Skip to content
Noroxi

redhat records

6,164 published records for vendor redhat.

Researcher profile

Entered KEV
97 · 1.6%
Weaponized
150 · 2.4%
Pre-auth RCE
572
With a fix record
82.4%
Median publish → KEV
2108 days

All records

6,164 records
  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · archivaJul 19, 2013

  • sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpMay 11, 2012

  • Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    adobe · flash playerJun 23, 2015

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection me

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    elastic · elasticsearchFeb 17, 2015

  • Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    adobe · flash playerFeb 5, 2014

  • Underflow in PHP-FPM can lead to RCE

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpOct 28, 2019

  • Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    adobe · flash playerJul 8, 2015

  • Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    oracle · jdkAug 27, 2012

  • Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.

    CriticalCVSS 10.0KEVWeaponizedEPSS 95%

    elastic · kibanaMar 25, 2019

  • A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/cor

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    jenkins · jenkinsDec 10, 2018

  • OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    openslp · openslpDec 6, 2019

  • A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/wo

    CriticalCVSS 9.9KEVWeaponizedEPSS 97%

    jenkins · pipeline\Mar 8, 2019

  • Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    oracle · jdkOct 19, 2011

  • Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil

    CriticalCVSS 9.8KEVWeaponizedEPSS 94%

    adobe · flash playerMay 10, 2016

  • Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0

    CriticalCVSS 9.8KEVWeaponizedEPSS 94%

    adobe · flash playerJul 14, 2015

  • Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier,

    CriticalCVSS 9.8KEVWeaponizedEPSS 94%

    oracle · jdkJun 16, 2012

  • Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbit

    CriticalCVSS 9.8KEVWeaponizedEPSS 93%

    apache · auroraJun 7, 2016

  • Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff

    CriticalCVSS 9.8KEVWeaponizedEPSS 92%

    oracle · jdkApr 21, 2016

  • A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    CriticalCVSS 9.0KEVWeaponizedEPSS 100%

    resf · rocky linuxSep 16, 2021

  • In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOn

    CriticalCVSS 9.8KEVWeaponizedEPSS 91%

    redhat · jboss enterprise application platformOct 4, 2017

  • Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before

    CriticalCVSS 9.8KEVWeaponizedEPSS 90%

    apache · tomcatApr 6, 2017

  • When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.

    HighCVSS 8.1KEVWeaponizedEPSS 100%

    apache · tomcatOct 3, 2017

  • When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.

    HighCVSS 8.1KEVWeaponizedEPSS 100%

    apache · tomcatSep 19, 2017