Vulnerabilities (CVE)

Filtered by vendor Redhat Subscribe
Filtered by product Redhat Package Manager
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2002-2204 1 Redhat 1 Redhat Package Manager 2024-11-20 7.5 HIGH N/A
The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.
CVE-2001-0923 1 Redhat 1 Redhat Package Manager 2024-11-20 7.2 HIGH N/A
RPM Package Manager 4.0.x through 4.0.2.x allows an attacker to execute arbitrary code via corrupted data in the RPM file when the file is queried.