cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,864 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159

Vulnerabilities

Page 65 of 94
CVE-2019-2510P4MEDIUMCVSS 4.9v8.02019-01-16
CVE-2019-2510 [MEDIUM] CVE-2019-2510: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2016-0650P4MEDIUMCVSS 5.5v6.0v7.02016-04-21
CVE-2016-0650 [MEDIUM] CVE-2016-0650: Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and ear Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to Replication.
nvd
CVE-2016-0649P4MEDIUMCVSS 5.5v6.0v7.02016-04-21
CVE-2016-0649 [MEDIUM] CVE-2016-0649: Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and ear Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to PS.
nvd
CVE-2016-0644P4MEDIUMCVSS 5.5v6.0v7.02016-04-21
CVE-2016-0644 [MEDIUM] CVE-2016-0644: Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and ear Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to DDL.
nvd
CVE-2016-0646P4MEDIUMCVSS 5.5v6.0v7.02016-04-21
CVE-2016-0646 [MEDIUM] CVE-2016-0646: Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and ear Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to DML.
nvd
CVE-2016-8612P4MEDIUMCVSS 4.3v6.0v7.02018-03-09
CVE-2016-8612 [MEDIUM] CWE-20 CVE-2016-8612: Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Valida Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Validation in the protocol parsing logic in the load balancer resulting in a Segmentation Fault in the serving httpd process.
nvd
CVE-2017-7848P4MEDIUMCVSS 5.3v6.0v7.02018-06-11
CVE-2017-7848 [MEDIUM] CWE-74 CVE-2017-7848: RSS fields can inject new lines into the created email structure, modifying the message body. This v RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.
nvd
CVE-2021-3409P4MEDIUMCVSS 5.7v7.02021-03-23
CVE-2021-3409 [MEDIUM] CVE-2021-3409: The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or potential code execution. QEMU up to
nvd
CVE-2003-0699P4HIGHCVSS 7.5v2.12003-08-27
CVE-2003-0699 [HIGH] CVE-2003-0699: The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access use The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0700.
nvd
CVE-2020-27825P4MEDIUMCVSS 5.7v7.0v8.02020-12-11
CVE-2020-27825 [MEDIUM] CWE-362 CVE-2020-27825: A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). The A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of service problem (DOS). This flaw could even allow a local attacker with special user privilege to a kernel information leak threat.
nvd
CVE-2019-7222P4MEDIUMCVSS 5.5v8.02019-03-21
CVE-2019-7222 [MEDIUM] CVE-2019-7222: The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak. The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.
nvd
CVE-2019-11833P4MEDIUMCVSS 5.5v8.02019-05-15
CVE-2019-11833 [MEDIUM] CWE-908 CVE-2019-11833: fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in th fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.
nvd
CVE-2023-43785P4MEDIUMCVSS 5.5v8.0v9.02023-10-10
CVE-2023-43785 [MEDIUM] CWE-787 CVE-2023-43785: A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() functio A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local user to trigger an out-of-bounds read error and read the contents of memory on the system.
nvd
CVE-2019-3887P4MEDIUMCVSS 5.6v8.02019-04-09
CVE-2019-3887 [MEDIUM] CWE-863 CVE-2019-3887: A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access wi A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via L2 guest, when 'virtualize x2APIC mode' is enabled. A guest could use this flaw to potentially crash the host kernel resulting in DoS issue. Kernel versio
nvd
CVE-2020-12458P4MEDIUMCVSS 5.5v8.02020-04-29
CVE-2020-12458 [MEDIUM] CWE-732 CVE-2020-12458: An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/g An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).
nvd
CVE-2022-1198P4MEDIUMCVSS 5.5v9.02022-08-29
CVE-2022-1198 [MEDIUM] CWE-416 CVE-2022-1198: A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows an attacker to crash linux kernel by simulating ax25 device using 6pack driver from user space.
nvd
CVE-2023-4155P4MEDIUMCVSS 5.6v8.0v9.02023-09-13
CVE-2023-4155 [MEDIUM] CWE-367 CVE-2023-4155: A flaw was found in KVM AMD Secure Encrypted Virtualization (SEV) in the Linux kernel. A KVM guest u A flaw was found in KVM AMD Secure Encrypted Virtualization (SEV) in the Linux kernel. A KVM guest using SEV-ES or SEV-SNP with multiple vCPUs can trigger a double fetch race condition vulnerability and invoke the `VMGEXIT` handler recursively. If an attacker manages to call the handler multiple times, they can trigger a stack overflow and cause a den
nvd
CVE-2012-5644P4MEDIUMCVSS 5.5v5.0v6.02019-11-25
CVE-2012-5644 [MEDIUM] CWE-200 CVE-2012-5644: libuser has information disclosure when moving user's home directory libuser has information disclosure when moving user's home directory
nvd
CVE-2015-7837P4MEDIUMCVSS 5.5v7.0v7.2+1 more2017-09-19
CVE-2015-7837 [MEDIUM] CWE-254 CVE-2015-7837: The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when bo The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot.
nvd
CVE-2021-3620P4MEDIUMCVSS 5.5v8.02022-03-03
CVE-2021-3620 [MEDIUM] CWE-209 CVE-2021-3620: A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
nvd
Redhat Enterprise Linux vulnerabilities | cvebase