013-1869
Red Hat Satellite and Spacewalk Java < 2.1.147-1 - CRLF Injection via Return URL Parameter
Apr 01, 2014
EPSS 0.02
CVE-2013-7347
Luci in Red Hat Conga - Info Disclosure
Mar 31, 2014
EPSS 0.00
CVE-2013-6493
IcedTea-Web < 1.4.2 - Local Information Disclosure via Predictable Socket File
Mar 03, 2014
EPSS 0.00
CVE-2013-4415
Red Hat Satellite - Cross-Site Scripting via Multiple Search Parameters
Feb 14, 2014
EPSS 0.02
CVE-2013-1871
Red Hat Satellite 5.6 - Cross-Site Scripting via Account EditAddress Type Parameter
Feb 14, 2014
EPSS 0.02
CVE-2013-6393
LibYAML < 0.1.5 - Heap-Based Buffer Overflow via Crafted YAML Tags
Feb 06, 2014
EPSS 0.08
CVE-2013-6491
OpenStack Oslo < 2013.2 - Unauthenticated Sensitive Information Exposure via Qpid SSL Enforcement Bypass
Feb 02, 2014
EPSS 0.02