cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,864 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159

Vulnerabilities

Page 87 of 94
CVE-2011-1593P4MEDIUMCVSS 4.9v5.02011-05-03
CVE-2011-1593 [MEDIUM] CWE-190 CVE-2011-1593: Multiple integer overflows in the next_pidmap function in kernel/pid.c in the Linux kernel before 2. Multiple integer overflows in the next_pidmap function in kernel/pid.c in the Linux kernel before 2.6.38.4 allow local users to cause a denial of service (system crash) via a crafted (1) getdents or (2) readdir system call.
nvd
CVE-2012-2697P4MEDIUMCVSS 4.9v52013-02-24
CVE-2012-2697 [MEDIUM] CWE-20 CVE-2012-2697: Unspecified vulnerability in autofs, as used in Red Hat Enterprise Linux (RHEL) 5, allows local user Unspecified vulnerability in autofs, as used in Red Hat Enterprise Linux (RHEL) 5, allows local users to cause a denial of service (autofs crash and delayed mounts) or prevent "mount expiration" via unspecified vectors related to "using an LDAP-based automount map."
nvd
CVE-2008-1615P4MEDIUMCVSS 4.9vas_4ves_4+1 more2008-05-08
CVE-2008-1615 [MEDIUM] CWE-399 CVE-2008-1615: Linux kernel 2.6.18, and possibly other versions, when running on AMD64 architectures, allows local Linux kernel 2.6.18, and possibly other versions, when running on AMD64 architectures, allows local users to cause a denial of service (crash) via certain ptrace calls.
nvd
CVE-2013-0309P4MEDIUMCVSS 4.7v6.02013-02-22
CVE-2013-0309 [MEDIUM] CWE-119 CVE-2013-0309: arch/x86/include/asm/pgtable.h in the Linux kernel before 3.6.2, when transparent huge pages are use arch/x86/include/asm/pgtable.h in the Linux kernel before 3.6.2, when transparent huge pages are used, does not properly support PROT_NONE memory regions, which allows local users to cause a denial of service (system crash) via a crafted application.
nvd
CVE-2008-0595P4MEDIUMCVSS 4.6v5v5.02008-02-29
CVE-2008-0595 [MEDIUM] CWE-863 CVE-2008-0595: dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.
nvd
CVE-2019-2797P4MEDIUMCVSS 4.2v8.02019-07-23
CVE-2019-2797 [MEDIUM] CVE-2019-2797: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Server executes to compromise
nvd
CVE-2022-0168P4MEDIUMCVSS 4.4v8.0v9.02022-08-26
CVE-2022-0168 [MEDIUM] CWE-476 CVE-2022-0168: A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in th A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet File System (CIFS) due to an incorrect return from the memdup_user function. This flaw allows a local, privileged (CAP_SYS_ADMIN) attacker to crash the system.
nvd
CVE-2019-2422P4LOWCVSS 3.1v8.02019-01-16
CVE-2019-2422 [LOW] CVE-2019-2422: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versio Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction fr
nvd
CVE-2019-12614P4MEDIUMCVSS 4.1v7.0v8.02019-06-03
CVE-2019-12614 [MEDIUM] CWE-476 CVE-2019-12614: An issue was discovered in dlpar_parse_cc_property in arch/powerpc/platforms/pseries/dlpar.c in the An issue was discovered in dlpar_parse_cc_property in arch/powerpc/platforms/pseries/dlpar.c in the Linux kernel through 5.1.6. There is an unchecked kstrdup of prop->name, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash).
nvd
CVE-2019-16229P4MEDIUMCVSS 4.1v7.0v8.02019-09-11
CVE-2019-16229 [MEDIUM] CWE-476 CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14 does not check the alloc_workq drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: The security community disputes this issues as not being serious enough to be deserving a CVE id
nvd
CVE-2011-3346P4MEDIUMCVSS 4.0v52014-04-01
CVE-2011-3346 [MEDIUM] CWE-119 CVE-2011-3346: Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command. NOTE: this is only a vulnerability when root has manually modified certain permissions or ACLs.
nvd
CVE-2013-1774P4MEDIUMCVSS 4.0v6.02013-02-28
CVE-2013-1774 [MEDIUM] CWE-264 CVE-2013-1774: The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local users to cause a denial of service (NULL pointer dereference and system crash) via an attempted /dev/ttyUSB read or write operation on a disconnected Edgeport USB serial converter.
nvd
CVE-2016-0643P4LOWCVSS 3.3v6.0v7.02016-04-21
CVE-2016-0643 [LOW] CVE-2016-0643: Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and ear Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect confidentiality via vectors related to DML.
nvd
CVE-2015-6815P4LOWCVSS 3.5v5.0v6.0+1 more2020-01-31
CVE-2015-6815 [LOW] CWE-835 CVE-2015-6815: The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process tran The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.
nvd
CVE-2013-0219P4LOWCVSS 3.7v5v6.02013-02-24
CVE-2013-0219 [LOW] CWE-264 CVE-2013-0219: System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.
nvd
CVE-2005-0109P4MEDIUMCVSS 5.6v2.1v3.0+1 more2005-03-05
CVE-2005-0109 [MEDIUM] CVE-2005-0109: Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pen Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.
nvd
CVE-2016-0605P4LOWCVSS 2.1v6.0v7.02016-01-21
CVE-2016-0605 [LOW] CVE-2016-0605: Unspecified vulnerability in Oracle MySQL 5.6.26 and earlier allows remote authenticated users to af Unspecified vulnerability in Oracle MySQL 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors.
nvd
CVE-2003-0548P4MEDIUMCVSS 5.0v2.12003-08-27
CVE-2003-0548 [MEDIUM] CVE-2003-0548: The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to ca The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.
nvd
CVE-2004-1174P4MEDIUMCVSS 5.0v2.12005-04-14
CVE-2004-1174 [MEDIUM] CVE-2004-1174: direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of servi direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."
nvd
CVE-2026-0992P4LOWCVSS 2.9v6.0v7.0+3 more2026-01-15
CVE-2026-0992 [LOW] CWE-400 CVE-2026-0992: A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU c
nvd