Redhat Enterprise Linux vulnerabilities
1,864 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159
Vulnerabilities
Page 77 of 94
CVE-2021-30471P4MEDIUMCVSS 5.5v7.02021-05-26
CVE-2021-30471 [MEDIUM] CWE-674 CVE-2021-30471: A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary fu
A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary function in src/podofo/doc/PdfNamesTree.cpp can lead to a stack overflow.
nvd
CVE-2021-30469P4MEDIUMCVSS 5.5v7.02021-05-26
CVE-2021-30469 [MEDIUM] CWE-416 CVE-2021-30469: A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can c
A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can cause a denial of service via a crafted PDF file.
nvd
CVE-2014-3647P4MEDIUMCVSS 5.5v5.0v6.02014-11-10
CVE-2014-3647 [MEDIUM] CVE-2014-3647: arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly per
arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
nvd
CVE-2022-1354P4MEDIUMCVSS 5.5v9.02022-08-31
CVE-2022-1354 [MEDIUM] CWE-125 CVE-2022-1354: A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function.
A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.
nvd
CVE-2020-10769P4MEDIUMCVSS 5.5v7.02020-06-26
CVE-2020-10769 [MEDIUM] CWE-125 CVE-2020-10769: A buffer over-read flaw was found in RH kernel versions before 5.0 in crypto_authenc_extractkeys in
A buffer over-read flaw was found in RH kernel versions before 5.0 in crypto_authenc_extractkeys in crypto/authenc.c in the IPsec Cryptographic algorithm's module, authenc. When a payload longer than 4 bytes, and is not following 4-byte alignment boundary guidelines, it causes a buffer over-read threat, leading to a system crash. This flaw allows a l
nvd
CVE-2023-43786P4MEDIUMCVSS 5.5v8.0v9.02023-10-10
CVE-2023-43786 [MEDIUM] CWE-400 CVE-2023-43786: A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This
A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition.
nvd
CVE-2022-25310P4MEDIUMCVSS 5.5v8.0v9.02022-09-06
CVE-2022-25310 [MEDIUM] CWE-119 CVE-2022-25310: A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bid
A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file. This flaw allows an attacker to pass a specially crafted file to Fribidi, leading to a crash and causing a denial of service.
nvd
CVE-2018-16878P4MEDIUMCVSS 5.5v8.02019-04-18
CVE-2018-16878 [MEDIUM] CWE-400 CVE-2018-16878: A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflic
A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS
nvd
CVE-2023-40546P4MEDIUMCVSS 5.5v8.0v9.02024-01-29
CVE-2023-40546 [MEDIUM] CWE-476 CVE-2023-40546: A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to
A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the logging function doesn't match the format string used by it, leading to a crash under certain circumstances.
nvd
CVE-2022-3821P4MEDIUMCVSS 5.5v8.0v9.02022-11-08
CVE-2022-3821 [MEDIUM] CWE-193 CVE-2022-3821: An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An
An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.
nvd
CVE-2017-15127P4MEDIUMCVSS 5.5v7.02018-01-14
CVE-2017-15127 [MEDIUM] CWE-460 CVE-2017-15127: A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before
A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13. A superfluous implicit page unlock for VM_SHARED hugetlbfs mapping could trigger a local denial of service (BUG).
nvd
CVE-2024-0232P4MEDIUMCVSS 5.5v8.0v9.02024-01-16
CVE-2024-0232 [MEDIUM] CWE-416 CVE-2024-0232: A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
nvd
CVE-2023-4042P4MEDIUMCVSS 5.5v8.02023-08-23
CVE-2023-4042 [MEDIUM] CVE-2023-4042: A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.
nvd
CVE-2023-6622P4MEDIUMCVSS 5.5v8.0v9.02023-12-08
CVE-2023-6622 [MEDIUM] CWE-476 CVE-2023-6622: A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset.
A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset.c in nf_tables in the Linux kernel. This issue may allow a local attacker with CAP_NET_ADMIN user privilege to trigger a denial of service.
nvd
CVE-2023-6679P4MEDIUMCVSS 5.5v9.02023-12-11
CVE-2023-6679 [MEDIUM] CWE-476 CVE-2023-6679: A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll
A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Digital Phase Locked Loop (DPLL) subsystem in the Linux kernel. This issue could be exploited to trigger a denial of service.
nvd
CVE-2023-32627P4MEDIUMCVSS 5.5v6.0v7.02023-07-10
CVE-2023-32627 [MEDIUM] CWE-1077 CVE-2023-32627: A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/v
A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.
nvd
CVE-2023-6915P4MEDIUMCVSS 5.5v8.0v9.02024-01-15
CVE-2023-6915 [MEDIUM] CWE-476 CVE-2023-6915: A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issu
A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attacker using this library to cause a denial of service problem due to a missing check at a function return.
nvd
CVE-2023-2700P4MEDIUMCVSS 5.5v8.0v9.02023-05-15
CVE-2023-2700 [MEDIUM] CWE-401 CVE-2023-2700: A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IO
A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.
nvd
CVE-2023-26590P4MEDIUMCVSS 5.5v6.0v7.02023-07-10
CVE-2023-26590 [MEDIUM] CWE-1077 CVE-2023-26590: A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox
A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service.
nvd
CVE-2013-4332P4MEDIUMCVSS 4.3v52013-10-09
CVE-2013-4332 [MEDIUM] CWE-189 CVE-2013-4332: Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and ear
Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of service (heap corruption) via a large value to the (1) pvalloc, (2) valloc, (3) posix_memalign, (4) memalign, or (5) aligned_alloc functions.
nvd