Redhat Enterprise Linux vulnerabilities
1,864 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159
Vulnerabilities
Page 78 of 94
CVE-2016-0611P4MEDIUMCVSS 4.0v6.0v7.02016-01-21
CVE-2016-0611 [MEDIUM] CWE-284 CVE-2016-0611: Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated u
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2016-0503P4MEDIUMCVSS 4.0v6.0v7.02016-01-21
CVE-2016-0503 [MEDIUM] CVE-2016-0503: Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated u
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2016-0504.
nvd
CVE-2018-12374P4MEDIUMCVSS 4.3v6.0v7.0+2 more2018-10-18
CVE-2018-12374 [MEDIUM] CWE-200 CVE-2018-12374: Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter
Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects Thunderbird < 52.9.
nvd
CVE-2010-2598P4MEDIUMCVSS 4.3v3v3.02010-07-02
CVE-2010-2598 [MEDIUM] CWE-20 CVE-2010-2598: LibTIFF in Red Hat Enterprise Linux (RHEL) 3 on x86_64 platforms, as used in tiff2rgba, attempts to
LibTIFF in Red Hat Enterprise Linux (RHEL) 3 on x86_64 platforms, as used in tiff2rgba, attempts to process image data even when the required compression functionality is not configured, which allows remote attackers to cause a denial of service via a crafted TIFF image, related to "downsampled OJPEG input."
nvd
CVE-2019-2996P4MEDIUMCVSS 4.2v8.02019-10-16
CVE-2019-2996 [MEDIUM] CVE-2019-2996: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Deployment). Th
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Deployment). The supported version that is affected is Java SE: 8u221; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require hu
nvd
CVE-2023-5380P4MEDIUMCVSS 4.7v7.0v8.0+1 more2023-10-25
CVE-2023-5380 [MEDIUM] CWE-416 CVE-2023-5380: A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specif
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed follo
nvd
CVE-2005-0403P4HIGHCVSS 7.2v3.02005-09-01
CVE-2005-0403 [HIGH] CVE-2005-0403: init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 does not properly
init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 does not properly clear controlling tty's in multi-threaded applications, which allows local users to cause a denial of service (crash) and possibly gain tty access via unknown attack vectors that trigger an access of a pointer to a freed structure.
nvd
CVE-2021-3660P4MEDIUMCVSS 4.3v8.02022-03-10
CVE-2021-3660 [MEDIUM] CWE-1021 CVE-2021-3660: Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to rend
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
nvd
CVE-2005-1194P4MEDIUMCVSS 4.6v2.1v3.0+1 more2005-05-04
CVE-2005-1194 [MEDIUM] CVE-2005-1194: Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers
Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2004-1287.
nvd
CVE-2023-6176P4MEDIUMCVSS 4.7v8.0v9.02023-11-16
CVE-2023-6176 [MEDIUM] CWE-476 CVE-2023-6176: A null pointer dereference flaw was found in the Linux kernel API for the cryptographic algorithm sc
A null pointer dereference flaw was found in the Linux kernel API for the cryptographic algorithm scatterwalk functionality. This issue occurs when a user constructs a malicious packet with specific socket configuration, which could allow a local user to crash the system or escalate their privileges on the system.
nvd
CVE-2004-0886P4MEDIUMCVSS 5.0v2.1v3.02005-01-27
CVE-2004-0886 [MEDIUM] CVE-2004-0886: Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
nvd
CVE-2004-0635P4MEDIUMCVSS 5.0v2.1v3.02004-12-06
CVE-2004-0635 [MEDIUM] CVE-2004-0635: The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of se
The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read.
nvd
CVE-2012-6137P4MEDIUMCVSS 4.3v52013-05-21
CVE-2012-6137 [MEDIUM] CWE-255 CVE-2012-6137: rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network
rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensitive information such as user credentials.
nvd
CVE-2019-15718P4MEDIUMCVSS 4.4v8.02019-09-04
CVE-2019-15718 [MEDIUM] CVE-2019-15718: In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be restricted to privileged users, in order
nvd
CVE-2023-39194P4MEDIUMCVSS 4.4v8.0v9.02023-10-09
CVE-2023-39194 [MEDIUM] CWE-125 CVE-2023-39194: A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the proc
A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.
nvd
CVE-2004-0930P4MEDIUMCVSS 5.0v2.1v3.02005-01-27
CVE-2004-0930 [MEDIUM] CVE-2004-0930: The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authentic
The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.
nvd
CVE-2022-0984P4MEDIUMCVSS 4.3v7.02022-04-29
CVE-2022-0984 [MEDIUM] CWE-863 CVE-2022-0984: Users with the capability to configure badge criteria (teachers and managers by default) were able t
Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.
nvd
CVE-2024-45619P4MEDIUMCVSS 4.3v7.0v8.0+1 more2024-09-03
CVE-2024-45619 [MEDIUM] CWE-120 CVE-2024-45619: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.
nvd
CVE-2020-25656P4MEDIUMCVSS 4.1v7.0v8.02020-12-02
CVE-2020-25656 [MEDIUM] CWE-416 CVE-2020-25656: A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem wa
A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidentiality.
nvd
CVE-2013-4482P4MEDIUMCVSS 6.2v6.02013-11-23
CVE-2013-4482 [MEDIUM] CVE-2013-4482: Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started
Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local users to gain privileges via a Trojan horse .egg-info file in the (1) current working directory or (2) its parent directories.
nvd