cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,853 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,853
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH638MEDIUM890LOW158

Vulnerabilities

Page 31 of 93
CVE-2021-4207P3HIGHCVSS 8.2v8.02022-04-29
CVE-2021-4207 [HIGH] CWE-362 CVE-2021-4207: A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled val A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or
nvd
CVE-2012-1156P3HIGHCVSS 7.5v6.02019-11-14
CVE-2012-1156 [HIGH] CWE-532 CVE-2012-1156: Moodle before 2.2.2 has users' private files included in course backups Moodle before 2.2.2 has users' private files included in course backups
nvd
CVE-2022-1304P3HIGHCVSS 7.8v6.0v7.0+1 more2022-04-14
CVE-2022-1304 [HIGH] CWE-125 CVE-2022-1304: An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segme An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
nvd
CVE-2020-36332P3HIGHCVSS 7.5v8.02021-05-21
CVE-2020-36332 [HIGH] CWE-20 CVE-2020-36332: A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an exces A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
nvd
CVE-2023-2953P3HIGHCVSS 7.5v8.0v9.02023-05-30
CVE-2023-2953 [HIGH] CWE-476 CVE-2023-2953: A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_m A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
nvd
CVE-2017-5386P3HIGHCVSS 7.3v5.0v6.0+1 more2018-06-11
CVE-2017-5386 [HIGH] CVE-2017-5386: WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions usi WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential data disclosure or privilege escalation in affected extensions. This vulnerability affects Firefox ESR < 45.7 and Firefox < 51.
nvd
CVE-2023-52355P3HIGHCVSS 7.5v8.0v9.02024-01-25
CVE-2023-52355 [HIGH] CWE-787 CVE-2023-52355: An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.
nvd
CVE-2020-25708P3HIGHCVSS 7.5v6.0v7.0+1 more2020-11-27
CVE-2020-25708 [HIGH] CWE-369 CVE-2020-25708: A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a floating point exception, resulting in a denial of service.
nvd
CVE-2017-7518P3HIGHCVSS 7.8v7.02018-07-30
CVE-2017-7518 [HIGH] CWE-250 CVE-2017-7518: A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the tra A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug exception(#DB) being raised in the guest stack. A user/process inside a guest could use this flaw to potentially escalate their privileges inside the guest. Linux
nvd
CVE-2022-1652P3HIGHCVSS 7.8v9.02022-06-02
CVE-2022-1652 [HIGH] CWE-416 CVE-2022-1652: Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concu Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the bad_flp_intr function. By executing a specially-crafted program, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
nvd
CVE-2021-45417P3HIGHCVSS 7.8v6.0v7.0+1 more2022-01-20
CVE-2021-45417 [HIGH] CWE-787 CVE-2021-45417: AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as X AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.
nvd
CVE-2020-1749P3HIGHCVSS 7.5v7.02020-09-09
CVE-2020-1749 [HIGH] CWE-319 CVE-2020-1749: A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encrypted tunnel is created between two hosts, the kernel isn't correctly routing tunneled data over the encrypted link; rather sending the data unencrypted. This would allow anyone in between the two endpoints
nvd
CVE-2023-43787P3HIGHCVSS 7.8v8.0v9.02023-10-10
CVE-2023-43787 [HIGH] CWE-122 CVE-2023-43787: A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. T A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.
nvd
CVE-2025-26599P3HIGHCVSS 7.8v7.0v8.0+1 more2025-02-25
CVE-2025-26599 [HIGH] CWE-824 CVE-2025-26599: An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRe An access to an uninitialized pointer flaw was found in X.Org and Xwayland. The function compCheckRedirect() may fail if it cannot allocate the backing pixmap. In that case, compRedirectWindow() will return a BadAlloc error without validating the window tree marked just before, which leaves the validated data partly initialized and the use of an unini
nvd
CVE-2021-38160P3HIGHCVSS 7.8v8.02021-08-07
CVE-2021-38160 [HIGH] CWE-120 CVE-2021-38160: In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be t In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in
nvd
CVE-2024-0409P3HIGHCVSS 7.8v6.0v7.0+2 more2024-01-18
CVE-2024-0409 [HIGH] CWE-787 CVE-2024-0409: A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong typ A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context.
nvd
CVE-2020-25712P3HIGHCVSS 7.8v8.02020-12-15
CVE-2020-25712 [HIGH] CWE-122 CVE-2020-25712: A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may l A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2024-0841P3HIGHCVSS 7.8v8.0v9.02024-01-28
CVE-2024-0841 [HIGH] CWE-476 CVE-2024-0841: A null pointer dereference flaw was found in the hugetlbfs_fill_super function in the Linux kernel h A null pointer dereference flaw was found in the hugetlbfs_fill_super function in the Linux kernel hugetlbfs (HugeTLB pages) functionality. This issue may allow a local user to crash the system or potentially escalate their privileges on the system.
nvd
CVE-2021-3600P3HIGHCVSS 7.8v8.02024-01-08
CVE-2021-3600 [HIGH] CWE-125 CVE-2021-3600: It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds inf It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.
nvd
CVE-2022-2938P3HIGHCVSS 7.8v8.02022-08-23
CVE-2022-2938 [HIGH] CWE-416 CVE-2022-2938: A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the featu A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corruption side effects.
nvd
Redhat Enterprise Linux vulnerabilities | cvebase