Redhat Enterprise Linux vulnerabilities
1,864 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159
Vulnerabilities
Page 82 of 94
CVE-2016-0598P4LOWCVSS 3.5v6.0v7.02016-01-21
CVE-2016-0598 [LOW] CVE-2016-0598: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML.
nvd
CVE-2016-0608P4LOWCVSS 3.5v6.0v7.02016-01-21
CVE-2016-0608 [LOW] CVE-2016-0608: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to UDF.
nvd
CVE-2016-0600P4LOWCVSS 3.5v6.0v7.02016-01-21
CVE-2016-0600 [LOW] CVE-2016-0600: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2018-16888P4MEDIUMCVSS 4.7v7.02019-01-14
CVE-2018-16888 [MEDIUM] CWE-250 CVE-2018-16888: It was discovered systemd does not correctly check the content of PIDFile files before using it to k
It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run from an unprivileged user (e.g. User field set in the service file), a local attacker who is able to write to the PIDFile of the mentioned service may use this flaw to trick systemd into killing other services and/
nvd
CVE-2014-3611P4MEDIUMCVSS 4.7v5.02014-11-10
CVE-2014-3611 [MEDIUM] CWE-362 CVE-2014-3611: Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem
Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem in the Linux kernel through 3.17.2 allows guest OS users to cause a denial of service (host OS crash) by leveraging incorrect PIT emulation.
nvd
CVE-2023-42756P4MEDIUMCVSS 4.7v9.02023-09-28
CVE-2023-42756 [MEDIUM] CWE-362 CVE-2023-42756: A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_
A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue may allow a local user to crash the system.
nvd
CVE-2021-20321P4MEDIUMCVSS 4.7v7.0v8.02022-02-18
CVE-2021-20321 [MEDIUM] CWE-362 CVE-2021-20321: A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way
A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in specific way with OverlayFS. A local user could use this flaw to crash the system.
nvd
CVE-2005-0087P4MEDIUMCVSS 4.6v4.02005-04-27
CVE-2005-0087 [MEDIUM] CVE-2005-0087: The alsa-lib package in Red Hat Linux 4 disables stack protection for the libasound.so library, whic
The alsa-lib package in Red Hat Linux 4 disables stack protection for the libasound.so library, which makes it easier for attackers to execute arbitrary code if there are other vulnerabilities in the library.
nvd
CVE-2013-4324P4MEDIUMCVSS 4.6v6.02013-10-03
CVE-2013-4324 [MEDIUM] CVE-2013-4324: spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_
spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
nvd
CVE-2019-15030P4MEDIUMCVSS 4.4v7.0v8.02019-09-13
CVE-2019-15030 [MEDIUM] CWE-862 CVE-2019-15030: In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers o
In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a Facility Unavailable exception. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction tbegin) and then accesses vector registers. At some point, the vector regi
nvd
CVE-2021-4159P4MEDIUMCVSS 4.4v8.02022-08-24
CVE-2021-4159 [MEDIUM] CWE-202 CVE-2021-4159: A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures
A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel.
nvd
CVE-2026-12892P4MEDIUMCVSS 4.4v6.0v7.0+3 more2026-06-23
CVE-2026-12892 [MEDIUM] CWE-125 CVE-2026-12892: A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 v
A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contain
nvd
CVE-2005-3626P4MEDIUMCVSS 5.0v2.1v3.0+1 more2005-12-31
CVE-2005-3626 [MEDIUM] CWE-399 CVE-2005-3626: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and oth
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
nvd
CVE-2004-1068P4MEDIUMCVSS 6.2v2.1v3.02005-01-10
CVE-2004-1068 [MEDIUM] CVE-2004-1068: A "missing serialization" error in the unix_dgram_recvmsg function in Linux 2.4.27 and earlier, and
A "missing serialization" error in the unix_dgram_recvmsg function in Linux 2.4.27 and earlier, and 2.6.x up to 2.6.9, allows local users to gain privileges via a race condition.
nvd
CVE-2004-0960P4MEDIUMCVSS 5.0v3.02005-02-09
CVE-2004-0960 [MEDIUM] CVE-2004-0960: FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malform
FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.
nvd
CVE-2026-15041P4LOWCVSS 3.7v7.0v8.0+2 more2026-07-08
CVE-2026-15041 [LOW] CWE-208 CVE-2026-15041: A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses stan
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though practical exploitation is extremely di
nvd
CVE-2005-1918P4LOWCVSS 2.6v2.1v3.02005-12-31
CVE-2005-1918 [LOW] CVE-2005-1918: The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterp
The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably involving "/../" sequences with a leading "/".
nvd
CVE-2004-1142P4MEDIUMCVSS 5.0v2.1v3.02004-12-15
CVE-2004-1142 [MEDIUM] CVE-2004-1142: Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption)
Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet.
nvd
CVE-2013-2051P4LOWCVSS 2.6v6.02013-07-09
CVE-2013-2051 [LOW] CVE-2013-2051: The Tomcat 6 DIGEST authentication functionality as used in Red Hat Enterprise Linux 6 allows remote
The Tomcat 6 DIGEST authentication functionality as used in Red Hat Enterprise Linux 6 allows remote attackers to bypass intended access restrictions by performing a replay attack after a nonce becomes stale. NOTE: this issue is due to an incomplete fix for CVE-2012-5887.
nvd
CVE-2016-0609P4LOWCVSS 1.7v6.0v7.02016-01-21
CVE-2016-0609 [LOW] CVE-2016-0609: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to privileges.
nvd