Redhat Enterprise Linux vulnerabilities
1,864 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159
Vulnerabilities
Page 68 of 94
CVE-2019-2780P4MEDIUMCVSS 4.9v8.02019-07-23
CVE-2019-2780 [MEDIUM] CVE-2019-2780: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Components / Serv
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Components / Services). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unau
nvd
CVE-2017-2625P4MEDIUMCVSS 5.5v7.02018-07-27
CVE-2017-2625 [MEDIUM] CWE-331 CVE-2017-2625: It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. O
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.
nvd
CVE-2018-10883P4MEDIUMCVSS 5.5v7.02018-07-30
CVE-2018-10883 [MEDIUM] CWE-787 CVE-2018-10883: A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds writ
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_dirty_metadata(), a denial of service, and a system crash by mounting and operating on a crafted ext4 filesystem image.
nvd
CVE-2017-2623P4MEDIUMCVSS 5.3v7.02018-07-27
CVE-2017-2623 [MEDIUM] CWE-295 CVE-2017-2623: It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG sig
It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic Host, where certificate pinning is used by default.
nvd
CVE-2018-10872P4MEDIUMCVSS 5.5v6.02018-07-10
CVE-2018-10872 [MEDIUM] CWE-250 CVE-2018-10872: A flaw was found in the way the Linux kernel handled exceptions delivered after a stack switch opera
A flaw was found in the way the Linux kernel handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, processor does not deliver interrupts and exceptions, they are delivered once the first instruction after the stack switch is executed. An unprivileged system user could use th
nvd
CVE-2022-2153P4MEDIUMCVSS 5.5v6.0v7.0+2 more2022-08-31
CVE-2022-2153 [MEDIUM] CWE-476 CVE-2022-2153: A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it p
A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of servi
nvd
CVE-2020-10763P4MEDIUMCVSS 5.5v7.02020-11-24
CVE-2020-10763 [MEDIUM] CWE-532 CVE-2020-10763: An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information.
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.
nvd
CVE-2015-5160P4MEDIUMCVSS 5.5v5v6.02018-08-20
CVE-2015-5160 [MEDIUM] CWE-200 CVE-2015-5160: libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
nvd
CVE-2023-40549P4MEDIUMCVSS 5.5v8.0v9.02024-01-29
CVE-2023-40549 [MEDIUM] CWE-125 CVE-2023-40549: An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during
An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service.
nvd
CVE-2022-23645P4MEDIUMCVSS 5.5v8.02022-02-18
CVE-2022-23645 [MEDIUM] CWE-125 CVE-2022-23645: swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versi
swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing t
nvd
CVE-2020-25641P4MEDIUMCVSS 5.5v7.0v8.02020-10-06
CVE-2020-25641 [MEDIUM] CWE-835 CVE-2020-25641: A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-
A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local attacker with basic privileges to issue requests to a block device, resulting in a denial of se
nvd
CVE-2021-3527P4MEDIUMCVSS 5.5v8.02021-05-26
CVE-2021-3527 [MEDIUM] CWE-770 CVE-2021-3527: A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined in
A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large transfer request, to reduce the overhead and improve performance. The combined size of the bulk transfer is used to dynamically allocate a variable length array (VLA) on the stack without proper validation. Since the total size is not
nvd
CVE-2022-4900P4MEDIUMCVSS 5.5v6.0v7.0+2 more2023-11-02
CVE-2022-4900 [MEDIUM] CWE-119 CVE-2022-4900: A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a
A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.
nvd
CVE-2023-38471P4MEDIUMCVSS 5.5v8.0v9.02023-11-02
CVE-2023-38471 [MEDIUM] CWE-617 CVE-2023-38471: A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
nvd
CVE-2023-38472P4MEDIUMCVSS 5.5v8.0v9.02023-11-02
CVE-2023-38472 [MEDIUM] CWE-617 CVE-2023-38472: A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.
nvd
CVE-2023-38473P4MEDIUMCVSS 5.5v8.0v9.02023-11-02
CVE-2023-38473 [MEDIUM] CWE-617 CVE-2023-38473: A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name(
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.
nvd
CVE-2023-38470P4MEDIUMCVSS 5.5v8.0v9.02023-11-02
CVE-2023-38470 [MEDIUM] CWE-617 CVE-2023-38470: A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() functio
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function.
nvd
CVE-2022-2873P4MEDIUMCVSS 5.5v6.0v7.0+2 more2022-08-22
CVE-2022-2873 [MEDIUM] CWE-131 CVE-2022-2873: An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller
An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data. This flaw allows a local user to crash the system.
nvd
CVE-2024-1062P4MEDIUMCVSS 5.5v8.02024-02-12
CVE-2024-1062 [MEDIUM] CWE-122 CVE-2024-1062: A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing
A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
nvd
CVE-2022-0171P4MEDIUMCVSS 5.5v8.0v9.02022-08-26
CVE-2022-0171 [MEDIUM] CWE-459 CVE-2022-0171: A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non
A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU that supports Secure Encrypted Virtualization (SEV).
nvd