cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,853 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,853
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH638MEDIUM890LOW158

Vulnerabilities

Page 28 of 93
CVE-2023-44488P3HIGHCVSS 7.5v8.0v9.02023-09-30
CVE-2023-44488 [HIGH] CWE-755 CVE-2023-44488: VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding. VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
nvd
CVE-2020-0602P3HIGHCVSS 7.5v8.02020-01-14
CVE-2020-0602 [HIGH] CVE-2020-0602: A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
nvd
CVE-2022-2639P3HIGHCVSS 7.8v8.0v9.02022-09-01
CVE-2022-2639 [HIGH] CWE-192 CVE-2022-2639: An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large num An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does not return -EMSGSIZE as expected, potentially leading to an out-of-bounds write access. This flaw allows a local user to crash or poten
nvd
CVE-2018-1087P3HIGHCVSS 7.8v7.02018-05-15
CVE-2018-1087 [HIGH] CWE-250 CVE-2018-1087: kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, the processor did not deliver interrupts and e
nvd
CVE-2023-38200P3HIGHCVSS 7.5v9.02023-07-24
CVE-2023-38200 [HIGH] CWE-400 CVE-2023-38200: A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a rem A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections. This flaw allows an attacker to exhaust all available connections.
nvd
CVE-2015-4598P3MEDIUMCVSS 6.5v6.0v7.02016-05-16
CVE-2015-4598 [MEDIUM] CWE-20 CVE-2015-4598: PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument save method or (2) the GD imagepsloadfont function, as demonstrated by a filename\0.html attack that byp
nvd
CVE-2018-1128P3HIGHCVSS 7.5v7.02018-07-10
CVE-2018-1128 [HIGH] CWE-294 CVE-2018-1128: It was found that cephx authentication protocol did not verify ceph clients correctly and was vulner It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, lumino
nvd
CVE-2020-14361P3HIGHCVSS 7.8v6.0v7.0+1 more2020-09-15
CVE-2020-14361 [HIGH] CWE-191 CVE-2020-14361: A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2020-14362P3HIGHCVSS 7.8v6.0v7.0+1 more2020-09-15
CVE-2020-14362 [HIGH] CWE-191 CVE-2020-14362: A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2019-10168P3HIGHCVSS 7.8v7.0v8.02019-08-02
CVE-2019-10168 [HIGH] CWE-250 CVE-2019-10168: The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x befor The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an arbitrary pat
nvd
CVE-2022-1055P3HIGHCVSS 7.8v8.02022-03-29
CVE-2022-1055 [HIGH] CWE-416 CVE-2022-1055: A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to g A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5
nvd
CVE-2019-10166P3HIGHCVSS 7.8v7.0v8.02019-08-02
CVE-2019-10166 [HIGH] CWE-284 CVE-2019-10166: It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit r It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify this file such that libvirtd would
nvd
CVE-2025-7424P3HIGHCVSS 7.5v6.0v7.0+3 more2025-07-10
CVE-2025-7424 [HIGH] CWE-843 CVE-2025-7424: A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet an A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt memory. In some cases, it may lead to denial of service or unexpected behavior.
nvd
CVE-2021-4213P3HIGHCVSS 7.5v8.02022-08-24
CVE-2021-4213 [HIGH] CWE-401 CVE-2021-4213: A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.
nvd
CVE-2017-7753P3CRITICALCVSS 9.1v6.0v7.02018-06-11
CVE-2017-7753 [CRITICAL] CWE-125 CVE-2017-7753: An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, usi An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2021-33285P3HIGHCVSS 7.8v7.0v8.02021-09-07
CVE-2021-33285 [HIGH] CWE-787 CVE-2021-33285: In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vulnerability is caused by an out-of-bound buffer access which can be triggered by mounting a crafted ntfs partition. The root cause is
nvd
CVE-2021-20194P3HIGHCVSS 7.8v8.02021-02-23
CVE-2021-20194 [HIGH] CWE-20 CVE-2021-20194: There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with confi There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger bug in __cgroup_bpf_run_filter_get
nvd
CVE-2025-26601P3HIGHCVSS 7.8v7.0v8.0+1 more2025-02-25
CVE-2025-26601 [HIGH] CWE-416 CVE-2025-26601: A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the cha A use-after-free flaw was found in X.Org and Xwayland. When changing an alarm, the values of the change mask are evaluated one after the other, changing the trigger values as requested, and eventually, SyncInitTrigger() is called. If one of the changes triggers an error, the function will return early, not adding the new sync object, possibly causing
nvd
CVE-2022-0135P3HIGHCVSS 7.8v8.02022-08-25
CVE-2022-0135 [HIGH] CWE-787 CVE-2022-0135: An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This fl An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, leading to a denial of service or possible code execution.
nvd
CVE-2023-50781P3HIGHCVSS 7.5v8.0v9.02024-02-05
CVE-2023-50781 [HIGH] CWE-203 CVE-2023-50781: A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
nvd
Redhat Enterprise Linux vulnerabilities | cvebase