cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,853 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,853
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH638MEDIUM890LOW158

Vulnerabilities

Page 45 of 93
CVE-2018-14879P4HIGHCVSS 7.0v7.0v8.02019-10-03
CVE-2018-14879 [HIGH] CWE-120 CVE-2018-14879: The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().
nvd
CVE-2021-20197P4MEDIUMCVSS 6.3v8.02021-03-26
CVE-2021-20197 [MEDIUM] CWE-59 CVE-2021-20197: There is an open race window when writing output in the following utilities in GNU binutils version There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary
nvd
CVE-2005-0337P4HIGHCVSS 7.5v4.02005-05-02
CVE-2005-0337 [HIGH] CVE-2005-0337: Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is enabled in smtpd_rec Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is enabled in smtpd_recipient_restrictions, allows remote attackers to bypass e-mail restrictions and perform mail relaying by sending mail to an IPv6 hostname.
nvd
CVE-2010-0302P4HIGHCVSS 7.5v5.02010-03-05
CVE-2010-0302 [HIGH] CVE-2010-0302: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, re
nvd
CVE-2023-3347P4MEDIUMCVSS 5.9v8.0v9.02023-07-20
CVE-2023-3347 [MEDIUM] CWE-347 CVE-2023-3347: A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not e A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a man-in-the-middle attack, by intercepting the net
nvd
CVE-2015-0831P4MEDIUMCVSS 6.8v5v6.02015-02-25
CVE-2015-0831 [MEDIUM] CVE-2015-0831: Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index
nvd
CVE-2026-12725P4MEDIUMCVSS 5.9v8.0v9.0+1 more2026-06-22
CVE-2026-12725 [MEDIUM] CWE-122 CVE-2026-12725: A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resul
nvd
CVE-2013-1824P4MEDIUMCVSS 4.3v5v6.02013-09-16
CVE-2013-1824 [MEDIUM] CWE-611 CVE-2013-1824: The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitra The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.
nvd
CVE-2015-5229P4HIGHCVSS 7.5v6.7v7.22016-04-08
CVE-2015-5229 [HIGH] CWE-17 CVE-2015-5229: The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not pro The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors.
nvd
CVE-2018-19214P4HIGHCVSS 7.8v5.0v6.0+1 more2018-11-12
CVE-2018-19214 [HIGH] CWE-125 CVE-2018-19214: Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/pre Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.
nvd
CVE-2020-35518P4MEDIUMCVSS 5.3v7.0v8.02021-03-26
CVE-2020-35518 [MEDIUM] CWE-200 CVE-2020-35518: When binding against a DN during authentication, the reply from 389-ds-base will be different whethe When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
nvd
CVE-2022-2963P4HIGHCVSS 7.5v8.0v9.02022-10-14
CVE-2022-2963 [HIGH] CWE-401 CVE-2022-2963: A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.
nvd
CVE-2026-12528P4MEDIUMCVSS 5.4v7.0v8.0+2 more2026-06-17
CVE-2026-12528 [MEDIUM] CWE-787 CVE-2026-12528: A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace stripping, leading to a 1-byte out-of-b
nvd
CVE-2026-1467P4MEDIUMCVSS 5.3v6.0v7.0+3 more2026-01-27
CVE-2026-1467 [MEDIUM] CWE-93 CVE-2026-1467: A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Ret A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP proxy is configured and the library improperly handles URL-decoded input used to create the Host header. A remote attacker can exploit this by providing a specially crafted URL containing CRLF sequences, allo
nvd
CVE-2026-1536P4MEDIUMCVSS 5.3v6.0v7.0+3 more2026-01-28
CVE-2026-1536 [MEDIUM] CWE-93 CVE-2026-1536: A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition heade A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) sequences into the header value. These sequences are then interpreted verbatim when the HTTP request or response is constructed, allowing arbitrary HTTP headers to be injected. This vulnerability can lead to
nvd
CVE-2015-2783P4MEDIUMCVSS 5.8v6.0v7.02015-06-09
CVE-2015-2783 [MEDIUM] CWE-119 CVE-2015-2783: ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote atta ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read and application crash) via a crafted length value in conjunction with crafted serialized data in a phar archive, related to the phar_parse_metadata
nvd
CVE-2020-0570P4HIGHCVSS 7.3v7.0v8.02020-09-14
CVE-2020-0570 [HIGH] CWE-426 CVE-2020-0570: Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticat Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.
nvd
CVE-2021-3864P4HIGHCVSS 7.0v6.0v7.0+1 more2022-08-26
CVE-2021-3864 [HIGH] CWE-284 CVE-2021-3864: A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries execute A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a result, if the descendant process crashes and core_pattern i
nvd
CVE-2021-44733P4HIGHCVSS 7.0v8.02021-12-22
CVE-2021-44733 [HIGH] CWE-362 CVE-2021-44733: A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5. A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.
nvd
CVE-2018-1129P4MEDIUMCVSS 6.5v7.02018-07-10
CVE-2018-1129 [MEDIUM] CWE-284 CVE-2018-1129: A flaw was found in the way signature calculation was handled by cephx authentication protocol. An a A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
nvd
Redhat Enterprise Linux vulnerabilities | cvebase