Redhat Enterprise Linux vulnerabilities
1,864 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159
Vulnerabilities
Page 88 of 94
CVE-2008-2944P4MEDIUMCVSS 4.9v5.02008-06-30
CVE-2008-2944 [MEDIUM] CVE-2008-2944: Double free vulnerability in the utrace support in the Linux kernel, probably 2.6.18, in Red Hat Ent
Double free vulnerability in the utrace support in the Linux kernel, probably 2.6.18, in Red Hat Enterprise Linux (RHEL) 5 and Fedora Core 6 (FC6) allows local users to cause a denial of service (oops), as demonstrated by a crash when running the GNU GDB testsuite, a different vulnerability than CVE-2008-2365.
nvd
CVE-2007-6283P4MEDIUMCVSS 4.9v5.02007-12-18
CVE-2007-6283 [MEDIUM] CWE-200 CVE-2007-6283: Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permis
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.
nvd
CVE-2007-5001P4MEDIUMCVSS 4.9vas_3ves_3+1 more2008-05-08
CVE-2007-5001 [MEDIUM] CWE-399 CVE-2007-5001: Linux kernel before 2.4.21 allows local users to cause a denial of service (kernel panic) via asynch
Linux kernel before 2.4.21 allows local users to cause a denial of service (kernel panic) via asynchronous input or output on a FIFO special file.
nvd
CVE-2007-2030P4MEDIUMCVSS 4.9v2.1v3.0+1 more2007-04-16
CVE-2007-2030 [MEDIUM] CVE-2007-2030: lharc.c in lha does not securely create temporary files, which might allow local users to read or wr
lharc.c in lha does not securely create temporary files, which might allow local users to read or write files by creating a file before LHA is invoked.
nvd
CVE-2011-3585P4MEDIUMCVSS 4.7v4.0v5.0+1 more2019-12-31
CVE-2011-3585 [MEDIUM] CWE-362 CVE-2011-3585: Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local
Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local users to cause a denial of service (mounting outage) via a SIGKILL signal during a time window when the /etc/mtab~ file exists.
nvd
CVE-2019-19068P4MEDIUMCVSS 4.6v7.0v8.02019-11-18
CVE-2019-19068 [MEDIUM] CWE-401 CVE-2019-19068: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl
A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.
nvd
CVE-2005-0003P4LOWCVSS 2.1v3.02005-04-14
CVE-2005-0003 [LOW] CVE-2005-0003: The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly
The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.
nvd
CVE-2019-19072P4MEDIUMCVSS 4.4v8.02019-11-18
CVE-2019-19072 [MEDIUM] CWE-401 CVE-2019-19072: A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux k
A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-96c5c6e6a5b6.
nvd
CVE-2019-2945P4LOWCVSS 3.1v8.02019-10-16
CVE-2019-2945 [LOW] CVE-2019-2945: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Su
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2019-16231P4MEDIUMCVSS 4.1v7.0v8.02019-09-11
CVE-2019-16231 [MEDIUM] CWE-476 CVE-2019-16231: drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return va
drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
nvd
CVE-2024-45615P4LOWCVSS 3.9v7.0v8.0+1 more2024-09-03
CVE-2024-45615 [LOW] CWE-457 CVE-2024-45615: A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK.
The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).
nvd
CVE-2016-1000033P4LOWCVSS 3.7v7.02016-10-25
CVE-2016-1000033 [LOW] CWE-295 CVE-2016-1000033: Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification valid
Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.
nvd
CVE-2016-0607P4LOWCVSS 2.8v6.0v7.02016-01-21
CVE-2016-0607 [LOW] CVE-2016-0607: Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated u
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to replication.
nvd
CVE-2012-0787P4LOWCVSS 3.7v6.02013-11-23
CVE-2012-0787 [LOW] CVE-2012-0787: The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and E
The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on the (1) .augsave or (2) destination file when using the backup save option, or (3) .augnew file when using the ne
nvd
CVE-2012-3359P4LOWCVSS 3.7v52014-03-31
CVE-2012-3359 [LOW] CWE-255 CVE-2012-3359: Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac
Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.
nvd
CVE-2012-4289P4LOWCVSS 3.3v52012-08-16
CVE-2012-4289 [LOW] CWE-399 CVE-2012-4289: epan/dissectors/packet-afp.c in the AFP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6
epan/dissectors/packet-afp.c in the AFP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a large number of ACL entries.
nvd
CVE-2012-4291P4LOWCVSS 3.3v52012-08-16
CVE-2012-4291 [LOW] CWE-399 CVE-2012-4291: The CIP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allo
The CIP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.
nvd
CVE-2012-4290P4LOWCVSS 3.3v52012-08-16
CVE-2012-4290 [LOW] CWE-399 CVE-2012-4290: The CTDB dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 all
The CTDB dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a malformed packet.
nvd
CVE-2018-16866P4LOWCVSS 3.3v7.62019-01-11
CVE-2018-16866 [LOW] CWE-125 CVE-2018-16866: An out of bounds read was discovered in systemd-journald in the way it parses log messages that term
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.
nvd
CVE-2015-2877P4LOWCVSS 3.3v4.0v5.0+2 more2017-03-03
CVE-2015-2877 [LOW] CWE-200 CVE-2015-2877: Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write
Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) attack. NOTE: the vendor states "Basically if you care about this attack vector, disable deduplica
nvd