cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,864 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159

Vulnerabilities

Page 70 of 94
CVE-2020-35522P4MEDIUMCVSS 5.5v6.0v7.0+1 more2021-03-09
CVE-2020-35522 [MEDIUM] CWE-119 CVE-2020-35522: In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a remote denial of service attack.
nvd
CVE-2021-20221P4MEDIUMCVSS 6.0v8.02021-05-13
CVE-2021-20221 [MEDIUM] CWE-125 CVE-2021-20221: An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64 platform. The issue occurs because while writing an interrupt ID to the controller memory area, it is not masked to be 4 bits wide. It may lead to the said issue while updating controller state fields
nvd
CVE-2020-27842P4MEDIUMCVSS 5.5v8.02021-01-05
CVE-2020-27842 [MEDIUM] CWE-125 CVE-2020-27842: There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provi There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability.
nvd
CVE-2020-35507P4MEDIUMCVSS 5.5v8.02021-01-04
CVE-2020-35507 [MEDIUM] CWE-476 CVE-2020-35507: There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 wh There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability.
nvd
CVE-2021-20246P4MEDIUMCVSS 5.5v6.0v7.0+1 more2021-03-09
CVE-2021-20246 [MEDIUM] CWE-369 CVE-2021-20246: A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file tha A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
nvd
CVE-2021-20245P4MEDIUMCVSS 5.5v6.0v7.0+1 more2021-03-09
CVE-2021-20245 [MEDIUM] CWE-369 CVE-2021-20245: A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is pro A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
nvd
CVE-2019-2539P4MEDIUMCVSS 4.9v8.02019-01-16
CVE-2019-2539 [MEDIUM] CVE-2019-2539: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection). Supp Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ab
nvd
CVE-2014-0186P4MEDIUMCVSS 5.0v7.02014-06-14
CVE-2014-0186 [MEDIUM] CVE-2014-0186: A certain tomcat7 package for Apache Tomcat 7 in Red Hat Enterprise Linux (RHEL) 7 allows remote att A certain tomcat7 package for Apache Tomcat 7 in Red Hat Enterprise Linux (RHEL) 7 allows remote attackers to cause a denial of service (CPU consumption) via a crafted request. NOTE: this vulnerability exists because of an unspecified regression.
nvd
CVE-2026-59845P4MEDIUMCVSS 5.9v8.0v9.0+1 more2026-07-21
CVE-2026-59845 [MEDIUM] CWE-390 CVE-2026-59845: A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.
nvd
CVE-2019-2530P4MEDIUMCVSS 4.9v8.02019-01-16
CVE-2019-2530 [MEDIUM] CVE-2019-2530: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abi
nvd
CVE-2019-2785P4MEDIUMCVSS 4.9v8.02019-07-23
CVE-2019-2785 [MEDIUM] CVE-2019-2785: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cau
nvd
CVE-2014-0081P4MEDIUMCVSS 4.3v6.02014-02-20
CVE-2014-0081 [MEDIUM] CWE-79 CVE-2014-0081: Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_hel Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to the (a) number_to_currency, (b) numbe
nvd
CVE-2019-2644P4MEDIUMCVSS 4.9v8.02019-04-23
CVE-2019-2644 [MEDIUM] CVE-2019-2644: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2019-2592P4MEDIUMCVSS 4.9v8.02019-04-23
CVE-2019-2592 [MEDIUM] CVE-2019-2592: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: PS). Supported ve Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: PS). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in un
nvd
CVE-2019-2581P4MEDIUMCVSS 4.9v8.02019-04-23
CVE-2019-2581 [MEDIUM] CVE-2019-2581: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can resul
nvd
CVE-2021-3679P4MEDIUMCVSS 5.5v8.02021-08-05
CVE-2021-3679 [MEDIUM] CWE-400 CVE-2021-3679: A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to starve the resources causing denial of service.
nvd
CVE-2019-2620P4MEDIUMCVSS 4.9v8.02019-04-23
CVE-2019-2620 [MEDIUM] CVE-2019-2620: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privile Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2019-2580P4MEDIUMCVSS 4.9v8.02019-04-23
CVE-2019-2580 [MEDIUM] CVE-2019-2580: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cau
nvd
CVE-2019-2606P4MEDIUMCVSS 4.9v8.02019-04-23
CVE-2019-2606 [MEDIUM] CVE-2019-2606: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privile Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2019-2607P4MEDIUMCVSS 4.9v8.02019-04-23
CVE-2019-2607 [MEDIUM] CVE-2019-2607: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abi
nvd
Redhat Enterprise Linux vulnerabilities | cvebase