Redhat Enterprise Linux vulnerabilities
1,738 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,738
CISA KEV
20
actively exploited
Public exploits
88
Exploited in wild
26
Severity breakdown
CRITICAL157HIGH589MEDIUM839LOW153
Vulnerabilities
Page 16 of 87
CVE-2023-3161MEDIUMCVSS 5.5v8.0v9.02023-06-12
CVE-2023-3161 [MEDIUM] CWE-1335 CVE-2023-3161: A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width
A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined behavior and possible denial of service.
nvd
CVE-2023-2454HIGHCVSS 7.2v8.0v9.02023-06-09
CVE-2023-2454 [HIGH] CWE-20 CVE-2023-2454: schema_element defeats protective search_path changes; It was found that certain database calls in P
schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.
nvd
CVE-2023-2455MEDIUMCVSS 5.4v8.0v9.02023-06-09
CVE-2023-2455 [MEDIUM] CWE-20 CVE-2023-2455: Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect po
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is plan
nvd
CVE-2023-2603HIGHCVSS 7.8v8.0v9.02023-06-06
CVE-2023-2603 [HIGH] CWE-190 CVE-2023-2603: A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
nvd
CVE-2023-2602LOWCVSS 3.3v6.0v7.0+2 more2023-06-06
CVE-2023-2602 [LOW] CWE-401 CVE-2023-2602: A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicio
A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.
nvd
CVE-2023-2977HIGHCVSS 7.1v8.0v9.02023-06-01
CVE-2023-2977 [HIGH] CWE-119 CVE-2023-2977: A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs1
A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer
nvd
CVE-2023-34152CRITICALCVSS 9.8v6.0v7.02023-05-30
CVE-2023-34152 [CRITICAL] CWE-20 CVE-2023-34152: A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerabi
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
nvd
CVE-2023-34153HIGHCVSS 7.8v6.0v7.02023-05-30
CVE-2023-34153 [HIGH] CWE-77 CVE-2023-34153: A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulner
A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.
nvd
CVE-2023-2953HIGHCVSS 7.5v8.0v9.02023-05-30
CVE-2023-2953 [HIGH] CWE-476 CVE-2023-2953: A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_m
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
nvd
CVE-2023-34151MEDIUMCVSS 5.5v6.0v7.02023-05-30
CVE-2023-34151 [MEDIUM] CVE-2023-34151: A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of ca
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
nvd
CVE-2023-2283MEDIUMCVSS 6.5v8.0v9.02023-05-26
CVE-2023-2283 [MEDIUM] CWE-287 CVE-2023-2283: A vulnerability was found in libssh, where the authentication check of the connecting client can be
A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is insufficient memory or the memory usage is limited. The problem is caused by the return value `rc,` which is initialized to SSH_ERROR and
nvd
CVE-2023-1981MEDIUMCVSS 5.5v6.0v7.0+2 more2023-05-26
CVE-2023-1981 [MEDIUM] CWE-400 CVE-2023-1981: A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
nvd
CVE-2023-1667MEDIUMCVSS 6.5v8.0v9.02023-05-26
CVE-2023-1667 [MEDIUM] CWE-476 CVE-2023-1667: A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue
A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.
nvd
CVE-2023-33203MEDIUMCVSS 6.4v8.0v9.02023-05-18
CVE-2023-33203 [MEDIUM] CWE-362 CVE-2023-33203: The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ether
The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device.
nvd
CVE-2023-2203HIGHCVSS 8.8v8.0v9.02023-05-17
CVE-2023-2203 [HIGH] CWE-416 CVE-2023-2203: A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-afte
A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK pa
nvd
CVE-2023-2295HIGHCVSS 7.5v8.0v9.02023-05-17
CVE-2023-2295 [HIGH] CWE-400 CVE-2023-2295: A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggress
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the plu
nvd
CVE-2023-2491HIGHCVSS 7.8v8.0v9.02023-05-17
CVE-2023-2491 [HIGH] CWE-77 CVE-2023-2491: A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "or
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
nvd
CVE-2023-2731MEDIUMCVSS 5.5v9.02023-05-17
CVE-2023-2731 [MEDIUM] CWE-476 CVE-2023-2731: A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c
A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.
nvd
CVE-2023-2700MEDIUMCVSS 5.5v8.0v9.02023-05-15
CVE-2023-2700 [MEDIUM] CWE-401 CVE-2023-2700: A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IO
A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.
nvd
CVE-2023-1729MEDIUMCVSS 6.5v7.0v8.0+1 more2023-05-15
CVE-2023-1729 [MEDIUM] CWE-119 CVE-2023-1729: A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted
A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
nvd