cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,853 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,853
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH638MEDIUM890LOW158

Vulnerabilities

Page 52 of 93
CVE-2004-0827P4HIGHCVSS 7.5v2.1v3.02004-09-16
CVE-2004-0827 [HIGH] CVE-2004-0827: Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6 Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files.
nvd
CVE-2019-2762P4MEDIUMCVSS 5.3v8.02019-07-23
CVE-2019-2762 [MEDIUM] CVE-2019-2762: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities) Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Su
nvd
CVE-2019-2769P4MEDIUMCVSS 5.3v8.02019-07-23
CVE-2019-2769 [MEDIUM] CVE-2019-2769: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities) Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Su
nvd
CVE-2023-1667P4MEDIUMCVSS 6.5v8.0v9.02023-05-26
CVE-2023-1667 [MEDIUM] CWE-476 CVE-2023-1667: A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.
nvd
CVE-2015-0410P4MEDIUMCVSS 5.0v5.0v6.0+1 more2015-01-21
CVE-2015-0410 [MEDIUM] CVE-2015-0410: Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security.
nvd
CVE-2023-40660P4MEDIUMCVSS 6.6v8.0v9.02023-11-06
CVE-2023-40660 [MEDIUM] CWE-287 CVE-2023-40660: A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenti A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographic operations in other processes when an empty zero-length pin is passed. This issue poses a security risk, particularly for OS logon/screen unlock and for small, permanently connected tokens to computer
nvd
CVE-2020-27777P4MEDIUMCVSS 6.7v5.0v6.0+2 more2020-12-15
CVE-2020-27777 [MEDIUM] CWE-862 CVE-2020-27777: A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors (pseries platform) a root like local user could use this flaw to further increase their privileges to that of a running kernel.
nvd
CVE-2016-0739P4MEDIUMCVSS 5.9v7.02016-04-13
CVE-2016-0739 [MEDIUM] CWE-200 CVE-2016-0739: libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-grou libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
nvd
CVE-2023-40661P4MEDIUMCVSS 6.4v8.0v9.02023-11-06
CVE-2023-40661 [MEDIUM] CWE-119 CVE-2023-40661: Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user or administrator enrolls cards. To take advantage of these flaws, an attacker must have physical access to the computer system and employ a custom-crafted USB device or smart card to manipulate responses
nvd
CVE-2020-14331P4MEDIUMCVSS 6.6v7.0v8.02020-09-15
CVE-2020-14331 [MEDIUM] CWE-787 CVE-2020-14331: A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console, calling an ioctl VT_RESIZE, which causes an out-of-bounds write to occur. This flaw allows a local user with access to the VGA console to crash the system, potentially escalating their privileges on the
nvd
CVE-2019-19319P4MEDIUMCVSS 6.5v7.0v8.02019-11-27
CVE-2019-19319 [MEDIUM] CWE-416 CVE-2019-19319: In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cau In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large old_size value is used in a memset call, aka CID-345c0dbf3a30.
nvd
CVE-2023-1073P4MEDIUMCVSS 6.6v7.0v8.0+1 more2023-03-27
CVE-2023-1073 [MEDIUM] CWE-119 CVE-2023-1073: A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in h A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in how a user inserts a malicious USB device. This flaw allows a local user to crash or potentially escalate their privileges on the system.
nvd
CVE-2024-0564P4MEDIUMCVSS 6.5v8.0v9.02024-01-30
CVE-2024-0564 [MEDIUM] CWE-203 CVE-2024-0564: A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kerne A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the same host and the default setting of KSM is "max page sharing=256", it is possible for the attacker to time the u
nvd
CVE-2004-1145P4MEDIUMCVSS 5.0v2.1v3.02004-12-15
CVE-2004-1145 [MEDIUM] CVE-2004-1145: Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java c Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.
nvd
CVE-2008-4313P4MEDIUMCVSS 6.0v5.02008-11-27
CVE-2008-4313 [MEDIUM] CWE-264 CVE-2008-4313: A certain Red Hat patch for tog-pegasus in OpenGroup Pegasus 2.7.0 does not properly configure the P A certain Red Hat patch for tog-pegasus in OpenGroup Pegasus 2.7.0 does not properly configure the PAM tty name, which allows remote authenticated users to bypass intended access restrictions and send requests to OpenPegasus WBEM services.
nvd
CVE-2021-3573P4MEDIUMCVSS 6.4v6.0v7.0+1 more2021-08-13
CVE-2021-3573 [MEDIUM] CWE-362 CVE-2021-3573: A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in t A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in the way user calls ioct HCIUNBLOCKADDR or other way triggers race condition of the call hci_unregister_dev() together with one of the calls hci_sock_blacklist_add(), hci_sock_blacklist_del(), hci_get_conn_info(), hci_get_auth_info(). A privileged local u
nvd
CVE-2020-1730P4MEDIUMCVSS 5.3v8.02020-04-13
CVE-2020-1730 [MEDIUM] CWE-476 CVE-2020-1730: A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability
nvd
CVE-2021-20261P4MEDIUMCVSS 6.4v7.02021-03-11
CVE-2021-20261 [MEDIUM] CWE-362 CVE-2021-20261: A race condition was found in the Linux kernels implementation of the floppy disk drive controller d A race condition was found in the Linux kernels implementation of the floppy disk drive controller driver software. The impact of this issue is lessened by the fact that the default permissions on the floppy device (/dev/fd0) are restricted to root. If the permissions on the device have changed the impact changes greatly. In the default configuratio
nvd
CVE-2019-3902P4MEDIUMCVSS 5.9v7.02019-04-22
CVE-2019-3902 [MEDIUM] CWE-22 CVE-2019-3902: A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to def A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.
nvd
CVE-2014-8119P4HIGHCVSS 7.5v6.0v7.02017-12-29
CVE-2014-8119 [HIGH] CWE-20 CVE-2014-8119: The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of servic The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.
nvd
Redhat Enterprise Linux vulnerabilities | cvebase