cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,853 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,853
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH638MEDIUM890LOW158

Vulnerabilities

Page 39 of 93
CVE-2021-3772P3MEDIUMCVSS 6.5v8.02022-03-02
CVE-2021-3772 [MEDIUM] CWE-354 CVE-2021-3772: A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP asso A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through invalid chunks if the attacker knows the IP-addresses and port numbers being used and the attacker can send packets with spoofed IP addresses.
nvd
CVE-2016-0720P3HIGHCVSS 8.8v7.02017-04-21
CVE-2016-0720 [HIGH] CWE-352 CVE-2016-0720: Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149. Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
nvd
CVE-2022-24808P3MEDIUMCVSS 6.5v9.02024-04-16
CVE-2022-24808 [MEDIUM] CWE-476 CVE-2022-24808: net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing
nvd
CVE-2008-2365P4MEDIUMCVSS 4.7PoCv4.02008-06-30
CVE-2008-2365 [MEDIUM] CWE-362 CVE-2008-2365: Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_ATTACH ptrace calls to another user's process that trigger a conflict between utrace_detach and report_quiescent, related to "late ptr
nvd
CVE-2016-0741P3HIGHCVSS 7.5v7.02016-04-19
CVE-2016-0741 [HIGH] CWE-399 CVE-2016-0741: slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an abnormally closed connection.
nvd
CVE-2026-9150P3MEDIUMCVSS 6.5v7.0v8.0+2 more2026-05-20
CVE-2026-9150 [MEDIUM] CWE-121 CVE-2026-9150: A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debi A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.
nvd
CVE-2010-4251P3HIGHCVSS 7.5v4.02011-05-26
CVE-2010-4251 [HIGH] CWE-400 CVE-2010-4251: The socket implementation in net/core/sock.c in the Linux kernel before 2.6.34 does not properly man The socket implementation in net/core/sock.c in the Linux kernel before 2.6.34 does not properly manage a backlog of received packets, which allows remote attackers to cause a denial of service (memory consumption) by sending a large amount of network traffic, as demonstrated by netperf UDP tests.
nvd
CVE-2006-5170P3HIGHCVSS 7.5v4.02006-10-10
CVE-2006-5170 [HIGH] CWE-755 CVE-2006-5170: pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other di pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally repo
nvd
CVE-2016-0721P3HIGHCVSS 8.1v7.02017-04-21
CVE-2016-0721 [HIGH] CWE-384 CVE-2016-0721: Session fixation vulnerability in pcsd in pcs before 0.9.157. Session fixation vulnerability in pcsd in pcs before 0.9.157.
nvd
CVE-2018-16228P3HIGHCVSS 7.5v7.0v8.02019-10-03
CVE-2018-16228 [HIGH] CWE-125 CVE-2018-16228: The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix(). The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().
nvd
CVE-2013-4397P3MEDIUMCVSS 6.8v6.02013-10-17
CVE-2013-4397 [MEDIUM] CWE-189 CVE-2013-4397: Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remo Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) name or (2) link in an archive, which triggers a heap-based buffer overflow.
nvd
CVE-2026-11786P3MEDIUMCVSS 6.5v7.0v8.0+2 more2026-06-09
CVE-2026-11786 [MEDIUM] CWE-125 CVE-2026-11786: A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when p A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable under memory instrumentation.
nvd
CVE-2026-0964P3MEDIUMCVSS 6.3v8.0v9.0+1 more2026-03-26
CVE-2026-0964 [MEDIUM] CVE-2026-0964: A malicious SCP server can send unexpected paths that could make the client application override loc A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could be misused to create malicious executable or configuration files and make the user execute them under specific consequences. This is the same issue as in OpenSSH, tracked as CVE-2019-6111.
nvd
CVE-2026-11787P3MEDIUMCVSS 6.3v7.0v8.0+2 more2026-06-09
CVE-2026-11787 [MEDIUM] CWE-126 CVE-2026-11787: A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.
nvd
CVE-2015-4021P4MEDIUMCVSS 5.0v6.0v7.02015-06-09
CVE-2015-4021 [MEDIUM] CWE-189 CVE-2015-4021: The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6 The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 does not verify that the first character of a filename is different from the \0 character, which allows remote attackers to cause a denial of service (integer underflow and memory corruption) via a crafted entry in a tar archive.
nvd
CVE-2018-14645P3HIGHCVSS 7.5v7.0v7.3+3 more2018-09-21
CVE-2018-14645 [HIGH] CWE-125 CVE-2018-14645: A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An ou A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
nvd
CVE-2017-5333P3HIGHCVSS 7.8v7.02019-11-04
CVE-2017-5333 [HIGH] CWE-190 CVE-2017-5333: Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icout Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.
nvd
CVE-2017-5332P3HIGHCVSS 7.8v7.02019-11-04
CVE-2017-5332 [HIGH] CWE-119 CVE-2017-5332: The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access un The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
nvd
CVE-2017-9953P3HIGHCVSS 7.5v7.02017-06-26
CVE-2017-9953 [HIGH] CWE-416 CVE-2017-9953: There is an invalid free in Image::printIFDStructure that leads to a Segmentation fault in Exiv2 0.2 There is an invalid free in Image::printIFDStructure that leads to a Segmentation fault in Exiv2 0.26. A crafted input will lead to a remote denial of service attack.
nvd
CVE-2017-5445P3HIGHCVSS 7.5v6.0v7.02018-06-11
CVE-2017-5445 [HIGH] CWE-129 CVE-2017-5445: A vulnerability while parsing "application/http-index-format" format content where uninitialized val A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to create an array. This could allow the reading of uninitialized memory into the arrays affected. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
Redhat Enterprise Linux vulnerabilities | cvebase