cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,853 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,853
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH638MEDIUM890LOW158

Vulnerabilities

Page 47 of 93
CVE-2021-3672P4MEDIUMCVSS 5.6v7.0v7.7+1 more2021-11-23
CVE-2021-3672 [MEDIUM] CWE-79 CVE-2021-3672: A flaw was found in c-ares library, where a missing input validation check of host names returned by A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
nvd
CVE-2026-4426P4MEDIUMCVSS 6.5v6.0v7.0+3 more2026-03-19
CVE-2026-4426 [MEDIUM] CWE-1335 CVE-2026-4426: A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompressi A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential applicat
nvd
CVE-2026-55653P4MEDIUMCVSS 6.5v6.0v7.0+3 more2026-06-23
CVE-2026-55653 [MEDIUM] CWE-415 CVE-2026-55653: A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the D A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to c
nvd
CVE-2004-0079P4HIGHCVSS 7.5v3.02004-11-23
CVE-2004-0079 [HIGH] CWE-476 CVE-2004-0079: The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
nvd
CVE-2021-3565P4MEDIUMCVSS 5.9v8.02021-06-04
CVE-2021-3565 [MEDIUM] CWE-665 CVE-2021-3565: A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed A A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being imported. The highest threat from this vulnerability is to data confidentiality.
nvd
CVE-2023-51764P4MEDIUMCVSS 5.3v8.0v9.02023-12-24
CVE-2023-51764 [MEDIUM] CWE-345 CVE-2023-51764: Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_un Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass
nvd
CVE-2024-3049P4MEDIUMCVSS 5.9v7.0v8.0+1 more2024-06-06
CVE-2024-3049 [MEDIUM] CWE-345 CVE-2024-3049: A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_m A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
nvd
CVE-2013-1913P4MEDIUMCVSS 6.8v5.0v6.02013-12-12
CVE-2013-1913 [MEDIUM] CWE-190 CVE-2013-1913: Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large color entries value in an X Window System (XWD) image dump.
nvd
CVE-2018-19215P4HIGHCVSS 7.8v5.0v6.0+1 more2018-11-12
CVE-2018-19215 [HIGH] CWE-125 CVE-2018-19215: Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/pre Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and ! characters.
nvd
CVE-2016-0504P4MEDIUMCVSS 6.8v6.0v7.02016-01-21
CVE-2016-0504 [MEDIUM] CVE-2016-0504: Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated u Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2016-0503.
nvd
CVE-2023-7216P4MEDIUMCVSS 5.3v7.0v8.0+1 more2024-02-05
CVE-2023-7216 [MEDIUM] CWE-59 CVE-2023-7216: A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauth A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in arbitrary directories through symlinks.
nvd
CVE-2016-2143P4HIGHCVSS 7.8v7.02016-04-27
CVE-2016-2143 [HIGH] CWE-20 CVE-2016-2143: The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted application, related to arch/s390/include/asm/mmu_context.h and arch/s390/include/asm/pgalloc.h.
nvd
CVE-2026-14940P4MEDIUMCVSS 5.3v7.0v8.0+2 more2026-07-07
CVE-2026-14940 [MEDIUM] CWE-122 CVE-2026-14940: A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Dist A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN), the server can write past the end of a heap allocation while sorting RDN attribute-value pairs. An unauthenticated remote attacker
nvd
CVE-2021-4204P4HIGHCVSS 7.1v9.02022-08-24
CVE-2021-4204 [HIGH] CWE-20 CVE-2021-4204: An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper In An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or leak internal information.
nvd
CVE-2020-12430P4MEDIUMCVSS 6.5v8.02020-04-28
CVE-2020-12430 [MEDIUM] CWE-401 CVE-2020-12430: An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving domain statistics when managing QEMU guests. This flaw allows unprivileged users with a read-only connection to cause a memory leak
nvd
CVE-2013-4288P4HIGHCVSS 7.2v6.02013-10-03
CVE-2013-4288 [HIGH] CWE-362 CVE-2013-4288: Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restriction Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.
nvd
CVE-2022-1353P4HIGHCVSS 7.1v8.02022-04-29
CVE-2022-1353 [HIGH] CWE-200 CVE-2022-1353: A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. Th A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information.
nvd
CVE-2019-14822P4HIGHCVSS 7.1v7.0v8.02019-11-25
CVE-2019-14822 [HIGH] CWE-862 CVE-2019-14822: A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engi
nvd
CVE-2023-2977P4HIGHCVSS 7.1v8.0v9.02023-06-01
CVE-2023-2977 [HIGH] CWE-119 CVE-2023-2977: A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs1 A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags, where remaining length is wrongly caculated due to moved starting pointer
nvd
CVE-2020-1751P4HIGHCVSS 7.0v8.02020-04-17
CVE-2020-1751 [HIGH] CWE-787 CVE-2020-1751: An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability.
nvd
Redhat Enterprise Linux vulnerabilities | cvebase