cbcvebase.

Redhat Enterprise Linux vulnerabilities

1,864 known vulnerabilities affecting redhat/enterprise_linux.

Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159

Vulnerabilities

Page 92 of 94
CVE-2011-1182P4LOWCVSS 3.6v5.02013-03-01
CVE-2011-1182 [LOW] CVE-2011-1182: kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a s kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call.
nvd
CVE-2014-3917P4LOWCVSS 3.3v5v6.02014-06-05
CVE-2014-3917 [LOW] CWE-200 CVE-2014-3917: kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certai kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a large value of a syscall number.
nvd
CVE-2023-2602P4LOWCVSS 3.3v6.0v7.0+2 more2023-06-06
CVE-2023-2602 [LOW] CWE-401 CVE-2023-2602: A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicio A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.
nvd
CVE-2013-0222P4LOWCVSS 2.1v6.02013-11-23
CVE-2013-0222 [LOW] CWE-119 CVE-2013-0222: The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the uniq command, which triggers a stack-based buffer overflow in the alloca function.
nvd
CVE-2012-1568P4LOWCVSS 1.9v5v6.02013-03-01
CVE-2012-1568 [LOW] CVE-2012-1568: The ExecShield feature in a certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux ( The ExecShield feature in a certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 5 and 6 and Fedora 15 and 16 does not properly handle use of many shared libraries by a 32-bit executable file, which makes it easier for context-dependent attackers to bypass the ASLR protection mechanism by leveraging a predictable base address for one of
nvd
CVE-2003-0986P4LOWCVSS 1.7v3.02003-12-31
CVE-2003-0986 [LOW] CVE-2003-0986: Various routines for the ppc64 architecture on Linux kernel 2.6 prior to 2.6.2 and 2.4 prior to 2.4. Various routines for the ppc64 architecture on Linux kernel 2.6 prior to 2.6.2 and 2.4 prior to 2.4.24 do not use the copy_from_user function when copying data from userspace to kernelspace, which crosses security boundaries and allows local users to cause a denial of service.
nvd
CVE-2012-6655P4LOWCVSS 3.3v7.02019-11-27
CVE-2012-6655 [LOW] CWE-732 CVE-2012-6655: An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.
nvd
CVE-2014-0249P4LOWCVSS 3.3v5v6.02014-06-11
CVE-2014-0249 [LOW] CWE-264 CVE-2014-0249: The System Security Services Daemon (SSSD) 1.11.6 does not properly identify group membership when a The System Security Services Daemon (SSSD) 1.11.6 does not properly identify group membership when a non-POSIX group is in a group membership chain, which allows local users to bypass access restrictions via unspecified vectors.
nvd
CVE-2020-25743P4LOWCVSS 3.2v7.0v8.02020-10-06
CVE-2020-25743 [LOW] CWE-476 CVE-2020-25743: hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.
nvd
CVE-2021-20286P4LOWCVSS 2.7v8.3.02021-03-15
CVE-2021-20286 [LOW] CWE-617 CVE-2021-20286: A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service.
nvd
CVE-2019-2814P4LOWCVSS 2.2v8.02019-07-23
CVE-2019-2814 [LOW] CVE-2019-2814: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.16 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert
nvd
CVE-2021-3923P4LOWCVSS 2.3v6.0v7.0+1 more2023-03-27
CVE-2021-3923 [LOW] CWE-200 CVE-2021-3923: A flaw was found in the Linux kernel's implementation of RDMA over infiniband. An attacker with a pr A flaw was found in the Linux kernel's implementation of RDMA over infiniband. An attacker with a privileged local account can leak kernel stack information when issuing commands to the /dev/infiniband/rdma_cm device node. While this access is unlikely to leak sensitive user information, it can be further used to defeat existing kernel protection mechani
nvd
CVE-2005-0077P4LOWCVSS 2.1v4.02005-05-02
CVE-2005-0077 [LOW] CVE-2005-0077: The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
nvd
CVE-2005-0207P4LOWCVSS 2.1v4.02005-05-02
CVE-2005-0207 [LOW] CVE-2005-0207: Unknown vulnerability in Linux kernel 2.4.x, 2.5.x, and 2.6.x allows NFS clients to cause a denial o Unknown vulnerability in Linux kernel 2.4.x, 2.5.x, and 2.6.x allows NFS clients to cause a denial of service via O_DIRECT.
nvd
CVE-2005-2100P4LOWCVSS 2.1v4.02005-10-25
CVE-2005-2100 [LOW] CVE-2005-2100: The rw_vm function in usercopy.c in the 4GB split patch for the Linux kernel in Red Hat Enterprise L The rw_vm function in usercopy.c in the 4GB split patch for the Linux kernel in Red Hat Enterprise Linux 4 does not perform proper bounds checking, which allows local users to cause a denial of service (crash).
nvd
CVE-2005-0092P4LOWCVSS 2.1v4.02005-02-19
CVE-2005-0092 [LOW] CVE-2005-0092: Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem kernel, allows local users to cause a denial of service (crash).
nvd
CVE-2006-3813P4LOWCVSS 2.1v4.02006-08-11
CVE-2006-3813 [LOW] CVE-2006-3813: A regression error in the Perl package for Red Hat Enterprise Linux 4 omits the patch for CVE-2005-0 A regression error in the Perl package for Red Hat Enterprise Linux 4 omits the patch for CVE-2005-0155, which allows local users to overwrite arbitrary files with debugging information.
nvd
CVE-2004-0491P4LOWCVSS 2.1v3.02004-12-31
CVE-2004-0491 [LOW] CVE-2004-0491: The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit.
nvd
CVE-2007-3849P4LOWCVSS 1.9v5.02007-09-05
CVE-2007-3849 [LOW] CWE-264 CVE-2007-3849: Red Hat Enterprise Linux (RHEL) 5 ships the rpm for the Advanced Intrusion Detection Environment (AI Red Hat Enterprise Linux (RHEL) 5 ships the rpm for the Advanced Intrusion Detection Environment (AIDE) before 0.13.1 with a database that lacks checksum information, which allows context-dependent attackers to bypass file integrity checks and modify certain files.
nvd
CVE-2016-4983P4LOWCVSS 3.3v4.0v5.0+2 more2019-11-05
CVE-2016-4983 [LOW] CWE-732 CVE-2016-4983: A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
nvd
Redhat Enterprise Linux vulnerabilities | cvebase