cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,853 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,853
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH638MEDIUM890LOW158

Vulnerabilities

Page 41 of 93
CVE-2011-1002P4MEDIUMCVSS 5.0v5.0v6.02011-02-22
CVE-2011-1002 [MEDIUM] CVE-2011-1002: avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-2244.
nvd
CVE-2017-12197P3MEDIUMCVSS 6.5v6.02018-01-18
CVE-2017-12197 [MEDIUM] CWE-863 CVE-2017-12197: It was found that libpam4j up to and including 1.8 did not properly validate user accounts when auth It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information.
nvd
CVE-2023-4527P3MEDIUMCVSS 6.5v8.0v9.02023-09-18
CVE-2023-4527 [MEDIUM] CWE-121 CVE-2023-4527: A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
nvd
CVE-2023-5088P3HIGHCVSS 7.0v8.0v9.02023-11-03
CVE-2023-5088 [HIGH] CWE-821 CVE-2023-5088: A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to b A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). This could be used, for example, by L2 guests with a virtual disk (vdiskL2) stored on a virtual disk of an L1 (vdiskL1) hypervisor to read and/or write data to LBA 0 of vdiskL1,
nvd
CVE-2019-14824P3MEDIUMCVSS 6.5v7.02019-11-08
CVE-2019-14824 [MEDIUM] CWE-732 CVE-2019-14824: A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.
nvd
CVE-2022-24809P3MEDIUMCVSS 6.5v9.02024-04-16
CVE-2022-24809 [MEDIUM] CWE-476 CVE-2022-24809: net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credenti
nvd
CVE-2015-3412P3MEDIUMCVSS 5.3v6.0v7.02016-05-16
CVE-2015-3412 [MEDIUM] CWE-200 CVE-2015-3412: PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack % PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via crafted input to an application that calls the stream_resolve_include_path function in ext/standard/streamsfuncs.c, as demonstrated by a filename\0.extension attack that bypass
nvd
CVE-2026-3012P3MEDIUMCVSS 6.8v7.0v9.02026-05-27
CVE-2026-3012 [MEDIUM] CWE-345 CVE-2026-3012: A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit th
nvd
CVE-2011-3191P4HIGHCVSS 8.8v4.02012-05-24
CVE-2011-3191 [HIGH] CWE-119 CVE-2011-3191: Integer signedness error in the CIFSFindNext function in fs/cifs/cifssmb.c in the Linux kernel befor Integer signedness error in the CIFSFindNext function in fs/cifs/cifssmb.c in the Linux kernel before 3.1 allows remote CIFS servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large length value in a response to a read request for a directory.
nvd
CVE-2023-5455P3MEDIUMCVSS 6.5v7.0v8.0+2 more2024-01-10
CVE-2023-5455 [MEDIUM] CWE-352 CVE-2023-5455: A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported ver A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certai
nvd
CVE-2025-47711P3MEDIUMCVSS 6.5v7.0v8.0+2 more2025-06-09
CVE-2025-47711 [MEDIUM] CWE-193 CVE-2025-47711: There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, leading to a denial-of-service.
nvd
CVE-2010-4805P4HIGHCVSS 7.5v4.02011-05-26
CVE-2010-4805 [HIGH] CVE-2010-4805: The socket implementation in net/core/sock.c in the Linux kernel before 2.6.35 does not properly man The socket implementation in net/core/sock.c in the Linux kernel before 2.6.35 does not properly manage a backlog of received packets, which allows remote attackers to cause a denial of service by sending a large amount of network traffic, related to the sk_add_backlog function and the sk_rmem_alloc socket field. NOTE: this vulnerability exists because of an in
nvd
CVE-2019-7310P4HIGHCVSS 7.8v8.02019-02-03
CVE-2019-7310 [HIGH] CWE-125 CVE-2019-7310: In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::ge In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document, as demonstrated by pdftocairo.
nvd
CVE-2026-0990P3MEDIUMCVSS 5.9v6.0v7.0+3 more2026-01-15
CVE-2026-0990 [MEDIUM] CWE-674 CVE-2026-0990: A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occur A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recu
nvd
CVE-2019-14494P4HIGHCVSS 7.5v7.0v8.02019-08-01
CVE-2019-14494 [HIGH] CWE-369 CVE-2019-14494: An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function S An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.
nvd
CVE-2011-4967P4HIGHCVSS 7.5v4.0v5.0+1 more2019-11-19
CVE-2011-4967 [HIGH] CWE-20 CVE-2011-4967: tog-Pegasus has a package hash collision DoS vulnerability tog-Pegasus has a package hash collision DoS vulnerability
nvd
CVE-2021-45078P3HIGHCVSS 7.8v8.02021-12-15
CVE-2021-45078 [HIGH] CVE-2021-45078: stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial o stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
nvd
CVE-2012-0877P4HIGHCVSS 7.5v5.0v6.02019-11-22
CVE-2012-0877 [HIGH] CWE-400 CVE-2012-0877: PyXML: Hash table collisions CPU usage Denial of Service PyXML: Hash table collisions CPU usage Denial of Service
nvd
CVE-2023-5156P4HIGHCVSS 7.5v8.0v9.02023-09-25
CVE-2023-5156 [HIGH] CVE-2023-5156: A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.
nvd
CVE-2013-1943P4HIGHCVSS 7.8v5.02013-07-16
CVE-2013-1943 [HIGH] CWE-20 CVE-2013-1943: The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specifi The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specified during allocation of memory slots for use in a guest's physical address space, which allows local users to gain privileges or obtain sensitive information from kernel memory via a crafted application, related to arch/x86/kvm/paging_tmpl.h and virt/kvm/k
nvd
Redhat Enterprise Linux vulnerabilities | cvebase