Redhat Enterprise Linux vulnerabilities
1,864 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159
Vulnerabilities
Page 79 of 94
CVE-2013-3718P4MEDIUMCVSS 5.5v5.02019-11-01
CVE-2013-3718 [MEDIUM] CWE-20 CVE-2013-3718: evince is missing a check on number of pages which can lead to a segmentation fault
evince is missing a check on number of pages which can lead to a segmentation fault
nvd
CVE-2004-1014P4MEDIUMCVSS 5.0v3.02005-01-10
CVE-2004-1014 [MEDIUM] CVE-2004-1014: statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attacke
statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.
nvd
CVE-2019-7664P4MEDIUMCVSS 5.5v8.02019-02-09
CVE-2019-7664 [MEDIUM] CWE-787 CVE-2019-7664: In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h becau
In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program crash).
nvd
CVE-2012-3440P4MEDIUMCVSS 5.6v52012-08-08
CVE-2012-3440 [MEDIUM] CWE-59 CVE-2012-3440: A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to o
A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file.
nvd
CVE-2016-4470P4MEDIUMCVSS 5.5v6.02016-06-27
CVE-2016-4470 [MEDIUM] CVE-2016-4470: The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not e
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.
nvd
CVE-2016-3695P4MEDIUMCVSS 5.5v7.02017-12-29
CVE-2016-3695 [MEDIUM] CWE-74 CVE-2016-3695: The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to
The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leveraging failure to disable APEI error injection through EINJ when securelevel is set.
nvd
CVE-2015-1350P4MEDIUMCVSS 5.5v5.0v6.0+1 more2016-05-02
CVE-2015-1350 [MEDIUM] CWE-552 CVE-2015-1350: The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr ope
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the pin
nvd
CVE-2023-38559P4MEDIUMCVSS 5.5v8.0v9.02023-08-01
CVE-2023-38559 [MEDIUM] CWE-125 CVE-2023-38559: A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. Thi
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
nvd
CVE-2014-3646P4MEDIUMCVSS 5.5v5.02014-11-10
CVE-2014-3646 [MEDIUM] CVE-2014-3646: arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit han
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
nvd
CVE-2004-1093P4MEDIUMCVSS 5.0v2.12005-04-14
CVE-2004-1093 [MEDIUM] CVE-2004-1093: Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory."
nvd
CVE-2004-1092P4MEDIUMCVSS 5.0v2.12005-04-14
CVE-2004-1092 [MEDIUM] CVE-2004-1092: Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by c
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.
nvd
CVE-2023-42755P4MEDIUMCVSS 5.5v8.02023-10-05
CVE-2023-42755 [MEDIUM] CWE-125 CVE-2023-42755: A flaw was found in the IPv4 Resource Reservation Protocol (RSVP) classifier in the Linux kernel. Th
A flaw was found in the IPv4 Resource Reservation Protocol (RSVP) classifier in the Linux kernel. The xprt pointer may go beyond the linear part of the skb, leading to an out-of-bounds read in the `rsvp_classify` function. This issue may allow a local user to crash the system and cause a denial of service.
nvd
CVE-2017-15121P4MEDIUMCVSS 5.5v6.0v7.02017-12-07
CVE-2017-15121 [MEDIUM] CWE-20 CVE-2017-15121: A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an app
A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary.
nvd
CVE-2014-8171P4MEDIUMCVSS 5.5v6.0v7.02018-02-09
CVE-2014-8171 [MEDIUM] CWE-399 CVE-2014-8171: The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial
The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.
nvd
CVE-2017-15116P4MEDIUMCVSS 5.5v7.02017-11-30
CVE-2017-15116 [MEDIUM] CWE-476 CVE-2017-15116: The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a
The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference).
nvd
CVE-2023-3576P4MEDIUMCVSS 5.5v8.0v9.02023-10-04
CVE-2023-3576 [MEDIUM] CWE-119 CVE-2023-3576: A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates
A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, which causes this memory leak issue, resulting an application crash, eventually leading to a denial of service.
nvd
CVE-2019-10140P4MEDIUMCVSS 5.5v7.02019-08-15
CVE-2019-10140 [MEDIUM] CWE-476 CVE-2019-10140: A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An at
A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c. This can allow attackers with ability to create directories on overlayfs to crash the kernel creatin
nvd
CVE-2023-3164P4MEDIUMCVSS 5.5v7.0v8.0+1 more2023-11-02
CVE-2023-3164 [MEDIUM] CWE-120 CVE-2023-3164: A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcro
A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file.
nvd
CVE-2022-1852P4MEDIUMCVSS 5.5v8.0v9.02022-06-30
CVE-2022-1852 [MEDIUM] CWE-476 CVE-2022-1852: A NULL pointer dereference flaw was found in the Linux kernel’s KVM module, which can lead to a deni
A NULL pointer dereference flaw was found in the Linux kernel’s KVM module, which can lead to a denial of service in the x86_emulate_insn in arch/x86/kvm/emulate.c. This flaw occurs while executing an illegal instruction in guest in the Intel CPU.
nvd
CVE-2023-4569P4MEDIUMCVSS 5.5v8.0v9.02023-08-28
CVE-2023-4569 [MEDIUM] CWE-402 CVE-2023-4569: A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux
A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a memory leak.
nvd