Redhat Enterprise Linux vulnerabilities
1,864 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159
Vulnerabilities
Page 63 of 94
CVE-2020-27824P4MEDIUMCVSS 5.5v8.02021-05-13
CVE-2020-27824 [MEDIUM] CWE-20 CVE-2020-27824: A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw
A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability.
nvd
CVE-2021-0129P4MEDIUMCVSS 5.7v7.0v8.02021-06-09
CVE-2021-0129 [MEDIUM] CVE-2021-0129: Improper access control in BlueZ may allow an authenticated user to potentially enable information d
Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjacent access.
nvd
CVE-2023-1206P4MEDIUMCVSS 5.7v8.0v9.02023-06-30
CVE-2023-1206 [MEDIUM] CWE-400 CVE-2023-1206: A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 funct
A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of the server that accepts IPV6 connections up to 95%.
nvd
CVE-2014-3562P4MEDIUMCVSS 5.0v6.0v7.02014-08-21
CVE-2014-3562 [MEDIUM] CWE-200 CVE-2014-3562: Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attack
Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory.
nvd
CVE-2018-3665P4MEDIUMCVSS 5.6v6.0v7.02018-06-21
CVE-2018-3665 [MEDIUM] CWE-200 CVE-2018-3665: System software utilizing Lazy FP state restore technique on systems using Intel Core-based micropro
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
nvd
CVE-2011-2207P4MEDIUMCVSS 5.3v6.02019-11-27
CVE-2011-2207 [MEDIUM] CWE-295 CVE-2011-2207: dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate.
nvd
CVE-2021-3421P4MEDIUMCVSS 5.5v8.02021-05-19
CVE-2021-3421 [MEDIUM] CWE-347 CVE-2021-3421: A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can
A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to data integrity. This flaw affects RPM versions before 4.17.0-alpha.
nvd
CVE-2016-7056P4MEDIUMCVSS 5.5v6.0v7.02018-09-10
CVE-2016-7056 [MEDIUM] CWE-385 CVE-2016-7056: A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with l
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
nvd
CVE-2020-1722P4MEDIUMCVSS 5.3v6.0v7.0+1 more2020-04-27
CVE-2020-1722 [MEDIUM] CWE-400 CVE-2020-1722: A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,00
A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.
nvd
CVE-2018-16862P4MEDIUMCVSS 5.5v7.02018-11-26
CVE-2018-16862 [MEDIUM] CWE-200 CVE-2018-16862: A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode
A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The new file created with the same inode may contain leftover pages from cleancache and the old file data instead of the new one.
nvd
CVE-2014-1859P4MEDIUMCVSS 5.5v6.0v7.02018-01-08
CVE-2014-1859 [MEDIUM] CWE-59 CVE-2014-1859: (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/te
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
nvd
CVE-2025-5916P4MEDIUMCVSS 5.6v6.0v7.0+3 more2025-06-09
CVE-2025-5916 [MEDIUM] CWE-190 CVE-2025-5916: A vulnerability has been identified in the libarchive library. This flaw involves an integer overflo
A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior,
nvd
CVE-2021-3505P4MEDIUMCVSS 5.5v8.02021-04-19
CVE-2021-3505 [MEDIUM] CWE-331 CVE-2021-3505: A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys
A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number check. The highest threat from this vulnerability is to data confidentiality.
nvd
CVE-2023-40550P4MEDIUMCVSS 5.5v8.0v9.02024-01-29
CVE-2023-40550 [MEDIUM] CWE-125 CVE-2023-40550: An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This is
An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's boot phase.
nvd
CVE-2014-5118P4MEDIUMCVSS 5.5v6.0v7.02019-11-18
CVE-2014-5118 [MEDIUM] CWE-20 CVE-2014-5118: Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
nvd
CVE-2023-6681P4MEDIUMCVSS 5.3v8.0v9.02024-02-12
CVE-2023-6681 [MEDIUM] CWE-400 CVE-2023-6681: A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (Do
A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result in a large amount of computational consumption, causing a denial of service attack.
nvd
CVE-2023-43788P4MEDIUMCVSS 5.5v8.0v9.02023-10-10
CVE-2023-43788 [MEDIUM] CWE-125 CVE-2023-43788: A vulnerability was found in libXpm due to a boundary condition within the XpmCreateXpmImageFromBuff
A vulnerability was found in libXpm due to a boundary condition within the XpmCreateXpmImageFromBuffer() function. This flaw allows a local attacker to trigger an out-of-bounds read error and read the contents of memory on the system.
nvd
CVE-2019-18391P4MEDIUMCVSS 5.5v8.02019-12-23
CVE-2019-18391 [MEDIUM] CWE-787 CVE-2019-18391: A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c i
A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.
nvd
CVE-2014-8181P4MEDIUMCVSS 5.5v7.02019-11-06
CVE-2014-8181 [MEDIUM] CWE-665 CVE-2014-8181: The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, whi
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.
nvd
CVE-2023-43789P4MEDIUMCVSS 5.5v8.0v9.02023-10-12
CVE-2023-43789 [MEDIUM] CWE-125 CVE-2023-43789: A vulnerability was found in libXpm where a vulnerability exists due to a boundary condition, a loca
A vulnerability was found in libXpm where a vulnerability exists due to a boundary condition, a local user can trigger an out-of-bounds read error and read contents of memory on the system.
nvd