cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,864 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159

Vulnerabilities

Page 91 of 94
CVE-2020-27765P4LOWCVSS 3.3v5.0v6.0+1 more2020-12-04
CVE-2020-27765 [LOW] CWE-369 CVE-2020-27765: A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that A flaw was found in ImageMagick in MagickCore/segment.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw
nvd
CVE-2020-27773P4LOWCVSS 3.3v5.0v6.0+1 more2020-12-04
CVE-2020-27773 [LOW] CWE-369 CVE-2020-27773: A flaw was found in ImageMagick in MagickCore/gem-private.h. An attacker who submits a crafted file A flaw was found in ImageMagick in MagickCore/gem-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned char` or division by zero. This would most likely lead to an impact to application availability, but could potentially cause other
nvd
CVE-2019-11884P4LOWCVSS 3.3v8.02019-05-10
CVE-2019-11884 [LOW] CVE-2019-11884: The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allow The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.
nvd
CVE-2020-35501P4LOWCVSS 3.4v7.0v8.02022-03-30
CVE-2020-35501 [LOW] CWE-863 CVE-2020-35501: A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedl A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem
nvd
CVE-2019-10183P4LOWCVSS 3.3v8.02019-07-03
CVE-2019-10183 [LOW] CWE-200 CVE-2019-10183: Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattende Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction. This option accepts guest VM password as command line arguments, thus leaking them to others users on the system via process listing. It was introduced recently in the virt-manager v2.2.0 release.
nvd
CVE-2023-1513P4LOWCVSS 3.3v7.0v8.0+1 more2023-03-23
CVE-2023-1513 [LOW] CWE-665 CVE-2023-1513: A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit systems, there might be A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit systems, there might be some uninitialized portions of the kvm_debugregs structure that could be copied to userspace, causing an information leak.
nvd
CVE-2020-14394P4LOWCVSS 3.2v5.0v6.0+3 more2022-08-17
CVE-2020-14394 [LOW] CWE-835 CVE-2020-14394: An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the len An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.
nvd
CVE-2008-3270P4LOWCVSS 2.6v5.02008-08-18
CVE-2008-3270 [LOW] CWE-310 CVE-2008-3270: yum-rhn-plugin in Red Hat Enterprise Linux (RHEL) 5 does not verify the SSL certificate for a file d yum-rhn-plugin in Red Hat Enterprise Linux (RHEL) 5 does not verify the SSL certificate for a file download from a Red Hat Network (RHN) server, which makes it easier for remote man-in-the-middle attackers to cause a denial of service (loss of updates) or force the download and installation of official Red Hat packages that were not requested.
nvd
CVE-2003-0859P4MEDIUMCVSS 4.9v2.1v3.02003-12-15
CVE-2003-0859 [MEDIUM] CVE-2003-0859: The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial o The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
nvd
CVE-2016-4980P4LOWCVSS 2.5v6.0v7.02019-11-27
CVE-2016-4980 [LOW] CWE-330 CVE-2016-4980: A password generation weakness exists in xquest through 2016-06-13. A password generation weakness exists in xquest through 2016-06-13.
nvd
CVE-2025-6170P4LOWCVSS 2.5v6.0v7.0+3 more2025-06-16
CVE-2025-6170 [LOW] CWE-121 CVE-2025-6170: A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML fil A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
nvd
CVE-2007-3099P4LOWCVSS 2.1v5.02007-06-14
CVE-2007-3099 [LOW] CVE-2007-3099: usr/mgmt_ipc.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 checks the client's UI usr/mgmt_ipc.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 checks the client's UID on the listening AF_LOCAL socket instead of the new connection, which allows remote attackers to access the management interface and cause a denial of service (iscsid exit or iSCSI connection loss).
nvd
CVE-2004-0685P4MEDIUMCVSS 4.6v3.02004-12-23
CVE-2004-0685 [MEDIUM] CVE-2004-0685: Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structure Certain USB drivers in the Linux 2.4 kernel use the copy_to_user function on uninitialized structures, which could allow local users to obtain sensitive information by reading memory that was not cleared from previous usage.
nvd
CVE-2002-1323P4MEDIUMCVSS 4.6v2.12002-12-11
CVE-2002-1323 [MEDIUM] CVE-2002-1323: Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.
nvd
CVE-2005-0078P4MEDIUMCVSS 4.6v2.1v3.02005-05-02
CVE-2005-0078 [MEDIUM] CVE-2005-0078: The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain fun The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session.
nvd
CVE-2003-0857P4MEDIUMCVSS 4.6v2.1v3.02003-12-31
CVE-2003-0857 [MEDIUM] CWE-264 CVE-2003-0857: The (1) ipq_read and (2) ipulog_read functions in iptables allow local users to cause a denial of se The (1) ipq_read and (2) ipulog_read functions in iptables allow local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
nvd
CVE-2014-0179P4LOWCVSS 1.9v6.02014-08-03
CVE-2014-0179 [LOW] CWE-20 CVE-2014-0179: libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU or (2) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this is
nvd
CVE-2013-0223P4LOWCVSS 1.9v6.02013-11-23
CVE-2013-0223 [LOW] CWE-119 CVE-2013-0223: The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the join command, when using the -i switch, which triggers a stack-based buffer overflow in the alloca function.
nvd
CVE-2012-4285P4LOWCVSS 3.3v52012-08-16
CVE-2012-4285 [LOW] CWE-189 CVE-2012-4285: The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a zero-length message.
nvd
CVE-2012-2313P4LOWCVSS 1.2v52012-06-13
CVE-2012-2313 [LOW] CWE-264 CVE-2012-2313: The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does no The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
nvd
Redhat Enterprise Linux vulnerabilities | cvebase