cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,853 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,853
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH638MEDIUM890LOW158

Vulnerabilities

Page 58 of 93
CVE-2004-0809P4MEDIUMCVSS 5.0v3.02004-09-16
CVE-2004-0809 [MEDIUM] CVE-2004-0809: The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
nvd
CVE-2021-20201P4MEDIUMCVSS 5.3v6.0v7.0+1 more2021-05-28
CVE-2021-20201 [MEDIUM] CWE-400 CVE-2021-20201: A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote att A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection.
nvd
CVE-2005-0206P4HIGHCVSS 7.5v2.1v3.02005-04-27
CVE-2005-0206 [HIGH] CVE-2005-0206: The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
nvd
CVE-2020-2655P4MEDIUMCVSS 4.8v6.0v7.0+1 more2020-01-15
CVE-2020-2655 [MEDIUM] CVE-2020-2655: Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that ar Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.5 and 13.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete acces
nvd
CVE-2021-3623P4MEDIUMCVSS 6.1v8.02022-03-02
CVE-2021-3623 [MEDIUM] CWE-787 CVE-2021-3623: A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets co A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of-bounds access when the volatile state of the TPM 2 is marshalled/written or unmarshalled/read. The highest threat from this vulnerability is to system availability.
nvd
CVE-2021-3622P4MEDIUMCVSS 4.3v6.0v7.0+1 more2021-12-23
CVE-2021-3622 [MEDIUM] CWE-400 CVE-2021-3622: A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Win A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability.
nvd
CVE-2026-4647P4MEDIUMCVSS 6.1v6.0v7.0+3 more2026-03-23
CVE-2026-4647 [MEDIUM] CWE-125 CVE-2026-4647: A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds.
nvd
CVE-2023-39192P4MEDIUMCVSS 6.0v8.02023-10-09
CVE-2023-39192 [MEDIUM] CWE-125 CVE-2023-39192: A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32 module did not validate A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32 module did not validate the fields in the xt_u32 structure. This flaw allows a local privileged attacker to trigger an out-of-bounds read by setting the size fields with a value beyond the array boundaries, leading to a crash or information disclosure.
nvd
CVE-2021-42780P4MEDIUMCVSS 5.3v7.02022-04-18
CVE-2021-42780 [MEDIUM] CWE-252 CVE-2021-42780: A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.
nvd
CVE-2021-42778P4MEDIUMCVSS 5.3v7.0v8.02022-04-18
CVE-2021-42778 [MEDIUM] CWE-672 CVE-2021-42778: A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo. A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.
nvd
CVE-2026-55655P4MEDIUMCVSS 6.1v6.0v7.0+3 more2026-06-23
CVE-2026-55655 [MEDIUM] CWE-923 CVE-2026-55655: A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client- A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traf
nvd
CVE-2020-10742P4MEDIUMCVSS 6.0v6.02021-06-02
CVE-2020-10742 [MEDIUM] CWE-787 CVE-2020-10742: A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the index after one memory allocation by kmalloc will cause a kernel panic. The highest threat from this vulnerability is to data confidentiality and system availability.
nvd
CVE-2019-2623P4MEDIUMCVSS 5.3v8.02019-04-23
CVE-2019-2623 [MEDIUM] CVE-2019-2623: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abil
nvd
CVE-2020-2593P4MEDIUMCVSS 4.8v8.02020-01-15
CVE-2020-2593 [MEDIUM] CVE-2020-2593: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Su Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Succ
nvd
CVE-2003-0689P4HIGHCVSS 7.5v2.12003-10-20
CVE-2003-0689 [HIGH] CVE-2003-0689: The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial o The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.
nvd
CVE-2023-5546P4MEDIUMCVSS 5.4v7.02023-11-09
CVE-2023-5546 [MEDIUM] CWE-79 CVE-2023-5546: ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored X ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.
nvd
CVE-2018-16838P4MEDIUMCVSS 5.4v7.02019-03-25
CVE-2018-16838 [MEDIUM] CWE-284 CVE-2018-16838: A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD d A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the server side, SSSD will allow all authenticated users to login instead of denying access.
nvd
CVE-2022-30597P4MEDIUMCVSS 5.3v8.02022-05-18
CVE-2022-30597 [MEDIUM] CWE-472 CVE-2022-30597: A flaw was found in moodle where the description user field was not hidden when being set as a hidde A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
nvd
CVE-2018-10892P4MEDIUMCVSS 5.3v7.02018-07-06
CVE-2018-10892 [MEDIUM] CWE-250 CVE-2018-10892: The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not b The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.
nvd
CVE-2004-0494P4HIGHCVSS 7.5v2.1v3.02004-11-23
CVE-2004-0494 [HIGH] CVE-2004-0494: Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote att Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI.
nvd
Redhat Enterprise Linux vulnerabilities | cvebase