Redhat Enterprise Mrg vulnerabilities
73 known vulnerabilities affecting redhat/enterprise_mrg.
Total CVEs
73
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH20MEDIUM45LOW7
Vulnerabilities
Page 2 of 4
CVE-2009-4133P4MEDIUMCVSS 6.5v1.22009-12-23
CVE-2009-4133 [MEDIUM] CVE-2009-4133: Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node fo
Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as an arbitrary user, and thereby gain privileges, by using a Condor command-line tool to modify an unspecified job attribute.
nvd
CVE-2013-4345P4MEDIUMCVSS 5.8v2.0v2.1+3 more2013-10-10
CVE-2013-4345 [MEDIUM] CWE-189 CVE-2013-4345: Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3
Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via multiple requests for small amounts of data, leading to improper management of the state of the consumed data.
nvd
CVE-2020-12826P4MEDIUMCVSS 5.3v2.02020-05-12
CVE-2020-12826 [MEDIUM] CWE-190 CVE-2020-12826: A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2.
A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can send an arbitrary signal to a parent process in a different security domain. Exploitation li
nvd
CVE-2012-1097P4HIGHCVSS 7.8v2.02012-05-17
CVE-2012-1097 [HIGH] CWE-476 CVE-2012-1097: The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the
The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a (1) PTRACE_GETREGSET or (2) PTRACE_SETREGSET ptrace call.
nvd
CVE-2013-6461P4MEDIUMCVSS 6.5v2.02019-11-05
CVE-2013-6461 [MEDIUM] CWE-776 CVE-2013-6461: Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
nvd
CVE-2013-4404P4MEDIUMCVSS 6.5v2.42013-12-23
CVE-2013-4404 [MEDIUM] CWE-264 CVE-2013-4404: cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote a
cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restrictions and obtain sensitive information or perform privileged operations via unspecified vectors.
nvd
CVE-2019-3459P4MEDIUMCVSS 6.5v2.02019-04-11
CVE-2019-3459 [MEDIUM] CWE-125 CVE-2019-3459: A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel be
A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.
nvd
CVE-2019-14898P4HIGHCVSS 7.0v2.02020-05-08
CVE-2019-14898 [HIGH] CVE-2019-14898: The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user
The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impacts by triggering a race condition with mmget_not_zero or get_task_mm calls.
nvd
CVE-2010-4526P4HIGHCVSS 7.1v1.02011-01-11
CVE-2010-4526 [HIGH] CWE-362 CVE-2010-4526: Race condition in the sctp_icmp_proto_unreachable function in net/sctp/input.c in Linux kernel 2.6.1
Race condition in the sctp_icmp_proto_unreachable function in net/sctp/input.c in Linux kernel 2.6.11-rc2 through 2.6.33 allows remote attackers to cause a denial of service (panic) via an ICMP unreachable message to a socket that is already locked by a user, which causes the socket to be freed and triggers list corruption, related to the sctp_wait_for_
nvd
CVE-2013-6460P4MEDIUMCVSS 6.5v2.02019-11-05
CVE-2013-6460 [MEDIUM] CWE-776 CVE-2013-6460: Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
nvd
CVE-2012-2734P4MEDIUMCVSS 6.8v2.02012-09-28
CVE-2012-2734 [MEDIUM] CWE-352 CVE-2012-2734: Multiple cross-site request forgery (CSRF) vulnerabilities in Cumin before 0.1.5444, as used in Red
Multiple cross-site request forgery (CSRF) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to hijack the authentication of arbitrary users for requests that execute commands via unspecified vectors.
nvd
CVE-2013-1909P4MEDIUMCVSS 5.8v2.02013-08-23
CVE-2013-1909 [MEDIUM] CWE-20 CVE-2013-1909: The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domai
The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
nvd
CVE-2012-2681P4MEDIUMCVSS 5.8v2.02012-09-28
CVE-2012-2681 [MEDIUM] CWE-310 CVE-2012-2681: Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, uses p
Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, uses predictable random numbers to generate session keys, which makes it easier for remote attackers to guess the session key.
nvd
CVE-2012-3459P4MEDIUMCVSS 4.9v2.02012-09-28
CVE-2012-3459 [MEDIUM] CWE-264 CVE-2012-3459: Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows
Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote authenticated users to modify Condor attributes and possibly gain privileges via crafted additional parameters in an HTTP POST request, which triggers a job attribute change request to Condor.
nvd
CVE-2013-4405P4MEDIUMCVSS 6.8v2.42013-12-23
CVE-2013-4405 [MEDIUM] CWE-352 CVE-2013-4405: Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allow remote attackers to hijack the authentication of cumin users for unspecified requests.
nvd
CVE-2009-5005P4MEDIUMCVSS 5.0≤ 1.2.2v1.0+6 more2010-10-18
CVE-2009-5005 [MEDIUM] CVE-2009-5005: The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enter
The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote attackers to cause a denial of service (daemon crash and cluster outage) via invalid AMQP data.
nvd
CVE-2014-3706P4MEDIUMCVSS 5.9v3.02017-10-18
CVE-2014-3706 [MEDIUM] CWE-295 CVE-2014-3706: ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by lever
ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to verify key attributes in vdsm X.509 certificates.
nvd
CVE-2012-2680P4MEDIUMCVSS 5.0v2.02012-09-28
CVE-2012-2680 [MEDIUM] CWE-264 CVE-2012-2680: Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, does n
Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, does not properly restrict access to resources, which allows remote attackers to obtain sensitive information via unspecified vectors related to (1) "web pages," (2) "export functionality," and (3) "image viewing."
nvd
CVE-2014-8181P4MEDIUMCVSS 5.5v2.02019-11-06
CVE-2014-8181 [MEDIUM] CWE-665 CVE-2014-8181: The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, whi
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.
nvd
CVE-2020-27825P4MEDIUMCVSS 5.7v2.02020-12-11
CVE-2020-27825 [MEDIUM] CWE-362 CVE-2020-27825: A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). The
A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of service problem (DOS). This flaw could even allow a local attacker with special user privilege to a kernel information leak threat.
nvd