Redhat Enterprise Linux vulnerabilities
1,738 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,738
CISA KEV
20
actively exploited
Public exploits
88
Exploited in wild
26
Severity breakdown
CRITICAL157HIGH589MEDIUM839LOW153
Vulnerabilities
Page 77 of 87
CVE-2013-0383MEDIUMCVSS 4.3v6.02013-01-17
CVE-2013-0383 [MEDIUM] CVE-2013-0383: Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote attackers to affect availability via unknown vectors related to Server Locking.
nvd
CVE-2012-3166MEDIUMCVSS 4.0v6.02012-10-17
CVE-2012-3166 [MEDIUM] CVE-2012-3166: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2012-3177MEDIUMCVSS 6.8v6.02012-10-17
CVE-2012-3177 [MEDIUM] CVE-2012-3177: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server.
nvd
CVE-2012-4291LOWCVSS 3.3v52012-08-16
CVE-2012-4291 [LOW] CWE-399 CVE-2012-4291: The CIP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allo
The CIP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.
nvd
CVE-2012-4290LOWCVSS 3.3v52012-08-16
CVE-2012-4290 [LOW] CWE-399 CVE-2012-4290: The CTDB dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 all
The CTDB dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a malformed packet.
nvd
CVE-2012-4289LOWCVSS 3.3v52012-08-16
CVE-2012-4289 [LOW] CWE-399 CVE-2012-4289: epan/dissectors/packet-afp.c in the AFP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6
epan/dissectors/packet-afp.c in the AFP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a large number of ACL entries.
nvd
CVE-2012-4285LOWCVSS 3.3v52012-08-16
CVE-2012-4285 [LOW] CWE-189 CVE-2012-4285: The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark
The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a zero-length message.
nvd
CVE-2012-3440MEDIUMCVSS 5.6v52012-08-08
CVE-2012-3440 [MEDIUM] CWE-59 CVE-2012-3440: A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to o
A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file.
nvd
CVE-2012-2665HIGHCVSS 7.5v6.02012-08-06
CVE-2012-2665 [HIGH] CWE-787 CVE-2012-2665: Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in Ope
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a
nvd
CVE-2012-0867MEDIUMCVSS 4.3v5.02012-07-18
CVE-2012-0867 [MEDIUM] CWE-20 CVE-2012-0867: PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name
PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters.
nvd
CVE-2012-1149HIGHCVSS 7.5v5.02012-06-21
CVE-2012-1149 [HIGH] CWE-189 CVE-2012-1149: Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based b
nvd
CVE-2012-2313LOWCVSS 1.2v52012-06-13
CVE-2012-2313 [LOW] CWE-264 CVE-2012-2313: The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does no
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
nvd
CVE-2011-3188CRITICALCVSS 9.1v4.02012-05-24
CVE-2011-3188 [CRITICAL] CVE-2011-3188: The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorith
The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.
nvd
CVE-2011-3191HIGHCVSS 8.8v4.02012-05-24
CVE-2011-3191 [HIGH] CWE-119 CVE-2011-3191: Integer signedness error in the CIFSFindNext function in fs/cifs/cifssmb.c in the Linux kernel befor
Integer signedness error in the CIFSFindNext function in fs/cifs/cifssmb.c in the Linux kernel before 3.1 allows remote CIFS servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large length value in a response to a read request for a directory.
nvd
CVE-2011-2699HIGHCVSS 7.5v4.02012-05-24
CVE-2011-2699 [HIGH] CVE-2011-2699: The IPv6 implementation in the Linux kernel before 3.1 does not generate Fragment Identification val
The IPv6 implementation in the Linux kernel before 3.1 does not generate Fragment Identification values separately for each destination, which makes it easier for remote attackers to cause a denial of service (disrupted networking) by predicting these values and sending crafted packets.
nvd
CVE-2011-2517HIGHCVSS 7.2v5.02012-05-24
CVE-2011-2517 [HIGH] CWE-119 CVE-2011-2517: Multiple buffer overflows in net/wireless/nl80211.c in the Linux kernel before 2.6.39.2 allow local
Multiple buffer overflows in net/wireless/nl80211.c in the Linux kernel before 2.6.39.2 allow local users to gain privileges by leveraging the CAP_NET_ADMIN capability during scan operations with a long SSID value.
nvd
CVE-2011-3363MEDIUMCVSS 6.5v4.02012-05-24
CVE-2011-3363 [MEDIUM] CWE-20 CVE-2011-3363: The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly
The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS servers to cause a denial of service (system crash) by placing a referral at the root of a share.
nvd
CVE-2012-1097HIGHCVSS 7.8v4.02012-05-17
CVE-2012-1097 [HIGH] CWE-476 CVE-2012-1097: The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the
The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a (1) PTRACE_GETREGSET or (2) PTRACE_SETREGSET ptrace call.
nvd
CVE-2011-4097MEDIUMCVSS 5.5v6.02012-05-17
CVE-2011-4097 [MEDIUM] CWE-190 CVE-2011-4097: Integer overflow in the oom_badness function in mm/oom_kill.c in the Linux kernel before 3.1.8 on 64
Integer overflow in the oom_badness function in mm/oom_kill.c in the Linux kernel before 3.1.8 on 64-bit platforms allows local users to cause a denial of service (memory consumption or process termination) by using a certain large amount of memory.
nvd
CVE-2011-3637MEDIUMCVSS 5.5v6.02012-05-17
CVE-2011-3637 [MEDIUM] CWE-476 CVE-2011-3637: The m_stop function in fs/proc/task_mmu.c in the Linux kernel before 2.6.39 allows local users to ca
The m_stop function in fs/proc/task_mmu.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (OOPS) via vectors that trigger an m_start error.
nvd