Записи RedHat
6 164 опубликованных записей вендора redhat.
Профиль для исследователя
- Попали в KEV
- 97 · 1,6 %
- С эксплойтом
- 150 · 2,4 %
- Pre-auth RCE
- 572
- С записью об исправлении
- 82,5 %
- Медиана: публикация → KEV
- 2108 дн.
Повторяющиеся классы
- CWE-20 Improper Input Validation368
- CWE-416 Use After Free295
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer286
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor286
- CWE-125 Out-of-bounds Read239
- CWE-787 Out-of-bounds Write220
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 164 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2014-6271Готовый эксплойт | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Критическая9,8 | KEV | 100,0 % | 24 сент. 2014 г. |
99Срочно | CVE-2013-2251Готовый эксплойт | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,apache · archiva · CWE-74 | Критическая9,8 | KEV | 100,0 % | 19 июл. 2013 г. |
99Срочно | CVE-2012-1823Готовый эксплойт | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Критическая9,8 | KEV | 100,0 % | 11 мая 2012 г. |
99Срочно | CVE-2015-3113Готовый эксплойт | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11adobe · flash player · CWE-787 | Критическая9,8 | KEV | 99,9 % | 23 июн. 2015 г. |
99Срочно | CVE-2014-7169Готовый эксплойт | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Критическая9,8 | KEV | 99,9 % | 24 сент. 2014 г. |
99Срочно | CVE-2015-1427Готовый эксплойт | The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection meelastic · elasticsearch | Критическая9,8 | KEV | 99,9 % | 17 февр. 2015 г. |
99Срочно | CVE-2014-0497Готовый эксплойт | Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1adobe · flash player · CWE-191 | Критическая9,8 | KEV | 99,9 % | 5 февр. 2014 г. |
99Срочно | CVE-2019-11043Готовый эксплойт | Underflow in PHP-FPM can lead to RCEphp · php · CWE-120 | Критическая9,8 | KEV | 99,8 % | 28 окт. 2019 г. |
99Срочно | CVE-2015-5119Готовый эксплойт | Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296adobe · flash player · CWE-416 | Критическая9,8 | KEV | 99,3 % | 8 июл. 2015 г. |
99Срочно | CVE-2012-4681Готовый эксплойт | Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to oracle · jdk · CWE-284 | Критическая9,8 | KEV | 98,5 % | 27 авг. 2012 г. |
99Срочно | CVE-2019-7609Готовый эксплойт | Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.elastic · kibana · CWE-94 | Критическая10,0 | KEV | 95,3 % | 25 мар. 2019 г. |
98Срочно | CVE-2018-1000861Готовый эксплойт | A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/corjenkins · jenkins · CWE-502 | Критическая9,8 | KEV | 98,3 % | 10 дек. 2018 г. |
98Срочно | CVE-2019-5544Готовый эксплойт | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.openslp · openslp · CWE-787 | Критическая9,8 | KEV | 97,3 % | 6 дек. 2019 г. |
98Срочно | CVE-2019-1003030Готовый эксплойт | A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/wojenkins · pipeline\ · CWE-693 | Критическая9,9 | KEV | 96,9 % | 8 мар. 2019 г. |
98Срочно | CVE-2011-3544Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remotoracle · jdk · CWE-284 | Критическая9,8 | KEV | 96,7 % | 19 окт. 2011 г. |
97Срочно | CVE-2016-4117Готовый эксплойт | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wiladobe · flash player | Критическая9,8 | KEV | 94,4 % | 10 мая 2016 г. |
97Срочно | CVE-2015-5122Готовый эксплойт | Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0adobe · flash player · CWE-416 | Критическая9,8 | KEV | 94,0 % | 14 июл. 2015 г. |
97Срочно | CVE-2012-1723Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier,oracle · jdk · CWE-284 | Критическая9,8 | KEV | 93,7 % | 16 июн. 2012 г. |
97Срочно | CVE-2016-4437Готовый эксплойт | Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitapache · aurora · CWE-321 | Критическая9,8 | KEV | 93,0 % | 7 июн. 2016 г. |
97Срочно | CVE-2016-3427Готовый эксплойт | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to afforacle · jdk · CWE-284 | Критическая9,8 | KEV | 92,3 % | 21 апр. 2016 г. |
96Срочно | CVE-2021-40438Готовый эксплойт | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.resf · rocky linux · CWE-918 | Критическая9,0 | KEV | 100,0 % | 16 сент. 2021 г. |
96Срочно | CVE-2017-12149Готовый эксплойт | In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnredhat · jboss enterprise application platform · CWE-502 | Критическая9,8 | KEV | 90,7 % | 4 окт. 2017 г. |
96Срочно | CVE-2016-8735Готовый эксплойт | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x beforeapache · tomcat | Критическая9,8 | KEV | 90,3 % | 6 апр. 2017 г. |
92Срочно | CVE-2017-12617Готовый эксплойт | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | Высокая8,1 | KEV | 100,0 % | 3 окт. 2017 г. |
92Срочно | CVE-2017-12615Готовый эксплойт | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.apache · tomcat · CWE-434 | Высокая8,1 | KEV | 99,6 % | 19 сент. 2017 г. |
- CVE-2014-627199Срочно
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2013-225199Срочно
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:,
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · archiva19 июл. 2013 г.
- CVE-2012-182399Срочно
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php11 мая 2012 г.
- CVE-2015-311399Срочно
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · flash player23 июн. 2015 г.
- CVE-2014-716999Срочно
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2015-142799Срочно
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection me
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %elastic · elasticsearch17 февр. 2015 г.
- CVE-2014-049799Срочно
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 1
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · flash player5 февр. 2014 г.
- CVE-2019-1104399Срочно
Underflow in PHP-FPM can lead to RCE
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php28 окт. 2019 г.
- CVE-2015-511999Срочно
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %adobe · flash player8 июл. 2015 г.
- CVE-2012-468199Срочно
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %oracle · jdk27 авг. 2012 г.
- CVE-2019-760999Срочно
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 95 %elastic · kibana25 мар. 2019 г.
- CVE-2018-100086198Срочно
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/cor
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %jenkins · jenkins10 дек. 2018 г.
- CVE-2019-554498Срочно
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %openslp · openslp6 дек. 2019 г.
- CVE-2019-100303098Срочно
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/wo
КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 97 %jenkins · pipeline\8 мар. 2019 г.
- CVE-2011-354498Срочно
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remot
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %oracle · jdk19 окт. 2011 г.
- CVE-2016-411797Срочно
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wil
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · flash player10 мая 2016 г.
- CVE-2015-512297Срочно
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %adobe · flash player14 июл. 2015 г.
- CVE-2012-172397Срочно
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier,
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %oracle · jdk16 июн. 2012 г.
- CVE-2016-443797Срочно
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbit
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 93 %apache · aurora7 июн. 2016 г.
- CVE-2016-342797Срочно
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to aff
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %oracle · jdk21 апр. 2016 г.
- CVE-2021-4043896Срочно
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %resf · rocky linux16 сент. 2021 г.
- CVE-2017-1214996Срочно
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOn
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 91 %redhat · jboss enterprise application platform4 окт. 2017 г.
- CVE-2016-873596Срочно
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %apache · tomcat6 апр. 2017 г.
- CVE-2017-1261792Срочно
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 100 %apache · tomcat3 окт. 2017 г.
- CVE-2017-1261592Срочно
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g.
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 100 %apache · tomcat19 сент. 2017 г.