Redhat Enterprise Linux vulnerabilities
1,864 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159
Vulnerabilities
Page 90 of 94
CVE-2019-2789P4LOWCVSS 2.7v8.02019-07-23
CVE-2019-2789 [LOW] CVE-2019-2789: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privile
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthor
nvd
CVE-2021-3655P4LOWCVSS 3.3v8.02021-08-05
CVE-2021-3655 [LOW] CWE-909 CVE-2021-3655: A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validatio
A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP packets may allow the kernel to read uninitialized memory.
nvd
CVE-2024-1048P4LOWCVSS 3.3v8.0v9.02024-02-06
CVE-2024-1048 [LOW] CVE-2024-1048: A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-
A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may fill the filesystem when invoked multiple times,
nvd
CVE-2022-0987P4LOWCVSS 3.3v9.02022-06-28
CVE-2022-0987 [LOW] CWE-200 CVE-2022-0987: A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface e
A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This issue allows a local user to measure the time the methods take to execute and know whether a file owned by root or other users exists.
nvd
CVE-2021-20239P4LOWCVSS 3.3v5.0v6.0+1 more2021-05-28
CVE-2021-20239 [LOW] CWE-822 CVE-2021-20239: A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows
A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a local account to leak information about kernel internal addresses. The highest threat from this vulnerability is to confidentiality.
nvd
CVE-2021-3716P4LOWCVSS 3.1v8.02022-03-02
CVE-2021-3716 [LOW] CWE-924 CVE-2021-3716: A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encrypti
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session. The highest threat from this vulnerab
nvd
CVE-2019-10155P4LOWCVSS 3.1v8.02019-06-12
CVE-2019-10155 [LOW] CWE-354 CVE-2019-10155: The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange pa
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted and integrity protected using the established IKE SA encryption and integrity keys, but as a receiver, the integrity check value was not verified. This issue affects versions before 3.29.
nvd
CVE-2026-0968P4LOWCVSS 3.1v9.0v10.02026-03-26
CVE-2026-0968 [LOW] CWE-476 CVE-2026-0968: A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a malformed 'longname' field within an `SSH_FXP_NAME` message during a file listing operation. This missing null check can lead to reading beyond allocated memory on the heap. This can cause unexpected behavior or lead to a denial of servi
nvd
CVE-2015-5281P4LOWCVSS 2.6v7.02015-11-24
CVE-2015-5281 [LOW] CWE-264 CVE-2015-5281: The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems,
The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and exe
nvd
CVE-2007-0771P4MEDIUMCVSS 4.9v5.02007-05-02
CVE-2007-0771 [MEDIUM] CVE-2007-0771: The utrace support in Linux kernel 2.6.18, and other versions, allows local users to cause a denial
The utrace support in Linux kernel 2.6.18, and other versions, allows local users to cause a denial of service (system hang) related to "MT exec + utrace_attach spin failure mode," as demonstrated by ptrace-thrash.c.
nvd
CVE-2007-4574P4MEDIUMCVSS 4.7v5.02007-10-23
CVE-2007-4574 [MEDIUM] CVE-2007-4574: Unspecified vulnerability in the "stack unwinder fixes" in kernel in Red Hat Enterprise Linux 5, whe
Unspecified vulnerability in the "stack unwinder fixes" in kernel in Red Hat Enterprise Linux 5, when running on AMD64 and Intel 64, allows local users to cause a denial of service via unknown vectors.
nvd
CVE-2005-3631P4MEDIUMCVSS 4.6v4.02005-12-22
CVE-2005-3631 [MEDIUM] CWE-264 CVE-2005-3631: udev does not properly set permissions on certain files in /dev/input, which allows local users to o
udev does not properly set permissions on certain files in /dev/input, which allows local users to obtain sensitive data that is entered at the console, such as user passwords.
nvd
CVE-2007-0773P4MEDIUMCVSS 4.6v4.42007-06-26
CVE-2007-0773 [MEDIUM] CVE-2007-0773: The Linux kernel before 2.6.9-42.0.8 in Red Hat 4.4 allows local users to cause a denial of service
The Linux kernel before 2.6.9-42.0.8 in Red Hat 4.4 allows local users to cause a denial of service (kernel OOPS from null dereference) via fput in a 32-bit ioctl on 64-bit x86 systems, an incomplete fix of CVE-2005-3044.1.
nvd
CVE-2004-0812P4LOWCVSS 2.1v3.02005-04-14
CVE-2004-0812 [LOW] CVE-2004-0812: Unknown vulnerability in the Linux kernel before 2.4.23, on the AMD AMD64 and Intel EM64T architectu
Unknown vulnerability in the Linux kernel before 2.4.23, on the AMD AMD64 and Intel EM64T architectures, associated with "setting up TSS limits," allows local users to cause a denial of service (crash) and possibly execute arbitrary code.
nvd
CVE-2009-3556P4LOWCVSS 1.9v52010-01-27
CVE-2009-3556 [LOW] CWE-264 CVE-2009-3556: A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat En
A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete files under /sys/class/scsi_host/, which allows local users to make arbitrary changes to SCSI host
nvd
CVE-2013-0200P4LOWCVSS 1.9v6.02013-03-06
CVE-2013-0200 [LOW] CVE-2013-0200: HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files
HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.
nvd
CVE-2019-2449P4LOWCVSS 3.1v8.02019-01-16
CVE-2019-2449 [LOW] CVE-2019-2449: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). The supported v
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). The supported version that is affected is Java SE: 8u192. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker. Succ
nvd
CVE-2019-2535P4MEDIUMCVSS 4.1v8.02019-01-16
CVE-2019-2535 [MEDIUM] CVE-2019-2535: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Support
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 8.0.13 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result i
nvd
CVE-2020-27771P4LOWCVSS 3.3v5.0v6.0+1 more2020-12-04
CVE-2020-27771 [LOW] CWE-190 CVE-2020-27771: In RestoreMSCWarning() of /coders/pdf.c there are several areas where calls to GetPixelIndex() could
In RestoreMSCWarning() of /coders/pdf.c there are several areas where calls to GetPixelIndex() could result in values outside the range of representable for the unsigned char type. The patch casts the return value of GetPixelIndex() to ssize_t type to avoid this bug. This undefined behavior could be triggered when ImageMagick processes a crafted pdf fi
nvd
CVE-2020-27767P4LOWCVSS 3.3v5.0v6.0+1 more2020-12-04
CVE-2020-27767 [LOW] CWE-190 CVE-2020-27767: A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of types `float` and `unsigned char`. This would most likely lead to an impact to application availability, but could potentially cause other problems r
nvd