Redhat Enterprise Linux vulnerabilities
1,864 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159
Vulnerabilities
Page 80 of 94
CVE-2023-28328P4MEDIUMCVSS 5.5v8.02023-04-19
CVE-2023-28328 [MEDIUM] CWE-476 CVE-2023-28328: A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c
A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel. The message from user space is not checked properly before transferring into the device. This flaw allows a local user to crash the system or potentially cause a denial of service.
nvd
CVE-2015-0383P4MEDIUMCVSS 5.4v5v6.0+1 more2015-01-21
CVE-2015-0383 [MEDIUM] CVE-2015-0383: Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via unknown vectors related to Hotspot.
nvd
CVE-2023-28327P4MEDIUMCVSS 5.5v8.0v9.02023-04-19
CVE-2023-28327 [MEDIUM] CWE-476 CVE-2023-28327: A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_e
A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Kernel. The newly allocated skb does not have sk, leading to a NULL pointer. This flaw allows a local user to crash or potentially cause a denial of service.
nvd
CVE-2026-6843P4MEDIUMCVSS 5.5v6.0v7.0+3 more2026-04-22
CVE-2026-6843 [MEDIUM] CWE-134 CVE-2026-6843: A flaw was found in nano. A local user could exploit a format string vulnerability in the `statuslin
A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading to a segmentation fault (SEGV). This results in a Denial of Service (DoS) for the `nano` application.
nvd
CVE-2015-4756P4MEDIUMCVSS 4.0v6.0v7.02015-07-16
CVE-2015-4756 [MEDIUM] CVE-2015-4756: Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB, a different vulnerability than CVE-2015-0439.
nvd
CVE-2022-3500P4MEDIUMCVSS 5.1v9.02022-11-22
CVE-2022-3500 [MEDIUM] CWE-248 CVE-2022-3500: A vulnerability was found in keylime. This security issue happens in some circumstances, due to some
A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in an attested state but not verifying that anymore.
nvd
CVE-2019-2617P4MEDIUMCVSS 4.4v8.02019-04-23
CVE-2019-2617 [MEDIUM] CVE-2019-2617: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2016-0595P4MEDIUMCVSS 4.0v6.0v7.02016-01-21
CVE-2016-0595 [MEDIUM] CVE-2016-0595: Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows remote authenticated users to af
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows remote authenticated users to affect availability via vectors related to DML.
nvd
CVE-2019-2630P4MEDIUMCVSS 4.4v8.02019-04-23
CVE-2019-2630 [MEDIUM] CVE-2019-2630: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2019-2636P4MEDIUMCVSS 4.4v8.02019-04-23
CVE-2019-2636 [MEDIUM] CVE-2019-2636: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Group Replication
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Group Replication Plugin). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via MySQL Procotol to compromise MySQL Server. Successful attacks of this vulnerability can result in una
nvd
CVE-2004-1057P4HIGHCVSS 7.2v2.1v3.0+1 more2005-01-21
CVE-2004-1057 [HIGH] CVE-2004-1057: Multiple drivers in Linux kernel 2.4.19 and earlier do not properly mark memory with the VM_IO flag,
Multiple drivers in Linux kernel 2.4.19 and earlier do not properly mark memory with the VM_IO flag, which causes incorrect reference counts and may lead to a denial of service (kernel panic) when accessing freed kernel pages.
nvd
CVE-2016-0606P4LOWCVSS 3.5v6.0v7.02016-01-21
CVE-2016-0606 [LOW] CVE-2016-0606: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect integrity via unknown vectors related to encryption.
nvd
CVE-2015-7810P4MEDIUMCVSS 4.7v7.02019-11-22
CVE-2015-7810 [MEDIUM] CWE-367 CVE-2015-7810: libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
nvd
CVE-2013-4235P4MEDIUMCVSS 4.7v5v6.02019-12-03
CVE-2013-4235 [MEDIUM] CWE-367 CVE-2013-4235: shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
nvd
CVE-2004-0634P4MEDIUMCVSS 5.0v2.1v3.02004-12-06
CVE-2004-0634 [MEDIUM] CVE-2004-0634: The SMB SID snooping capability in Ethereal 0.9.15 to 0.10.4 allows remote attackers to cause a deni
The SMB SID snooping capability in Ethereal 0.9.15 to 0.10.4 allows remote attackers to cause a denial of service (process crash) via a handle without a policy name, which causes a null dereference.
nvd
CVE-2011-1746P4MEDIUMCVSS 6.9v5.02011-05-09
CVE-2011-1746 [MEDIUM] CWE-189 CVE-2011-1746: Multiple integer overflows in the (1) agp_allocate_memory and (2) agp_create_user_memory functions i
Multiple integer overflows in the (1) agp_allocate_memory and (2) agp_create_user_memory functions in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allow local users to trigger buffer overflows, and consequently cause a denial of service (system crash) or possibly have unspecified other impact, via vectors related to calls that specif
nvd
CVE-2008-0884P4MEDIUMCVSS 6.9v5.02008-04-04
CVE-2008-0884 [MEDIUM] CWE-732 CVE-2008-0884: The Replace function in the capp-lspp-config script in the (1) lspp-eal4-config-ibm and (2) capp-lsp
The Replace function in the capp-lspp-config script in the (1) lspp-eal4-config-ibm and (2) capp-lspp-eal4-config-hp packages before 0.65-2 in Red Hat Enterprise Linux (RHEL) 5 uses lstat instead of stat to determine the /etc/pam.d/system-auth file permissions, leading to a change to world-writable permissions for the /etc/pam.d/system-auth-ac file, w
nvd
CVE-2019-15031P4MEDIUMCVSS 4.4v7.0v8.02019-09-13
CVE-2019-15031 [MEDIUM] CWE-662 CVE-2019-15031: In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers o
In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via an interrupt. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction tbegin) and then accesses vector registers. At some point, the vector registers will be corrup
nvd
CVE-2011-1773P4MEDIUMCVSS 4.4v6.02014-02-08
CVE-2011-1773 [MEDIUM] CWE-255 CVE-2011-1773: virt-v2v before 0.8.4 does not preserve the VNC console password when converting a guest, which allo
virt-v2v before 0.8.4 does not preserve the VNC console password when converting a guest, which allows local users to bypass the intended VNC authentication by connecting without a password.
nvd
CVE-2019-14826P4MEDIUMCVSS 4.4v7.0v8.02019-09-17
CVE-2019-14826 [MEDIUM] CWE-613 CVE-2019-14826: A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache aft
A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attacker could abuse this flaw if they obtain previously valid session cookies and can use this to gain access to the session.
nvd