Redhat Enterprise Linux vulnerabilities
1,864 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159
Vulnerabilities
Page 83 of 94
CVE-2004-1090P4MEDIUMCVSS 5.0v2.12005-04-14
CVE-2004-1090 [MEDIUM] CVE-2004-1090: Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."
nvd
CVE-2019-18811P4MEDIUMCVSS 5.5v8.02019-11-07
CVE-2019-18811 [MEDIUM] CWE-401 CVE-2019-18811: A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kern
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.
nvd
CVE-2012-0066P4MEDIUMCVSS 4.3v52012-04-11
CVE-2012-0066 [MEDIUM] CWE-20 CVE-2012-0066: Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of se
Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a (1) Accellent 5Views (aka .5vw) file, (2) I4B trace file, or (3) NETMON 2 capture file.
nvd
CVE-2020-2659P4LOWCVSS 3.7v8.02020-01-15
CVE-2020-2659 [LOW] CVE-2020-2659: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Su
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241 and 8u231; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of t
nvd
CVE-2020-2583P4LOWCVSS 3.7v8.02020-01-15
CVE-2020-2583 [LOW] CWE-755 CVE-2020-2583: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization).
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedd
nvd
CVE-2016-0655P4MEDIUMCVSS 4.7v6.0v7.02016-04-21
CVE-2016-0655 [MEDIUM] CVE-2016-0655: Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier and MariaDB 10.0
Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier and MariaDB 10.0.x before 10.0.25 and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to InnoDB.
nvd
CVE-2020-2654P4LOWCVSS 3.7v6.0v7.0+1 more2020-01-15
CVE-2020-2654 [LOW] CVE-2020-2654: Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions th
Vulnerability in the Java SE product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized a
nvd
CVE-2012-3166P4MEDIUMCVSS 4.0v6.02012-10-17
CVE-2012-3166 [MEDIUM] CVE-2012-3166: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2012-0041P4MEDIUMCVSS 4.3v52012-04-11
CVE-2012-0041 [MEDIUM] CWE-20 CVE-2012-0041: The dissect_packet function in epan/packet.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5
The dissect_packet function in epan/packet.c in Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 allows remote attackers to cause a denial of service (application crash) via a long packet in a capture file, as demonstrated by an airopeek file.
nvd
CVE-2010-4161P4MEDIUMCVSS 4.9v52010-12-30
CVE-2010-4161 [MEDIUM] CVE-2010-4161: The udp_queue_rcv_skb function in net/ipv4/udp.c in a certain Red Hat build of the Linux kernel 2.6.
The udp_queue_rcv_skb function in net/ipv4/udp.c in a certain Red Hat build of the Linux kernel 2.6.18 in Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (deadlock and system hang) by sending UDP traffic to a socket that has a crafted socket filter, a related issue to CVE-2010-4158.
nvd
CVE-2014-8867P4MEDIUMCVSS 4.9v5.02014-12-01
CVE-2014-8867 [MEDIUM] CWE-17 CVE-2014-8867: The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks prope
The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) via unspecified vectors.
nvd
CVE-2013-4296P4MEDIUMCVSS 4.0v6.02013-09-30
CVE-2013-4296 [MEDIUM] CWE-119 CVE-2013-4296: The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0
The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.2.8, 1.0.x before 1.0.5.6, and 1.1.x before 1.1.2 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via a crafted RPC call.
nvd
CVE-2019-19062P4MEDIUMCVSS 4.7v7.0v8.02019-11-18
CVE-2019-19062 [MEDIUM] CWE-401 CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel throu
A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
nvd
CVE-2015-4862P4MEDIUMCVSS 4.0v6.0v7.02015-10-21
CVE-2015-4862 [MEDIUM] CVE-2015-4862: Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to DML.
nvd
CVE-2013-4485P4MEDIUMCVSS 4.0v6.02013-11-23
CVE-2013-4485 [MEDIUM] CWE-20 CVE-2013-4485: 389 Directory Server 1.2.11.15 (aka Red Hat Directory Server before 8.2.11-14) allows remote authent
389 Directory Server 1.2.11.15 (aka Red Hat Directory Server before 8.2.11-14) allows remote authenticated users to cause a denial of service (crash) via multiple @ characters in a GER attribute list in a search request.
nvd
CVE-2023-4732P4MEDIUMCVSS 4.7v8.02023-10-03
CVE-2023-4732 [MEDIUM] CWE-366 CVE-2023-4732: A flaw was found in pfn_swap_entry_to_page in memory management subsystem in the Linux Kernel. In th
A flaw was found in pfn_swap_entry_to_page in memory management subsystem in the Linux Kernel. In this flaw, an attacker with a local user privilege may cause a denial of service problem due to a BUG statement referencing pmd_t x.
nvd
CVE-2013-4326P4MEDIUMCVSS 4.6v6.02013-10-03
CVE-2013-4326 [MEDIUM] CVE-2013-4326: RealtimeKit (aka rtkit) 0.5 does not properly use D-Bus for communication with a polkit authority, w
RealtimeKit (aka rtkit) 0.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
nvd
CVE-2016-0610P4LOWCVSS 3.5v6.0v7.02016-01-21
CVE-2016-0610 [LOW] CVE-2016-0610: Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x b
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
nvd
CVE-2021-3802P4MEDIUMCVSS 4.2v8.02021-11-29
CVE-2021-3802 [MEDIUM] CWE-20 CVE-2021-3802: A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image fi
A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.
nvd
CVE-2021-3635P4MEDIUMCVSS 4.4v6.0v7.0+1 more2021-08-13
CVE-2021-3635 [MEDIUM] CWE-119 CVE-2021-3635: A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user w
A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able to panic the system when issuing netfilter netflow commands.
nvd