cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,864 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159

Vulnerabilities

Page 85 of 94
CVE-2023-3212P4MEDIUMCVSS 4.4v8.0v9.02023-06-23
CVE-2023-3212 [MEDIUM] CWE-476 CVE-2023-3212: A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileged local user could use this flaw to cause a kernel panic.
nvd
CVE-2004-0421P4MEDIUMCVSS 5.0v2.1v3.02004-08-18
CVE-2004-0421 [MEDIUM] CWE-125 CVE-2004-0421: The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.
nvd
CVE-2023-4535P4LOWCVSS 3.8v9.02023-11-06
CVE-2023-4535 [LOW] CWE-125 CVE-2023-4535: An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handli An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized ac
nvd
CVE-2022-41862P4LOWCVSS 3.7v8.02023-03-03
CVE-2022-41862 [LOW] CWE-200 CVE-2022-41862: In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establi In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.
nvd
CVE-2026-0989P4LOWCVSS 3.7v6.0v7.0+3 more2026-01-15
CVE-2026-0989 [LOW] CWE-674 CVE-2026-0989: A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating
nvd
CVE-2006-4342P4MEDIUMCVSS 5.5v3.02006-10-17
CVE-2006-4342 [MEDIUM] CWE-667 CVE-2006-4342: The kernel in Red Hat Enterprise Linux 3, when running on SMP systems, allows local users to cause a The kernel in Red Hat Enterprise Linux 3, when running on SMP systems, allows local users to cause a denial of service (deadlock) by running the shmat function on an shm at the same time that shmctl is removing that shm (IPC_RMID), which prevents a spinlock from being unlocked.
nvd
CVE-2011-3637P4MEDIUMCVSS 5.5v6.02012-05-17
CVE-2011-3637 [MEDIUM] CWE-476 CVE-2011-3637: The m_stop function in fs/proc/task_mmu.c in the Linux kernel before 2.6.39 allows local users to ca The m_stop function in fs/proc/task_mmu.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (OOPS) via vectors that trigger an m_start error.
nvd
CVE-2016-0661P4MEDIUMCVSS 4.7v6.0v7.02016-04-21
CVE-2016-0661 [MEDIUM] CVE-2016-0661: Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local use Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Options.
nvd
CVE-2019-2988P4LOWCVSS 3.7v8.02019-10-16
CVE-2019-2988 [LOW] CVE-2019-2988: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks o
nvd
CVE-2019-2978P4LOWCVSS 3.7v8.02019-10-16
CVE-2019-2978 [LOW] CVE-2019-2978: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Su Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2006-7226P4MEDIUMCVSS 4.3v4.02007-12-03
CVE-2006-7226 [MEDIUM] CVE-2006-7226: Perl-Compatible Regular Expression (PCRE) library before 6.7 does not properly calculate the compile Perl-Compatible Regular Expression (PCRE) library before 6.7 does not properly calculate the compiled memory allocation for regular expressions that involve a quantified "subpattern containing a named recursion or subroutine reference," which allows context-dependent attackers to cause a denial of service (error or crash).
nvd
CVE-2019-16994P4MEDIUMCVSS 4.7v7.02019-09-30
CVE-2019-16994 [MEDIUM] CWE-401 CVE-2019-16994: In the Linux kernel before 5.0, a memory leak exists in sit_init_net() in net/ipv6/sit.c when regist In the Linux kernel before 5.0, a memory leak exists in sit_init_net() in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev, which may cause denial of service, aka CID-07f12b26e21a.
nvd
CVE-2019-15807P4MEDIUMCVSS 4.7v7.0v8.02019-08-29
CVE-2019-15807 [MEDIUM] CWE-401 CVE-2019-15807: In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c when In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c when SAS expander discovery fails. This will cause a BUG and denial of service.
nvd
CVE-2013-2188P4MEDIUMCVSS 4.7v6.02013-07-16
CVE-2013-2188 [MEDIUM] CWE-264 CVE-2013-2188: A certain Red Hat patch to the do_filp_open function in fs/namei.c in the kernel package before 2.6. A certain Red Hat patch to the do_filp_open function in fs/namei.c in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle failure to obtain write permissions, which allows local users to cause a denial of service (system crash) by leveraging access to a filesystem that is mounted read-only.
nvd
CVE-2006-2933P4MEDIUMCVSS 4.6v3.02006-07-27
CVE-2006-2933 [MEDIUM] CVE-2006-2933: kdesktop_lock in kdebase before 3.1.3-5.11 for KDE in Red Hat Enterprise Linux (RHEL) 3 does not pro kdesktop_lock in kdebase before 3.1.3-5.11 for KDE in Red Hat Enterprise Linux (RHEL) 3 does not properly terminate, which can prevent the screensaver from activating or prevent users from manually locking the desktop.
nvd
CVE-2008-1951P4MEDIUMCVSS 4.6v4v52008-06-25
CVE-2008-1951 [MEDIUM] CWE-264 CVE-2008-1951: Untrusted search path vulnerability in a certain Red Hat build script for Standards Based Linux Inst Untrusted search path vulnerability in a certain Red Hat build script for Standards Based Linux Instrumentation for Manageability (sblim) libraries before 1-13a.el4_6.1 in Red Hat Enterprise Linux (RHEL) 4, and before 1-31.el5_2.1 in RHEL 5, allows local users to gain privileges via a malicious library in a certain subdirectory of /var/tmp, related to
nvd
CVE-2020-25639P4MEDIUMCVSS 4.4v5.0v6.0+2 more2021-03-04
CVE-2020-25639 [MEDIUM] CWE-476 CVE-2020-25639: A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local user to crash the system.
nvd
CVE-2023-7192P4MEDIUMCVSS 4.4v8.0v9.02024-01-02
CVE-2023-7192 [MEDIUM] CWE-401 CVE-2023-7192: A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink. A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to cause a denial of service (DoS) attack due to a refcount overflow.
nvd
CVE-2019-2786P4LOWCVSS 3.4v8.02019-07-23
CVE-2019-2786 [LOW] CVE-2019-2786: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2019-14850P4LOWCVSS 3.7v8.02021-03-18
CVE-2019-14850 [LOW] CWE-406 CVE-2019-14850: A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker co A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and degradation of service in nbdkit, dep
nvd
Redhat Enterprise Linux vulnerabilities | cvebase