Redhat Enterprise Linux vulnerabilities
1,853 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,853
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH638MEDIUM890LOW158
Vulnerabilities
Page 27 of 93
CVE-2017-5396P3CRITICALCVSS 9.8v5.0v6.0+1 more2018-06-11
CVE-2017-5396 [CRITICAL] CWE-416 CVE-2017-5396: A use-after-free vulnerability in the Media Decoder when working with media files when some events a
A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2013-2174P3MEDIUMCVSS 6.8v5v6.02013-07-31
CVE-2013-2174 [MEDIUM] CWE-119 CVE-2013-2174: Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.
Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.
nvd
CVE-2020-27827P3HIGHCVSS 7.5v7.0v8.02021-03-18
CVE-2020-27827 [HIGH] CWE-400 CVE-2020-27827: A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memor
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
nvd
CVE-2019-10216P3HIGHCVSS 7.8v5.0v6.0+1 more2019-11-27
CVE-2019-10216 [HIGH] CWE-648 CVE-2019-10216: In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.
nvd
CVE-2017-2591P3HIGHCVSS 7.5v7.02018-04-30
CVE-2017-2591 [HIGH] CWE-122 CVE-2017-2591: 389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniquen
389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or possibly unauthenticated, attacker could use this flaw to force an out-of-bound heap memory read, possibly triggering a crash of the LDAP ser
nvd
CVE-2021-41819P3HIGHCVSS 7.5v8.02022-01-01
CVE-2021-41819 [HIGH] CWE-565 CVE-2021-41819: CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affe
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
nvd
CVE-2017-5401P3CRITICALCVSS 9.8v5.0v6.0+1 more2018-06-11
CVE-2017-5401 [CRITICAL] CWE-388 CVE-2017-5401: A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a l
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2018-16871P3HIGHCVSS 7.5v7.02019-07-30
CVE-2018-16871 [HIGH] CWE-476 CVE-2018-16871: A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up
A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any outstanding disk writes to the NFS se
nvd
CVE-2020-29573P3HIGHCVSS 7.5v7.02020-12-06
CVE-2020-29573 [HIGH] CWE-787 CVE-2020-29573: sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a s
sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of the printf family of functions is an 80-bit long double with a non-canonical bit pattern, as seen when passing a \x00\x04\x00\x00\x00\x00\x00\x00\x00\x04 value to sprintf. NOTE: the issue does not affect
nvd
CVE-2019-9854P3HIGHCVSS 7.8v7.0v8.02019-09-06
CVE-2019-9854 [HIGH] CVE-2019-9854: LibreOffice has a feature where documents can specify that pre-installed macros can be executed on v
LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2019-9852, to avoid a d
nvd
CVE-2017-7751P3CRITICALCVSS 9.8v6.0v7.02018-06-11
CVE-2017-7751 [CRITICAL] CWE-416 CVE-2017-7751: A use-after-free vulnerability with content viewer listeners that results in a potentially exploitab
A use-after-free vulnerability with content viewer listeners that results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2021-4206P3HIGHCVSS 8.2v8.02022-04-29
CVE-2021-4206 [HIGH] CWE-190 CVE-2021-4206: A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_allo
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the
nvd
CVE-2019-7548P3HIGHCVSS 7.8v8.02019-02-06
CVE-2019-7548 [HIGH] CWE-89 CVE-2019-7548: SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
nvd
CVE-2017-7801P3CRITICALCVSS 9.8v6.0v7.02018-06-11
CVE-2017-7801 [CRITICAL] CWE-416 CVE-2017-7801: A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during wi
A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where the updated style object is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2021-3750P3HIGHCVSS 8.2v8.02022-05-02
CVE-2021-3750 [HIGH] CWE-416 CVE-2021-3750: A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify
A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ult
nvd
CVE-2004-0803P3HIGHCVSS 7.5v2.1v3.02004-12-23
CVE-2004-0803 [HIGH] CVE-2004-0803: Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, re
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.
nvd
CVE-2012-1155P3HIGHCVSS 7.5v6.02019-11-14
CVE-2012-1155 [HIGH] CWE-200 CVE-2012-1155: Moodle has a database activity export permission issue where the export function of the database act
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
nvd
CVE-2026-58013P3HIGHCVSS 8.2v6.0v7.0+3 more2026-06-30
CVE-2026-58013 [HIGH] CWE-126 CVE-2026-58013: A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the gi
A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read
nvd
CVE-2017-7793P3CRITICALCVSS 9.8v5.0v6.0+1 more2018-06-11
CVE-2017-7793 [CRITICAL] CWE-416 CVE-2017-7793: A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window a
A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvd
CVE-2007-1351P3HIGHCVSS 8.5v2.1v3.0+2 more2007-04-06
CVE-2007-1351 [HIGH] CWE-189 CVE-2007-1351: Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 2007040
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.
nvd