Redhat Enterprise Linux vulnerabilities
1,853 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,853
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH638MEDIUM890LOW158
Vulnerabilities
Page 13 of 93
CVE-2018-16396P3HIGHCVSS 8.1v6.0v7.0+3 more2018-11-16
CVE-2018-16396 [HIGH] CVE-2018-16396: An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x befo
An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.
nvd
CVE-2013-4409P3CRITICALCVSS 9.8v6.02019-11-04
CVE-2013-4409 [CRITICAL] CWE-20 CVE-2013-4409: An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.
nvd
CVE-2019-19340P3HIGHCVSS 8.2v7.02019-12-19
CVE-2019-19340 [HIGH] CWE-1188 CVE-2019-19340: A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enablin
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active, an attacker could guess the password and gain access to the system.
nvd
CVE-2019-6470P3HIGHCVSS 7.5v8.02019-11-01
CVE-2019-6470 [HIGH] CVE-2019-6470: There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when o
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC contain copies of this, and other, BIND lib
nvd
CVE-2019-5010P3HIGHCVSS 7.5v8.02019-10-31
CVE-2019-5010 [HIGH] CWE-476 CVE-2019-5010: An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org P
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.
nvd
CVE-2026-35091P3HIGHCVSS 8.2v7.0v8.0+2 more2026-04-01
CVE-2026-35091 [HIGH] CWE-253 CVE-2026-35091: A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vul
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and potentially disclosing limited memory conte
nvd
CVE-2017-5456P3CRITICALCVSS 9.8v7.02018-06-11
CVE-2017-5456 [CRITICAL] CWE-732 CVE-2017-5456: A mechanism to bypass file system access protections in the sandbox using the file system request co
A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for read and write access to the local file system. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53.
nvd
CVE-2021-20314P3CRITICALCVSS 9.8v7.02021-08-12
CVE-2021-20314 [CRITICAL] CWE-787 CVE-2021-20314: Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead t
Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages.
nvd
CVE-2019-3883P3HIGHCVSS 7.5v6.02019-04-17
CVE-2019-3883 [HIGH] CWE-772 CVE-2019-3883: In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be
In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into account during reads, and may hang longer.An unauthenticated attacker could r
nvd
CVE-2026-3497P3HIGHCVSS 7.5v8.0v9.0+1 more2026-03-12
CVE-2026-3497 [HIGH] CWE-908 CVE-2026-3497: Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerabilit
Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI
nvd
CVE-2011-2897P3CRITICALCVSS 9.8v4.0v5.02019-11-12
CVE-2011-2897 [CRITICAL] CWE-20 CVE-2011-2897: gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw
nvd
CVE-2026-50259P3HIGHCVSS 7.8v7.0v8.0+2 more2026-06-05
CVE-2026-50259 [HIGH] CWE-121 CVE-2026-50259: A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks()
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function CheckKeyTypes() writes to this buffer at a client-controlled offset, allowing a stack buffer overflow. This may be used to crash the server, or for privilege
nvd
CVE-2026-50256P3HIGHCVSS 7.8v7.0v8.0+2 more2026-06-05
CVE-2026-50256 [HIGH] CWE-121 CVE-2026-50256: A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow during font alias resolution. The server allocates a 256 byte stack buffer but libXfont2's alias target name length is 1024 bytes. A font alias name betwe
nvd
CVE-2026-9064P3HIGHCVSS 7.5v6.0v7.0+3 more2026-05-20
CVE-2026-9064 [HIGH] CWE-770 CVE-2026-9064: A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), c
nvd
CVE-2021-4048P3CRITICALCVSS 9.1v8.02021-12-08
CVE-2021-4048 [CRITICAL] CWE-125 CVE-2021-4048: An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack t
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory.
nvd
CVE-2018-25009P3CRITICALCVSS 9.1v8.02021-05-21
CVE-2018-25009 [CRITICAL] CWE-125 CVE-2018-25009: A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
nvd
CVE-2018-25012P3CRITICALCVSS 9.1v8.02021-05-21
CVE-2018-25012 [CRITICAL] CWE-125 CVE-2018-25012: A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
nvd
CVE-2018-25013P3CRITICALCVSS 9.1v8.02021-05-21
CVE-2018-25013 [CRITICAL] CWE-125 CVE-2018-25013: A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
nvd
CVE-2013-3301P4HIGHCVSS 7.2PoCv6.02013-04-29
CVE-2013-3301 [HIGH] CVE-2013-3301: The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of s
The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.
nvd
CVE-2026-34002P3CRITICALCVSS 9.1v6.0v7.0+3 more2026-05-05
CVE-2026-34002 [CRITICAL] CWE-805 CVE-2026-34002: A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (
A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit this by sending a malformed request, which causes the server to read beyond its intended memory boundaries. This can lead to the exposure of sensitive
nvd