cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,853 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,853
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH638MEDIUM890LOW158

Vulnerabilities

Page 16 of 93
CVE-2017-3071P3HIGHCVSS 8.8v6.02017-05-09
CVE-2017-3071 [HIGH] CWE-416 CVE-2017-3071: Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when masking display objects. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2019-11235P3CRITICALCVSS 9.8v7.02019-04-22
CVE-2019-11235 [CRITICAL] CWE-345 CVE-2019-11235: FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is withi FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar issue to CVE-2019-9498 and CVE-2019-9499.
nvd
CVE-2021-20305P3HIGHCVSS 8.1v7.0v8.02021-04-05
CVE-2021-20305 [HIGH] CWE-327 CVE-2021-20305: A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification fun A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to force an invalid signature, causing
nvd
CVE-2024-9341P3HIGHCVSS 8.2v8.0v9.02024-10-01
CVE-2024-9341 [HIGH] CWE-59 CVE-2024-9341: A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly ha A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attacker
nvd
CVE-2021-3935P3HIGHCVSS 8.1v7.02021-11-22
CVE-2021-3935 [HIGH] CWE-89 CVE-2021-3935: When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject a When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.
nvd
CVE-2019-12450P3CRITICALCVSS 9.8v8.02019-05-29
CVE-2019-12450 [CRITICAL] CWE-276 CVE-2019-12450: file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict fil file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.
nvd
CVE-2017-3070P3HIGHCVSS 8.8v6.02017-05-09
CVE-2017-3070 [HIGH] CWE-787 CVE-2017-3070: Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the ConvolutionFilter class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3069P3HIGHCVSS 8.8v6.02017-05-09
CVE-2017-3069 [HIGH] CWE-787 CVE-2017-3069: Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the BlendMode class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-3072P3HIGHCVSS 8.8v6.02017-05-09
CVE-2017-3072 [HIGH] CWE-787 CVE-2017-3072: Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerabili Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the BitmapData class. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2026-2436P3HIGHCVSS 8.2v6.0v7.0+3 more2026-03-26
CVE-2026-2436 [HIGH] CWE-825 CVE-2026-2436: A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerabi A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` function frees connection objects prematurely, even if a TLS handshake is still pending. If the handshake completes after the connection object has been freed, a dangling pointer is accessed, leading to a server c
nvd
CVE-2025-9784P3HIGHCVSS 7.5v8.0v9.02025-09-02
CVE-2025-9784 [HIGH] CWE-770 CVE-2025-9784: A flaw was found in Undertow where malformed client requests can trigger server-side stream resets w A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implem
nvd
CVE-2017-3073P3HIGHCVSS 8.8v6.02017-05-09
CVE-2017-3073 [HIGH] CWE-416 CVE-2017-3073: Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when handling multiple mask properties of display objects, aka memory corruption. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2012-1149P3HIGHCVSS 7.5v5.02012-06-21
CVE-2012-1149 [HIGH] CWE-189 CVE-2012-1149: Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based b
nvd
CVE-2018-18313P3CRITICALCVSS 9.1v6.0v7.0+3 more2018-12-07
CVE-2018-18313 [CRITICAL] CWE-125 CVE-2018-18313: Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.
nvd
CVE-2025-3891P3HIGHCVSS 7.5v7.0v8.0+1 more2025-04-29
CVE-2025-3891 [HIGH] CWE-248 CVE-2025-3891: A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthe A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
nvd
CVE-2023-4147P3HIGHCVSS 7.8v9.02023-08-07
CVE-2023-4147 [HIGH] CWE-416 CVE-2023-4147: A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule wit A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system.
nvd
CVE-2023-4692P3HIGHCVSS 7.8v8.0v9.02023-10-25
CVE-2023-4692 [HIGH] CWE-122 CVE-2023-4692: An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an att An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code execution and secure boot protection by
nvd
CVE-2026-35092P3HIGHCVSS 7.5v7.0v8.0+2 more2026-04-01
CVE-2026-35092 [HIGH] CWE-190 CVE-2026-35092: A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity va A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use
nvd
CVE-2026-50261P3HIGHCVSS 7.8v7.0v8.0+2 more2026-06-05
CVE-2026-50261 [HIGH] CWE-416 CVE-2026-50261: A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via a second client connection while changing those counters. This may be used to crash the server, or for privilege escalation if the X server runs as root.
nvd
CVE-2026-50260P3HIGHCVSS 7.8v7.0v8.0+2 more2026-06-05
CVE-2026-50260 [HIGH] CWE-416 CVE-2026-50260: A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that s A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroying those counters via a second client connection. This may be used to crash the server, or for privilege escalation if the X server runs as root.
nvd
Redhat Enterprise Linux vulnerabilities | cvebase