cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,853 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,853
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH638MEDIUM890LOW158

Vulnerabilities

Page 56 of 93
CVE-2011-2517P4HIGHCVSS 7.2v5.02012-05-24
CVE-2011-2517 [HIGH] CWE-119 CVE-2011-2517: Multiple buffer overflows in net/wireless/nl80211.c in the Linux kernel before 2.6.39.2 allow local Multiple buffer overflows in net/wireless/nl80211.c in the Linux kernel before 2.6.39.2 allow local users to gain privileges by leveraging the CAP_NET_ADMIN capability during scan operations with a long SSID value.
nvd
CVE-2019-18390P4HIGHCVSS 7.1v8.02019-12-23
CVE-2019-18390 [HIGH] CWE-125 CVE-2019-18390: An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer t An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands.
nvd
CVE-2026-3442P4HIGHCVSS 7.1v6.0v7.0+3 more2026-03-16
CVE-2026-3442 [HIGH] CWE-125 CVE-2026-3442: A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the
nvd
CVE-2014-0143P4HIGHCVSS 7.0v6.02017-08-10
CVE-2014-0143 [HIGH] CWE-190 CVE-2014-0143: Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of service (crash) via a crafted catalog size in (1) the parallels_open function in block/parallels.c or (2) bochs_open function in bochs.c, a large L1 table in the (3) qcow2_snapshot_load_tmp in qcow2-snapshot.c or (4) qcow2_grow_l1_table
nvd
CVE-2011-1011P4MEDIUMCVSS 6.9v3v4+2 more2011-02-24
CVE-2011-1011 [MEDIUM] CWE-264 CVE-2011-1011: The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of poli The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of policycoreutils 2.0.83 and earlier in Red Hat Enterprise Linux (RHEL) 6 and earlier, and Fedora 14 and earlier, mounts a new directory on top of /tmp without assigning root ownership and the sticky bit to this new directory, which allows local users to repl
nvd
CVE-2018-10840P4MEDIUMCVSS 6.6v7.02018-07-16
CVE-2018-10840 [MEDIUM] CWE-122 CVE-2018-10840: Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_ent Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by operating on a mounted crafted ext4 image.
nvd
CVE-2023-32573P4MEDIUMCVSS 6.5v8.0v9.02023-05-10
CVE-2023-32573 [MEDIUM] CWE-369 CVE-2023-32573: In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled.
nvd
CVE-2025-5918P4MEDIUMCVSS 6.6v6.0v7.0+2 more2025-06-09
CVE-2025-5918 [MEDIUM] CWE-125 CVE-2025-5918: A vulnerability has been identified in the libarchive library. This flaw can be triggered when file A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
nvd
CVE-2021-3611P4MEDIUMCVSS 6.5v8.02022-05-11
CVE-2021-3611 [MEDIUM] CWE-119 CVE-2021-3611: A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicio A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability. This flaw affects QEMU versions prior to 7.0.0.
nvd
CVE-2018-10880P4MEDIUMCVSS 5.5v7.02018-07-25
CVE-2018-10880 [MEDIUM] CWE-787 CVE-2018-10880: Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a crafted ext4 image in ext4_update_inline_data(). An attacker could use this to cause a system crash and a denial of service.
nvd
CVE-2020-10690P4MEDIUMCVSS 6.4v7.0v8.02020-05-08
CVE-2020-10690 [MEDIUM] CWE-416 CVE-2020-10690: There is a use-after-free in kernel versions before 5.5 due to a race condition between the release There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /dev/ptpX) and voluntarily goes to sleep. During this time if the underlying device is removed, it can cause an exploitable condition
nvd
CVE-2018-10850P4MEDIUMCVSS 5.9v7.02018-06-13
CVE-2018-10850 [MEDIUM] CWE-362 CVE-2018-10850: 389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-ba 389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load. An anonymous attacker could use this flaw to trigger a denial of service.
nvd
CVE-2022-35651P4MEDIUMCVSS 6.1v8.02022-07-25
CVE-2022-35651 [MEDIUM] CWE-79 CVE-2022-35651: A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitizati A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive
nvd
CVE-2017-15102P4MEDIUMCVSS 6.3v5.0v6.02017-11-15
CVE-2017-15102 [MEDIUM] CWE-476 CVE-2017-15102: The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occurs after a race condition and a NULL pointer dereference.
nvd
CVE-2021-42781P4MEDIUMCVSS 5.3v7.02022-04-18
CVE-2021-42781 [MEDIUM] CWE-119 CVE-2021-42781: Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that cou Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.
nvd
CVE-2019-19332P4MEDIUMCVSS 6.1v7.0v8.02020-01-09
CVE-2019-19332 [MEDIUM] CWE-787 CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by the KVM hypervisor. A user or process able to access the '/dev/kvm' device could use this flaw to crash the system, resulting
nvd
CVE-2019-2436P4MEDIUMCVSS 5.5v8.02019-01-16
CVE-2019-2436 [MEDIUM] CVE-2019-2436: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized a
nvd
CVE-2005-0086P4HIGHCVSS 7.5v3.02005-05-02
CVE-2005-0086 [HIGH] CVE-2005-0086: Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file, as demonstrated using the UTF-8 locale.
nvd
CVE-2019-2819P4MEDIUMCVSS 5.5v8.02019-07-23
CVE-2019-2819 [MEDIUM] CVE-2019-2819: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Audit). Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Audit). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this
nvd
CVE-2021-3504P4MEDIUMCVSS 5.4v6.0v7.0+1 more2021-05-11
CVE-2021-3504 [MEDIUM] CWE-125 CVE-2021-3504: A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bound A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is
nvd
Redhat Enterprise Linux vulnerabilities | cvebase