Redhat Enterprise Mrg vulnerabilities
73 known vulnerabilities affecting redhat/enterprise_mrg.
Total CVEs
73
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH20MEDIUM45LOW7
Vulnerabilities
Page 3 of 4
CVE-2015-7837P4MEDIUMCVSS 5.5v2.02017-09-19
CVE-2015-7837 [MEDIUM] CWE-254 CVE-2015-7837: The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when bo
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot.
nvd
CVE-2013-4284P4MEDIUMCVSS 5.0v2.42013-10-09
CVE-2013-4284 [MEDIUM] CWE-399 CVE-2013-4284: Cumin, as used in Red Hat Enterprise MRG 2.4, allows remote attackers to cause a denial of service (
Cumin, as used in Red Hat Enterprise MRG 2.4, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted Ajax update request.
nvd
CVE-2012-2735P4MEDIUMCVSS 4.9v2.02012-09-28
CVE-2012-2735 [MEDIUM] CVE-2012-2735: Session fixation vulnerability in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Re
Session fixation vulnerability in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote attackers to hijack web sessions via a crafted session cookie.
nvd
CVE-2012-2682P4MEDIUMCVSS 5.0v2.52014-07-19
CVE-2012-2682 [MEDIUM] CWE-20 CVE-2012-2682: Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with cer
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of service (inaccessible page) via a non-ASCII character in the name of a link.
nvd
CVE-2017-15128P4MEDIUMCVSS 5.5v2.02018-01-14
CVE-2017-15128 [MEDIUM] CWE-119 CVE-2017-15128: A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before
A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.12. A lack of size check could cause a denial of service (BUG).
nvd
CVE-2013-6445P4MEDIUMCVSS 5.0v2.52014-04-30
CVE-2013-6445 [MEDIUM] CWE-310 CVE-2013-6445: Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier for attackers to obtain sensitive information via a brute-force attack.
nvd
CVE-2011-4930P4MEDIUMCVSS 4.4v1.3v2.02014-02-10
CVE-2011-4930 [MEDIUM] CWE-134 CVE-2011-4930: Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x ver
Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_schedd daemon and failure to launch jobs) and possibly execute arbitrary code via format string specifiers in (1) the reason for a hol
nvd
CVE-2010-3083P4MEDIUMCVSS 4.3≤ 1.2v1.0+5 more2010-10-12
CVE-2010-3083 [MEDIUM] CVE-2010-3083: sys/ssl/SslSocket.cpp in qpidd in Apache Qpid, as used in Red Hat Enterprise MRG before 1.2.2 and ot
sys/ssl/SslSocket.cpp in qpidd in Apache Qpid, as used in Red Hat Enterprise MRG before 1.2.2 and other products, when SSL is enabled, allows remote attackers to cause a denial of service (daemon outage) by connecting to the SSL port but not participating in an SSL handshake.
nvd
CVE-2017-15127P4MEDIUMCVSS 5.5v2.02018-01-14
CVE-2017-15127 [MEDIUM] CWE-460 CVE-2017-15127: A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before
A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13. A superfluous implicit page unlock for VM_SHARED hugetlbfs mapping could trigger a local denial of service (BUG).
nvd
CVE-2009-5006P4MEDIUMCVSS 4.0≤ 1.2.2v1.0+6 more2010-10-18
CVE-2009-5006 [MEDIUM] CVE-2009-5006: The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the
The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker component in Apache Qpid before 0.6, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote authenticated users to cause a denial of service (NULL pointer dereference, daemon crash, and cluster outage) by attempting to modify
nvd
CVE-2013-4414P4MEDIUMCVSS 4.3v2.42013-12-23
CVE-2013-4414 [MEDIUM] CWE-79 CVE-2013-4414: Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Gr
Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to inject arbitrary web script or HTML via the "Max allowance" field in the "Set limit" form.
nvd
CVE-2016-4470P4MEDIUMCVSS 5.5v2.02016-06-27
CVE-2016-4470 [MEDIUM] CVE-2016-4470: The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not e
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.
nvd
CVE-2015-1350P4MEDIUMCVSS 5.5v2.02016-05-02
CVE-2015-1350 [MEDIUM] CWE-552 CVE-2015-1350: The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr ope
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the pin
nvd
CVE-2014-8171P4MEDIUMCVSS 5.5v2.02018-02-09
CVE-2014-8171 [MEDIUM] CWE-399 CVE-2014-8171: The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial
The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.
nvd
CVE-2012-4462P4MEDIUMCVSS 4.3v2.32013-03-14
CVE-2012-4462 [MEDIUM] CWE-20 CVE-2012-4462: aviary/jobcontrol.py in Condor, as used in Red Hat Enterprise MRG 2.3, when removing a job, allows r
aviary/jobcontrol.py in Condor, as used in Red Hat Enterprise MRG 2.3, when removing a job, allows remote attackers to cause a denial of service (condor_schedd restart) via square brackets in the cproc option.
nvd
CVE-2012-2683P4MEDIUMCVSS 4.3v2.02012-09-28
CVE-2012-2683 [MEDIUM] CWE-79 CVE-2012-2683: Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Ent
Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) "error message displays" or (2) "in source HTML on certain pages."
nvd
CVE-2011-2925P4MEDIUMCVSS 4.6v2.02011-09-20
CVE-2011-2925 [MEDIUM] CWE-287 CVE-2011-2925: Cumin in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0 records broker authentication cr
Cumin in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0 records broker authentication credentials in a log file, which allows local users to bypass authentication and perform unauthorized actions on jobs and message queues via a direct connection to the broker.
nvd
CVE-2015-2922P4LOWCVSS 3.3v2.52015-05-27
CVE-2015-2922 [LOW] CWE-17 CVE-2015-2922: The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol impl
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.
nvd
CVE-2014-0174P4MEDIUMCVSS 4.3v2.52014-07-11
CVE-2014-0174 [MEDIUM] CWE-200 CVE-2014-0174: Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTP
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
nvd
CVE-2012-1090P4MEDIUMCVSS 5.5v2.02012-05-17
CVE-2012-1090 [MEDIUM] CWE-20 CVE-2012-1090: The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to ca
The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted access to a special file, as demonstrated by a FIFO.
nvd