Redhat Enterprise Linux vulnerabilities
1,738 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,738
CISA KEV
20
actively exploited
Public exploits
88
Exploited in wild
26
Severity breakdown
CRITICAL157HIGH589MEDIUM839LOW153
Vulnerabilities
Page 87 of 87
CVE-2004-0557CRITICALCVSS 10.0PoCv3.02004-08-06
CVE-2004-0557 [CRITICAL] CVE-2004-0557: Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.
nvd
CVE-2004-0495HIGHCVSS 7.2v2.1v3.02004-08-06
CVE-2004-0495 [HIGH] CVE-2004-0495: Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or
Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.
nvd
CVE-2004-0554LOWCVSS 2.1PoCv2.1v3.02004-08-06
CVE-2004-0554 [LOW] CVE-2004-0554: Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash),
Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.
nvd
CVE-2004-0111MEDIUMCVSS 5.0v2.1v3.02004-04-15
CVE-2004-0111 [MEDIUM] CVE-2004-0111: gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap
gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.
nvd
CVE-2004-0105HIGHCVSS 7.5v2.12004-03-03
CVE-2004-0105 [HIGH] CVE-2004-0105: Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary co
Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.
nvd
CVE-2004-0104HIGHCVSS 7.5PoCv2.12004-03-03
CVE-2004-0104 [HIGH] CVE-2004-0104: Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute
Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.
nvd
CVE-2003-0857MEDIUMCVSS 4.6v2.1v3.02003-12-31
CVE-2003-0857 [MEDIUM] CWE-264 CVE-2003-0857: The (1) ipq_read and (2) ipulog_read functions in iptables allow local users to cause a denial of se
The (1) ipq_read and (2) ipulog_read functions in iptables allow local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
nvd
CVE-2003-1295LOWCVSS 2.1v3.02003-12-31
CVE-2003-1295 [LOW] CVE-2003-1295: Unspecified vulnerability in xscreensaver 4.12, and possibly other versions, allows attackers to cau
Unspecified vulnerability in xscreensaver 4.12, and possibly other versions, allows attackers to cause xscreensaver to crash via unspecified vectors "while verifying the user-password."
nvd
CVE-2003-0986LOWCVSS 1.7v3.02003-12-31
CVE-2003-0986 [LOW] CVE-2003-0986: Various routines for the ppc64 architecture on Linux kernel 2.6 prior to 2.6.2 and 2.4 prior to 2.4.
Various routines for the ppc64 architecture on Linux kernel 2.6 prior to 2.6.2 and 2.4 prior to 2.4.24 do not use the copy_from_user function when copying data from userspace to kernelspace, which crosses security boundaries and allows local users to cause a denial of service.
nvd
CVE-2003-0859MEDIUMCVSS 4.9v2.1v3.02003-12-15
CVE-2003-0859 [MEDIUM] CVE-2003-0859: The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial o
The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
nvd
CVE-2003-0689HIGHCVSS 7.5v2.12003-10-20
CVE-2003-0689 [HIGH] CVE-2003-0689: The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial o
The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.
nvd
CVE-2003-0699HIGHCVSS 7.5v2.12003-08-27
CVE-2003-0699 [HIGH] CVE-2003-0699: The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access use
The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0700.
nvd
CVE-2003-0548MEDIUMCVSS 5.0v2.12003-08-27
CVE-2003-0548 [MEDIUM] CVE-2003-0548: The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to ca
The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.
nvd
CVE-2003-0549MEDIUMCVSS 5.0v2.12003-08-27
CVE-2003-0549 [MEDIUM] CVE-2003-0549: The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to ca
The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.
nvd
CVE-2003-0434HIGHCVSS 7.5PoCv2.12003-07-24
CVE-2003-0434 [HIGH] CVE-2003-0434: Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to exe
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
nvd
CVE-2002-2185MEDIUMCVSS 4.9v3.0v4.02002-12-31
CVE-2002-2185 [MEDIUM] CVE-2002-2185: The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
nvd
CVE-2002-1323MEDIUMCVSS 4.6v2.12002-12-11
CVE-2002-1323 [MEDIUM] CVE-2002-1323: Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of
Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.
nvd
CVE-1999-1572LOWCVSS 2.1v4.01996-07-16
CVE-1999-1572 [LOW] CVE-1999-1572: cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask wh
cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.
nvd
← Previous87 / 87