cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,864 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159

Vulnerabilities

Page 86 of 94
CVE-2015-4890P4LOWCVSS 3.5v6.0v7.02015-10-21
CVE-2015-4890 [LOW] CVE-2015-4890: Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Replication.
nvd
CVE-2014-3940P4MEDIUMCVSS 4.0v6.02014-06-05
CVE-2014-3940 [MEDIUM] CWE-362 CVE-2014-3940: The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which al The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by triggering a race condition via numa_maps read operations during hugepage migration, related to fs/proc/task_mmu.
nvd
CVE-2024-45616P4LOWCVSS 3.9v7.0v8.0+1 more2024-09-03
CVE-2024-45616 [LOW] CWE-457 CVE-2024-45616: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following problems were caused by insufficient control of the response APDU buffer and its length when communicating with the car
nvd
CVE-2024-45617P4LOWCVSS 3.9v7.0v8.0+1 more2024-09-03
CVE-2024-45617 [LOW] CWE-457 CVE-2024-45617: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized
nvd
CVE-2024-45620P4LOWCVSS 3.9v7.0v8.0+1 more2024-09-03
CVE-2024-45620 [LOW] CWE-120 CVE-2024-45620: A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Dev A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.
nvd
CVE-2024-45618P4LOWCVSS 3.9v7.0v8.0+1 more2024-09-03
CVE-2024-45618 [LOW] CWE-457 CVE-2024-45618: A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Sm A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads to unexpected work with variables that have not been initialized.
nvd
CVE-2005-0473P4MEDIUMCVSS 5.0v4.02005-03-14
CVE-2005-0473 [MEDIUM] CVE-2005-0473: The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0208.
nvd
CVE-2026-59846P4LOWCVSS 3.9v8.0v9.0+1 more2026-07-21
CVE-2026-59846 [LOW] CWE-77 CVE-2026-59846: A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can in A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
nvd
CVE-2021-3593P4LOWCVSS 3.8v8.02021-06-15
CVE-2021-3593 [LOW] CWE-824 CVE-2021-3593: An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. Th An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest
nvd
CVE-2021-3594P4LOWCVSS 3.8v8.02021-06-15
CVE-2021-3594 [LOW] CWE-824 CVE-2021-3594: An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. Th An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest t
nvd
CVE-2021-3592P4LOWCVSS 3.8v8.02021-06-15
CVE-2021-3592 [LOW] CWE-824 CVE-2021-3592: An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. Th An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highe
nvd
CVE-2021-3595P4LOWCVSS 3.8v8.02021-06-15
CVE-2021-3595 [LOW] CWE-824 CVE-2021-3595: An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. Th An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest
nvd
CVE-2025-8283P4LOWCVSS 3.7v8.0v9.0+1 more2025-07-28
CVE-2025-8283 [LOW] CWE-15 CVE-2025-8283: A vulnerability was found in the netavark package, a network stack for containers used with Podman. A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's
nvd
CVE-2005-2492P4LOWCVSS 3.6v4.02005-09-14
CVE-2005-2492 [LOW] CWE-264 CVE-2005-2492: The raw_sendmsg function in the Linux kernel 2.6 before 2.6.13.1 allows local users to cause a denia The raw_sendmsg function in the Linux kernel 2.6 before 2.6.13.1 allows local users to cause a denial of service (change hardware state) or read from arbitrary memory via crafted input.
nvd
CVE-2004-1139P4MEDIUMCVSS 5.0v2.1v3.02004-12-15
CVE-2004-1139 [MEDIUM] CVE-2004-1139: Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attacke Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash).
nvd
CVE-2002-2185P4MEDIUMCVSS 4.9v3.0v4.02002-12-31
CVE-2002-2185 [MEDIUM] CVE-2002-2185: The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
nvd
CVE-2026-0965P4LOWCVSS 3.3v9.0v10.02026-03-26
CVE-2026-0965 [LOW] CWE-73 CVE-2026-0965: A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker can exploit this by providing a malicious configuration file or when the system is misconfigured. This vulnerability could lead to a Denial of Service (DoS) by causing the system to try and access dangerous files, such as block devices or
nvd
CVE-2004-1613P4MEDIUMCVSS 5.0v2.1v3.02004-10-18
CVE-2004-1613 [MEDIUM] CVE-2004-1613: Mozilla allows remote attackers to cause a denial of service (application crash from null dereferenc Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.
nvd
CVE-2003-0549P4MEDIUMCVSS 5.0v2.12003-08-27
CVE-2003-0549 [MEDIUM] CVE-2003-0549: The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to ca The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.
nvd
CVE-2019-2536P4MEDIUMCVSS 5.0v8.02019-01-16
CVE-2019-2536 [MEDIUM] CVE-2019-2536: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 8.0.13 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a
nvd
Redhat Enterprise Linux vulnerabilities | cvebase