redhat records
6,164 published records for vendor redhat.
Researcher profile
- Entered KEV
- 97 · 1.6%
- Weaponized
- 150 · 2.4%
- Pre-auth RCE
- 572
- With a fix record
- 82.4%
- Median publish → KEV
- 2108 days
Recurring classes
- CWE-20 Improper Input Validation368
- CWE-416 Use After Free295
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer286
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor286
- CWE-125 Out-of-bounds Read239
- CWE-787 Out-of-bounds Write220
The weakness classes this vendor ships most often: where to look.
CWEAll records
6,164 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2014-6271Weaponized | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 24, 2014 |
99Now | CVE-2013-2251Weaponized | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,apache · archiva · CWE-74 | Critical9.8 | KEV | 100.0% | Jul 19, 2013 |
99Now | CVE-2012-1823Weaponized | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Critical9.8 | KEV | 100.0% | May 11, 2012 |
99Now | CVE-2015-3113Weaponized | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Critical9.8 | KEV | 99.9% | Jun 23, 2015 |
99Now | CVE-2014-7169Weaponized | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 24, 2014 |
99Now | CVE-2015-1427Weaponized | The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection meelastic · elasticsearch | Critical9.8 | KEV | 99.9% | Feb 17, 2015 |
99Now | CVE-2014-0497Weaponized | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1adobe · flash player · CWE-191 | Critical9.8 | KEV | 99.9% | Feb 5, 2014 |
99Now | CVE-2019-11043Weaponized | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Critical9.8 | KEV | 99.8% | Oct 28, 2019 |
99Now | CVE-2015-5119Weaponized | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296adobe · flash player · CWE-416 | Critical9.8 | KEV | 99.3% | Jul 8, 2015 |
99Now | CVE-2012-4681Weaponized | Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to oracle · jdk · CWE-284 | Critical9.8 | KEV | 98.5% | Aug 27, 2012 |
99Now | CVE-2019-7609Weaponized | Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.elastic · kibana · CWE-94 | Critical10.0 | KEV | 95.3% | Mar 25, 2019 |
98Now | CVE-2018-1000861Weaponized | A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/corjenkins · jenkins · CWE-502 | Critical9.8 | KEV | 98.3% | Dec 10, 2018 |
98Now | CVE-2019-5544Weaponized | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.openslp · openslp · CWE-787 | Critical9.8 | KEV | 97.3% | Dec 6, 2019 |
98Now | CVE-2019-1003030Weaponized | A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/wojenkins · pipeline\ · CWE-693 | Critical9.9 | KEV | 96.9% | Mar 8, 2019 |
98Now | CVE-2011-3544Weaponized | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remotoracle · jdk · CWE-284 | Critical9.8 | KEV | 96.7% | Oct 19, 2011 |
97Now | CVE-2016-4117Weaponized | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wiladobe · flash player | Critical9.8 | KEV | 94.4% | May 10, 2016 |
97Now | CVE-2015-5122Weaponized | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0adobe · flash player · CWE-416 | Critical9.8 | KEV | 94.0% | Jul 14, 2015 |
97Now | CVE-2012-1723Weaponized | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier,oracle · jdk · CWE-284 | Critical9.8 | KEV | 93.7% | Jun 16, 2012 |
97Now | CVE-2016-4437Weaponized | Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitapache · aurora · CWE-321 | Critical9.8 | KEV | 93.0% | Jun 7, 2016 |
97Now | CVE-2016-3427Weaponized | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Critical9.8 | KEV | 92.3% | Apr 21, 2016 |
96Now | CVE-2021-40438Weaponized | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Critical9.0 | KEV | 100.0% | Sep 16, 2021 |
96Now | CVE-2017-12149Weaponized | In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnredhat · jboss enterprise application platform · CWE-502 | Critical9.8 | KEV | 90.7% | Oct 4, 2017 |
96Now | CVE-2016-8735Weaponized | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x beforeapache · tomcat | Critical9.8 | KEV | 90.3% | Apr 6, 2017 |
92Now | CVE-2017-12617Weaponized | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | High8.1 | KEV | 100.0% | Oct 3, 2017 |
92Now | CVE-2017-12615Weaponized | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | High8.1 | KEV | 99.6% | Sep 19, 2017 |
- CVE-2014-627199Now
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2013-225199Now
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · archivaJul 19, 2013
- CVE-2012-182399Now
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
CriticalCVSS 9.8KEVWeaponizedEPSS 100%php · phpMay 11, 2012
- CVE-2015-311399Now
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · flash playerJun 23, 2015
- CVE-2014-716999Now
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2015-142799Now
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection me
CriticalCVSS 9.8KEVWeaponizedEPSS 100%elastic · elasticsearchFeb 17, 2015
- CVE-2014-049799Now
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · flash playerFeb 5, 2014
- CVE-2019-1104399Now
Underflow in PHP-FPM can lead to RCE
CriticalCVSS 9.8KEVWeaponizedEPSS 100%php · phpOct 28, 2019
- CVE-2015-511999Now
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296
CriticalCVSS 9.8KEVWeaponizedEPSS 99%adobe · flash playerJul 8, 2015
- CVE-2012-468199Now
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to
CriticalCVSS 9.8KEVWeaponizedEPSS 99%oracle · jdkAug 27, 2012
- CVE-2019-760999Now
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.
CriticalCVSS 10.0KEVWeaponizedEPSS 95%elastic · kibanaMar 25, 2019
- CVE-2018-100086198Now
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/cor
CriticalCVSS 9.8KEVWeaponizedEPSS 98%jenkins · jenkinsDec 10, 2018
- CVE-2019-554498Now
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.
CriticalCVSS 9.8KEVWeaponizedEPSS 97%openslp · openslpDec 6, 2019
- CVE-2019-100303098Now
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/wo
CriticalCVSS 9.9KEVWeaponizedEPSS 97%jenkins · pipeline\Mar 8, 2019
- CVE-2011-354498Now
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot
CriticalCVSS 9.8KEVWeaponizedEPSS 97%oracle · jdkOct 19, 2011
- CVE-2016-411797Now
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil
CriticalCVSS 9.8KEVWeaponizedEPSS 94%adobe · flash playerMay 10, 2016
- CVE-2015-512297Now
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0
CriticalCVSS 9.8KEVWeaponizedEPSS 94%adobe · flash playerJul 14, 2015
- CVE-2012-172397Now
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier,
CriticalCVSS 9.8KEVWeaponizedEPSS 94%oracle · jdkJun 16, 2012
- CVE-2016-443797Now
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbit
CriticalCVSS 9.8KEVWeaponizedEPSS 93%apache · auroraJun 7, 2016
- CVE-2016-342797Now
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
CriticalCVSS 9.8KEVWeaponizedEPSS 92%oracle · jdkApr 21, 2016
- CVE-2021-4043896Now
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
CriticalCVSS 9.0KEVWeaponizedEPSS 100%resf · rocky linuxSep 16, 2021
- CVE-2017-1214996Now
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOn
CriticalCVSS 9.8KEVWeaponizedEPSS 91%redhat · jboss enterprise application platformOct 4, 2017
- CVE-2016-873596Now
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before
CriticalCVSS 9.8KEVWeaponizedEPSS 90%apache · tomcatApr 6, 2017
- CVE-2017-1261792Now
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.
HighCVSS 8.1KEVWeaponizedEPSS 100%apache · tomcatOct 3, 2017
- CVE-2017-1261592Now
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.
HighCVSS 8.1KEVWeaponizedEPSS 100%apache · tomcatSep 19, 2017