Oracle Linux vulnerabilities
228 known vulnerabilities affecting oracle/linux.
Total CVEs
228
CISA KEV
7
actively exploited
Public exploits
14
Exploited in wild
9
Severity breakdown
CRITICAL24HIGH84MEDIUM101LOW19
Vulnerabilities
Page 12 of 12
CVE-2015-4836P4LOWCVSS 2.8v72015-10-21
CVE-2015-4836 [LOW] CVE-2015-4836: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : SP.
nvd
CVE-2013-7421P4LOWCVSS 2.1v5v6+1 more2015-03-02
CVE-2013-7421 [LOW] CWE-269 CVE-2013-7421: The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.
nvd
CVE-2014-2678P4MEDIUMCVSS 4.7v52014-04-01
CVE-2014-2678 [MEDIUM] CWE-476 CVE-2014-2678: The rds_iw_laddr_check function in net/rds/iw.c in the Linux kernel through 3.14 allows local users
The rds_iw_laddr_check function in net/rds/iw.c in the Linux kernel through 3.14 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a bind system call for an RDS socket on a system that lacks RDS transports.
nvd
CVE-2014-9644P4LOWCVSS 2.1v5v6+1 more2015-03-02
CVE-2014-9644 [LOW] CVE-2014-9644: The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-2013-7421.
nvd
CVE-2007-6283P4MEDIUMCVSS 4.9v5.02007-12-18
CVE-2007-6283 [MEDIUM] CWE-200 CVE-2007-6283: Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permis
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.
nvd
CVE-2014-8134P4LOWCVSS 3.3v62014-12-12
CVE-2014-8134 [LOW] CVE-2014-8134: The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an im
The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted application that reads a 16-bit value.
nvd
CVE-2014-1738P4LOWCVSS 2.1v5v62014-05-11
CVE-2014-1738 [LOW] CWE-200 CVE-2014-1738: The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not p
The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device.
nvd
CVE-2014-9584P4LOWCVSS 2.1v52015-01-09
CVE-2014-9584 [LOW] CWE-20 CVE-2014-9584: The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 do
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.
nvd
← Previous12 / 12