Oracle Linux vulnerabilities
228 known vulnerabilities affecting oracle/linux.
Total CVEs
228
CISA KEV
7
actively exploited
Public exploits
14
Exploited in wild
9
Severity breakdown
CRITICAL24HIGH84MEDIUM101LOW19
Vulnerabilities
Page 10 of 12
CVE-2026-21996P4MEDIUMCVSS 5.5v8v9+1 more2026-05-01
CVE-2026-21996 [MEDIUM] CWE-369 CVE-2026-21996: An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF bin
An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an integer Divide-by-Zero in Pbuild_file_symtab()
nvd
CVE-2016-5444P4LOWCVSS 3.7v72016-07-21
CVE-2016-5444 [LOW] CVE-2016-5444: Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and ear
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to Server: Connection.
nvd
CVE-2016-3452P4LOWCVSS 3.7v72016-07-21
CVE-2016-3452 [LOW] CVE-2016-3452: Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.10 and ear
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to Server: Security: Encryption.
nvd
CVE-2015-8922P4MEDIUMCVSS 5.5v72016-09-20
CVE-2015-8922 [MEDIUM] CWE-476 CVE-2015-8922: The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows
The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to the _7z_folder struct.
nvd
CVE-2016-5403P4MEDIUMCVSS 5.5v5v6+1 more2016-08-02
CVE-2016-5403 [MEDIUM] CWE-400 CVE-2016-5403: The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cau
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
nvd
CVE-2022-21504P4MEDIUMCVSS 5.5v7v82022-06-14
CVE-2022-21504 [MEDIUM] CWE-416 CVE-2022-21504: The code in UEK6 U3 was missing an appropiate file descriptor count to be missing. This resulted in
The code in UEK6 U3 was missing an appropiate file descriptor count to be missing. This resulted in a use count error that allowed a file descriptor to a socket to be closed and freed while it was still in use by another portion of the kernel. An attack with local access can operate on the socket, and cause a denial of service. CVSS 3.1 Base Score 5.
nvd
CVE-2015-6244P4MEDIUMCVSS 4.3v72015-08-24
CVE-2015-6244 [MEDIUM] CWE-20 CVE-2015-6244: The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector i
The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improperly relies on length fields contained in packet data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
nvd
CVE-2023-22024P4MEDIUMCVSS 5.5v6v7+2 more2023-09-20
CVE-2023-22024 [MEDIUM] CVE-2023-22024: In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS
In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6_CONN_RESET, that are not re-entrant. A malicious local user with CAP_NET_ADMIN can use this to crash the kernel. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
nvd
CVE-2016-0616P4MEDIUMCVSS 4.0v72016-01-21
CVE-2016-0616 [MEDIUM] CVE-2016-0616: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x befor
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2015-6248P4MEDIUMCVSS 4.3v72015-08-24
CVE-2015-6248 [MEDIUM] CWE-20 CVE-2015-6248: The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x befor
The ptvcursor_add function in the ptvcursor implementation in epan/proto.c in Wireshark 1.12.x before 1.12.7 does not check whether the expected amount of data is available, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
nvd
CVE-2015-6243P4MEDIUMCVSS 4.3v72015-08-24
CVE-2015-6243 [MEDIUM] CWE-20 CVE-2015-6243: The dissector-table implementation in epan/packet.c in Wireshark 1.12.x before 1.12.7 mishandles tab
The dissector-table implementation in epan/packet.c in Wireshark 1.12.x before 1.12.7 mishandles table searches for empty strings, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to the (1) dissector_get_string_handle and (2) dissector_get_default_string_handle functions.
nvd
CVE-2015-4815P4MEDIUMCVSS 4.0v72015-10-21
CVE-2015-4815 [MEDIUM] CVE-2015-4815: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DDL.
nvd
CVE-2015-0239P4MEDIUMCVSS 4.4v5v72015-03-02
CVE-2015-0239 [MEDIUM] CWE-269 CVE-2015-0239: The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of a 16-bit code segment for emulation of a SYSENTER instruction.
nvd
CVE-2014-8559P4MEDIUMCVSS 5.5v72014-11-10
CVE-2014-8559 [MEDIUM] CWE-400 CVE-2014-8559: The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the
The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.
nvd
CVE-2014-3647P4MEDIUMCVSS 5.5v72014-11-10
CVE-2014-3647 [MEDIUM] CVE-2014-3647: arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly per
arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
nvd
CVE-2016-6197P4MEDIUMCVSS 5.5v62016-08-06
CVE-2016-6197 [MEDIUM] CWE-20 CVE-2016-6197: fs/overlayfs/dir.c in the OverlayFS filesystem implementation in the Linux kernel before 4.6 does no
fs/overlayfs/dir.c in the OverlayFS filesystem implementation in the Linux kernel before 4.6 does not properly verify the upper dentry before proceeding with unlink and rename system-call processing, which allows local users to cause a denial of service (system crash) via a rename system call that specifies a self-hardlink.
nvd
CVE-2016-1965P4MEDIUMCVSS 4.3v5.0v6+1 more2016-03-13
CVE-2016-1965 [MEDIUM] CWE-254 CVE-2016-1965: Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that re
Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the location.protocol property.
nvd
CVE-2015-3455P4LOWCVSS 2.6v72015-05-18
CVE-2015-3455 [LOW] CWE-20 CVE-2015-3455: Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when co
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.
nvd
CVE-2016-6198P4MEDIUMCVSS 5.5v62016-08-06
CVE-2016-6198 [MEDIUM] CWE-284 CVE-2016-6198: The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an
The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an OverlayFS file is renamed to a self-hardlink, which allows local users to cause a denial of service (system crash) via a rename system call, related to fs/namei.c and fs/open.c.
nvd
CVE-2016-4470P4MEDIUMCVSS 5.5v5.0v6+1 more2016-06-27
CVE-2016-4470 [MEDIUM] CVE-2016-4470: The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not e
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.
nvd