Skip to main content

Vendor archive

redhat CVEs

Beta · best-effort

5,981 CVEs tagged to vendor redhat666 Critical, 2,011 High, 2,837 Medium, 467 Low, 0 Unrated.

CVE-2003-0550

Published Aug 27, 2003

The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which allows attackers to modify the bridge topology.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0551

Published Aug 27, 2003

The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could allow attackers to cause a denial of service.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0552

Published Aug 27, 2003

Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose source addresses are the same as the target.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0442

Published Jul 24, 2003

Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1155

Published Jun 16, 2003

Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command line argument.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0247

Published Jun 16, 2003

Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops").

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0248

Published Jun 16, 2003

The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2003-0354

Published Jun 16, 2003

Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0364

Published Jun 16, 2003

The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a denial of service (CPU consumption) via certain packets that cause a large numbe…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0188

Published Jun 9, 2003

lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other director…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0135

Published Apr 11, 2003

vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restric…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1509

Published Mar 3, 2003

A patch for shadow-utils 20000902 causes the useradd command to create a mail spool files with read/write privileges of the new user's group (mode 660), which allows other users i…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-1160

Published Feb 19, 2003

The default configuration of the pam_xauth module forwards MIT-Magic-Cookies to new X sessions, which could allow local users to gain root privileges by stealing the cookies from…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0019

Published Feb 19, 2003

uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entrie…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1890

Published Dec 31, 2002

rhmask 1.0-9 in Red Hat Linux 7.1 allows local users to overwrite arbitrary files via a symlink attack on the mask file.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-2185

Published Dec 31, 2002

The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast…

CVSS 4.9 · Medium
Showing 5,801-5,825 of 5,981 CVEsPage 233 of 240