cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,864 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159

Vulnerabilities

Page 89 of 94
CVE-2020-1702P4LOWCVSS 3.3v8.02021-05-27
CVE-2020-1702 [LOW] CWE-400 CVE-2020-1702: A malicious container image can consume an unbounded amount of memory when being pulled to a contain A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat Enterprise Linux using podman, or OpenShift Container Platform. An attacker can use this flaw to trick a user, with privileges to pull container images, into crashing the process responsible for pulling the image. This flaw
nvd
CVE-2024-1454P4LOWCVSS 3.4v7.0v8.0+1 more2024-02-12
CVE-2024-1454 [LOW] CWE-416 CVE-2024-1454: The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in t The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker must have physical access to the computer system and requires a crafted USB device or smart card to present the system with specially crafted res
nvd
CVE-2007-1716P4LOWCVSS 3.4v4.42007-03-27
CVE-2007-1716 [LOW] CVE-2007-1716: pam_console does not properly restore ownership for certain console devices when there are multiple pam_console does not properly restore ownership for certain console devices when there are multiple users logged into the console and one user logs out, which might allow local users to gain privileges.
nvd
CVE-2004-0111P4MEDIUMCVSS 5.0v2.1v3.02004-04-15
CVE-2004-0111 [MEDIUM] CVE-2004-0111: gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.
nvd
CVE-2024-0217P4LOWCVSS 3.3v8.0v9.02024-01-03
CVE-2024-0217 [LOW] CWE-416 CVE-2024-0217: A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics f A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored data in this memory region is considered
nvd
CVE-2024-8443P4LOWCVSS 2.9v7.0v8.0+1 more2024-09-10
CVE-2024-8443 [LOW] CWE-122 CVE-2024-8443: A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` tool may lead to out-of-bound rights, possibly resulting in arbitrary code execution.
nvd
CVE-2015-4910P4LOWCVSS 2.1v6.0v7.02015-10-22
CVE-2015-4910 [LOW] CVE-2015-4910: Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Memcached.
nvd
CVE-2007-5494P4MEDIUMCVSS 4.9v4.0v5.02007-11-30
CVE-2007-5494 [MEDIUM] CWE-399 CVE-2007-5494: Memory leak in the Red Hat Content Accelerator kernel patch in Red Hat Enterprise Linux (RHEL) 4 and Memory leak in the Red Hat Content Accelerator kernel patch in Red Hat Enterprise Linux (RHEL) 4 and 5 allows local users to cause a denial of service (memory consumption) via a large number of open requests involving O_ATOMICLOOKUP.
nvd
CVE-2007-3739P4MEDIUMCVSS 4.7v5.02007-09-14
CVE-2007-3739 [MEDIUM] CWE-119 CVE-2007-3739: mm/mmap.c in the hugetlb kernel, when run on PowerPC systems, does not prevent stack expansion from mm/mmap.c in the hugetlb kernel, when run on PowerPC systems, does not prevent stack expansion from entering into reserved kernel page memory, which allows local users to cause a denial of service (OOPS) via unspecified vectors.
nvd
CVE-2019-16233P4MEDIUMCVSS 4.1v7.0v8.02019-09-11
CVE-2019-16233 [MEDIUM] CWE-476 CVE-2019-16233: drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return v drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
nvd
CVE-2005-0988P4LOWCVSS 3.7v2.1v3.0+1 more2005-05-02
CVE-2005-0988 [LOW] CVE-2005-0988: Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local us Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
nvd
CVE-2013-7347P4LOWCVSS 3.7v52014-03-31
CVE-2013-7347 [LOW] CVE-2013-7347: Luci in Red Hat Conga does not properly enforce the user session timeout, which might allow attacker Luci in Red Hat Conga does not properly enforce the user session timeout, which might allow attackers to gain access to the session by reading the __ac session cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2012-3359 for the base64-encoded storage of the user and password in a cookie.
nvd
CVE-2019-2738P4LOWCVSS 3.1v8.02019-07-23
CVE-2019-2738 [LOW] CVE-2019-2738: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Compiling). Supp Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Compiling). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2020-27775P4LOWCVSS 3.3v5.0v6.0+1 more2020-12-04
CVE-2020-27775 [LOW] CWE-190 CVE-2020-27775: A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type unsigned char. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undef
nvd
CVE-2020-27774P4LOWCVSS 3.3v5.0v6.0+1 more2020-12-04
CVE-2020-27774 [LOW] CWE-190 CVE-2020-27774: A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file th A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of a too large shift for 64-bit type `ssize_t`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefi
nvd
CVE-2020-27772P4LOWCVSS 3.3v5.0v6.0+1 more2020-12-04
CVE-2020-27772 [LOW] CWE-190 CVE-2020-27772: A flaw was found in ImageMagick in coders/bmp.c. An attacker who submits a crafted file that is proc A flaw was found in ImageMagick in coders/bmp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned int`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined be
nvd
CVE-2012-0042P4LOWCVSS 2.9v52012-04-11
CVE-2012-0042 [LOW] CVE-2012-0042: Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 does not properly perform certain string conver Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 does not properly perform certain string conversions, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet, related to epan/to_str.c.
nvd
CVE-2020-27776P4LOWCVSS 3.3v5.0v6.0+1 more2020-12-04
CVE-2020-27776 [LOW] CWE-190 CVE-2020-27776: A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file th A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type unsigned long. This would most likely lead to an impact to application availability, but could potentially cause other problems related to und
nvd
CVE-2010-0730P4LOWCVSS 2.6v5v5.02010-05-12
CVE-2010-0730 [LOW] CWE-20 CVE-2010-0730: The MMIO instruction decoder in the Xen hypervisor in the Linux kernel 2.6.18 in Red Hat Enterprise The MMIO instruction decoder in the Xen hypervisor in the Linux kernel 2.6.18 in Red Hat Enterprise Linux (RHEL) 5 allows guest OS users to cause a denial of service (32-bit guest OS crash) via vectors that trigger an unspecified instruction emulation.
nvd
CVE-2021-4217P4LOWCVSS 3.3v6.0v7.0+2 more2022-08-24
CVE-2021-4217 [LOW] CWE-476 CVE-2021-4217: A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, whi A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.
nvd
Redhat Enterprise Linux vulnerabilities | cvebase