cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,853 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,853
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH638MEDIUM890LOW158

Vulnerabilities

Page 24 of 93
CVE-2025-62230P3HIGHCVSS 7.3v8.0v9.0+1 more2025-10-30
CVE-2025-62230 [HIGH] CWE-416 CVE-2025-62230: A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resour A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect.
nvd
CVE-2018-1301P3MEDIUMCVSS 5.9v6.0v7.0+3 more2018-03-26
CVE-2018-1301 [MEDIUM] CWE-119 CVE-2018-1301: A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due t A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server us
nvd
CVE-2023-0778P3MEDIUMCVSS 6.8v8.0v9.02023-03-27
CVE-2023-0778 [MEDIUM] CWE-367 CVE-2023-0778: A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.
nvd
CVE-2018-10936P3HIGHCVSS 8.1v6.0v7.02018-08-30
CVE-2018-10936 [HIGH] CWE-297 CVE-2018-10936: A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Fac A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it
nvd
CVE-2021-40153P3HIGHCVSS 8.1v7.0v8.02021-08-27
CVE-2021-40153 [HIGH] CWE-22 CVE-2021-40153: squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; t squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.
nvd
CVE-2017-7785P3CRITICALCVSS 9.8v5.0v6.0+1 more2018-06-11
CVE-2017-7785 [CRITICAL] CWE-119 CVE-2017-7785: A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attribute A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2025-9572P3MEDIUMCVSS 6.5v9.02026-02-27
CVE-2025-9572 [MEDIUM] CWE-863 CVE-2025-9572: n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.
nvd
CVE-2012-0067P4MEDIUMCVSS 4.3PoCv52012-04-11
CVE-2012-0067 [MEDIUM] CWE-20 CVE-2012-0067: wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to wiretap/iptrace.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in an AIX iptrace file.
nvd
CVE-2019-18805P3CRITICALCVSS 9.8v7.02019-11-07
CVE-2019-18805 [CRITICAL] CWE-190 CVE-2019-18805: An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other impact, aka CID-19fad20d15a6.
nvd
CVE-2017-5376P3CRITICALCVSS 9.8v5.0v6.0+1 more2018-06-11
CVE-2017-5376 [CRITICAL] CWE-416 CVE-2017-5376: Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45 Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2013-4751P3HIGHCVSS 8.1v6.02019-11-01
CVE-2013-4751 [HIGH] CWE-20 CVE-2013-4751: php-symfony2-Validator has loss of information during serialization php-symfony2-Validator has loss of information during serialization
nvd
CVE-2017-5432P3CRITICALCVSS 9.8v6.0v7.02018-06-11
CVE-2017-5432 [CRITICAL] CWE-416 CVE-2017-5432: A use-after-free vulnerability occurs during certain text input selection resulting in a potentially A use-after-free vulnerability occurs during certain text input selection resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5435P3CRITICALCVSS 9.8v6.0v7.02018-06-11
CVE-2017-5435 [CRITICAL] CWE-416 CVE-2017-5435: A use-after-free vulnerability occurs during transaction processing in the editor during design mode A use-after-free vulnerability occurs during transaction processing in the editor during design mode interactions. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5446P3CRITICALCVSS 9.8v6.0v7.02018-06-11
CVE-2017-5446 [CRITICAL] CWE-125 CVE-2017-5446: An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5441P3CRITICALCVSS 9.8v6.0v7.02018-06-11
CVE-2017-5441 [CRITICAL] CWE-416 CVE-2017-5441: A use-after-free vulnerability when holding a selection during scroll events. This results in a pote A use-after-free vulnerability when holding a selection during scroll events. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2018-5096P3CRITICALCVSS 9.8v6.0v7.02018-06-11
CVE-2018-5096 [CRITICAL] CWE-416 CVE-2018-5096: A use-after-free vulnerability can occur while editing events in form elements on a page, resulting A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Thunderbird < 52.6.
nvd
CVE-2018-16884P3HIGHCVSS 8.0v7.02018-12-18
CVE-2018-16884 [HIGH] CWE-416 CVE-2018-16884: A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container user can cause a host kernel memory corruption and a system panic. Due to the nature of the flaw, privil
nvd
CVE-2017-5402P3CRITICALCVSS 9.8v5.0v6.0+1 more2018-06-11
CVE-2017-5402 [CRITICAL] CWE-416 CVE-2017-5402: A use-after-free can occur when events are fired for a "FontFace" object after the object has been a A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2020-35523P3HIGHCVSS 7.8v6.0v7.0+1 more2021-03-09
CVE-2020-35523 [HIGH] CWE-190 CVE-2020-35523: An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allo An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd
CVE-2007-3103P4MEDIUMCVSS 6.2PoCv4.02007-07-15
CVE-2007-3103 [MEDIUM] CWE-59 CVE-2007-3103: The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file.
nvd
Redhat Enterprise Linux vulnerabilities | cvebase