cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,864 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159

Vulnerabilities

Page 73 of 94
CVE-2016-0641P4MEDIUMCVSS 5.1v6.0v7.02016-04-21
CVE-2016-0641 [MEDIUM] CVE-2016-0641: Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and ear Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect confidentiality and availability via vectors related to MyISAM.
nvd
CVE-2024-8354P4MEDIUMCVSS 5.5v6.0v7.0+2 more2024-09-19
CVE-2024-8354 [MEDIUM] CWE-617 CVE-2024-8354: A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/co A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to crash the QEMU process on the host and cause a denial of service condition.
nvd
CVE-2022-1184P4MEDIUMCVSS 5.5v8.0v9.02022-08-29
CVE-2022-1184 [MEDIUM] CWE-416 CVE-2022-1184: A use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block() in the Linux kernel’s filesyste A use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block() in the Linux kernel’s filesystem sub-component. This flaw allows a local attacker with a user privilege to cause a denial of service.
nvd
CVE-2022-0480P4MEDIUMCVSS 5.5v9.02022-08-29
CVE-2022-0480 [MEDIUM] CWE-770 CVE-2022-0480: A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lea A flaw was found in the filelock_init in fs/locks.c function in the Linux kernel. This issue can lead to host memory exhaustion due to memcg not limiting the number of Portable Operating System Interface (POSIX) file locks.
nvd
CVE-2023-4132P4MEDIUMCVSS 5.5v8.02023-08-03
CVE-2023-4132 [MEDIUM] CWE-416 CVE-2023-4132: A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel. The bug occ A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel. The bug occurs during device initialization when the siano device is plugged in. This flaw allows a local user to crash the system, causing a denial of service condition.
nvd
CVE-2024-0443P4MEDIUMCVSS 5.5v8.0v9.02024-01-12
CVE-2024-0443 [MEDIUM] CWE-402 CVE-2024-0443: A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference count reaches 0. This circular dependency will prevent blkcg and some blkgs
nvd
CVE-2023-4133P4MEDIUMCVSS 5.5v8.0v9.02023-08-03
CVE-2023-4133 [MEDIUM] CWE-416 CVE-2023-4133: A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs whe A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device is detaching due to a possible rearming of the flower_stats_timer from the work queue. This flaw allows a local user to crash the system, causing a denial of service condition.
nvd
CVE-2026-5745P4MEDIUMCVSS 5.5v6.0v7.0+3 more2026-04-07
CVE-2026-5745 [MEDIUM] CWE-476 CVE-2026-5745: A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing l A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An
nvd
CVE-2026-5164P4MEDIUMCVSS 5.5v9.0v10.02026-03-30
CVE-2026-5164 [MEDIUM] CWE-120 CVE-2026-5164: A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number o A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap request. A local user could exploit this input validation vulnerability by supplying an excessive number of descriptors, leading to a buffer overrun. This can cause a system crash, resulting in a Denial o
nvd
CVE-2019-3811P4MEDIUMCVSS 5.2v7.02019-01-15
CVE-2019-3811 [MEDIUM] CWE-200 CVE-2019-3811: A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would r A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.
nvd
CVE-2023-5870P4MEDIUMCVSS 4.4v8.0v9.02023-12-10
CVE-2023-5870 [MEDIUM] CWE-400 CVE-2023-5870: A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue
nvd
CVE-2023-40551P4MEDIUMCVSS 5.1v8.0v9.02024-01-29
CVE-2023-40551 [MEDIUM] CWE-125 CVE-2023-40551: A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a cras A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase.
nvd
CVE-2012-0867P4MEDIUMCVSS 4.3v5.02012-07-18
CVE-2012-0867 [MEDIUM] CWE-20 CVE-2012-0867: PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters.
nvd
CVE-2016-5444P4LOWCVSS 3.7v6.0v7.02016-07-21
CVE-2016-5444 [LOW] CVE-2016-5444: Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and ear Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to Server: Connection.
nvd
CVE-2016-3452P4LOWCVSS 3.7v6.0v7.02016-07-21
CVE-2016-3452 [LOW] CVE-2016-3452: Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.10 and ear Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to Server: Security: Encryption.
nvd
CVE-2019-18660P4MEDIUMCVSS 4.7v6.0v7.0+1 more2019-11-27
CVE-2019-18660 [MEDIUM] CWE-200 CVE-2019-18660: The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigat The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.
nvd
CVE-2021-3393P4MEDIUMCVSS 4.3v8.02021-04-01
CVE-2021-3393 [MEDIUM] CWE-209 CVE-2021-3393: An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11. An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information sto
nvd
CVE-2023-39418P4MEDIUMCVSS 4.3v8.0v9.02023-08-11
CVE-2023-39418 [MEDIUM] CWE-1220 CVE-2023-39418: A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new r A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.
nvd
CVE-2011-1745P4MEDIUMCVSS 6.9v5.02011-05-09
CVE-2011-1745 [MEDIUM] CWE-190 CVE-2011-1745: Integer overflow in the agp_generic_insert_memory function in drivers/char/agp/generic.c in the Linu Integer overflow in the agp_generic_insert_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_BIND agp_ioctl ioctl call.
nvd
CVE-2020-35508P4MEDIUMCVSS 4.5v8.02021-03-26
CVE-2020-35508 [MEDIUM] CWE-665 CVE-2020-35508: A flaw possibility of race condition and incorrect initialization of the process id was found in the A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.
nvd
Redhat Enterprise Linux vulnerabilities | cvebase