cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,864 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159

Vulnerabilities

Page 61 of 94
CVE-2023-5547P4MEDIUMCVSS 6.1v7.02023-11-09
CVE-2023-5547 [MEDIUM] CWE-79 CVE-2023-5547: The course upload preview contained an XSS risk for users uploading unsafe data. The course upload preview contained an XSS risk for users uploading unsafe data.
nvd
CVE-2018-5117P4MEDIUMCVSS 5.3v6.0v7.02018-06-11
CVE-2018-5117 [MEDIUM] CVE-2018-5117: If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded. This vulnerability affects Thunderbird <
nvd
CVE-2020-14310P4MEDIUMCVSS 6.0v7.0v8.02020-07-31
CVE-2020-14310 [MEDIUM] CWE-122 CVE-2020-14310: There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a fo There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX,
nvd
CVE-2019-2975P4MEDIUMCVSS 4.8v8.02019-10-16
CVE-2019-2975 [MEDIUM] CVE-2019-2975: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Sup Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attac
nvd
CVE-2012-3404P4MEDIUMCVSS 5.0v6.02014-02-10
CVE-2012-3404 [MEDIUM] CWE-189 CVE-2012-3404: The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (stack corruption and crash) via a format string that uses posi
nvd
CVE-2019-10153P4MEDIUMCVSS 5.0v8.02019-07-30
CVE-2019-10153 [MEDIUM] CWE-172 CVE-2019-10153: A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception. In cluster environments, this could lead to preventing automated recovery or otherwise denying service to clusters of which that VM is a member.
nvd
CVE-2012-3405P4MEDIUMCVSS 5.0v6.02014-02-10
CVE-2012-3405 [MEDIUM] CVE-2012-3405: The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (segmentation fault and crash) via a format string with a large number
nvd
CVE-2019-2999P4MEDIUMCVSS 4.7v8.02019-10-16
CVE-2019-2999 [MEDIUM] CVE-2019-2999: Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than th
nvd
CVE-2014-3690P4MEDIUMCVSS 5.5v5.02014-11-10
CVE-2014-3690 [MEDIUM] CWE-400 CVE-2014-3690: arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does n arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial of service (system disruption) by leveraging /dev/kvm access, as demonstrated by PR_SET_TSC
nvd
CVE-2019-19338P4MEDIUMCVSS 5.5v6.02020-07-13
CVE-2019-19338 [MEDIUM] CVE-2019-19338: A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 whe A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CPUs handle speculative execution of instructions when a TSX Asynchronous Abort (TAA) error occurs. When a guest is running on a host CPU affected by the TAA flaw (TAA_NO=0), but is not affected by the MDS issue (MDS_NO=1), the guest was to
nvd
CVE-2004-0883P4MEDIUMCVSS 6.4v2.1v3.02005-01-10
CVE-2004-0883 [MEDIUM] CVE-2004-0883: Multiple vulnerabilities in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 allow remote sa Multiple vulnerabilities in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 allow remote samba servers to cause a denial of service (crash) or gain sensitive information from kernel memory via a samba server (1) returning more data than requested to the smb_proc_read function, (2) returning a data offset from outside the samba packet to the smb_proc_
nvd
CVE-2021-3602P4MEDIUMCVSS 5.5v8.02022-03-03
CVE-2021-3602 [MEDIUM] CWE-200 CVE-2021-3602: An information disclosure flaw was found in Buildah, when building containers using chroot isolation An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may include sensitive information that w
nvd
CVE-2024-0408P4MEDIUMCVSS 5.5v6.0v7.0+2 more2024-01-18
CVE-2024-0408 [MEDIUM] CWE-158 CVE-2024-0408: A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another resource that needs to access that buffer, such as a GC, the XSELINUX code will try to use an object tha
nvd
CVE-2023-5544P4MEDIUMCVSS 5.4v7.02023-11-09
CVE-2023-5544 [MEDIUM] CWE-79 CVE-2023-5544: Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk an Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.
nvd
CVE-2021-20320P4MEDIUMCVSS 5.5v7.0v8.02022-02-18
CVE-2021-20320 [MEDIUM] CWE-200 CVE-2021-20320: A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kerne A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem.
nvd
CVE-2024-49394P4MEDIUMCVSS 5.3v8.0v9.02024-11-12
CVE-2024-49394 [MEDIUM] CWE-347 CVE-2024-49394: In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing whi In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender.
nvd
CVE-2004-1071P4HIGHCVSS 7.2v2.1v3.02005-01-10
CVE-2004-1071 [HIGH] CVE-2004-1071: The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly handle a failed call to the mmap function, which causes an incorrect mapped image and may allow local users to execute arbitrary code.
nvd
CVE-2025-4598P4MEDIUMCVSS 4.7v7.0v8.0+2 more2025-05-30
CVE-2025-4598 [MEDIUM] CWE-364 CVE-2025-4598: A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process. A SUID binary or process has a special type o
nvd
CVE-2026-12549P4MEDIUMCVSS 4.8v6.0v7.0+3 more2026-06-22
CVE-2026-12549 [MEDIUM] CWE-805 CVE-2026-12549: The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflo The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.
nvd
CVE-2018-18897P4MEDIUMCVSS 6.5v8.02018-11-02
CVE-2018-18897 [MEDIUM] CWE-772 CVE-2018-18897: An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfil An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo.
nvd
Redhat Enterprise Linux vulnerabilities | cvebase