Redhat Enterprise Linux vulnerabilities
1,864 known vulnerabilities affecting redhat/enterprise_linux.
Total CVEs
1,864
CISA KEV
23
actively exploited
Public exploits
96
Exploited in wild
44
Severity breakdown
CRITICAL167HIGH643MEDIUM895LOW159
Vulnerabilities
Page 93 of 94
CVE-2014-4027P4LOWCVSS 2.3v6.02014-06-23
CVE-2014-4027 [LOW] CWE-200 CVE-2014-4027: The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.1
The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveraging access to a SCSI initiator.
nvd
CVE-2004-0977P4LOWCVSS 2.1v3.02005-02-09
CVE-2004-0977 [LOW] CVE-2004-0977: The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files
The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files.
nvd
CVE-2005-0090P4LOWCVSS 2.1v4.02005-05-02
CVE-2005-0090 [LOW] CVE-2005-0090: A regression error in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch omits an "access che
A regression error in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch omits an "access check," which allows local users to cause a denial of service (crash).
nvd
CVE-2004-0968P4LOWCVSS 2.1v3.02005-02-09
CVE-2004-0968 [LOW] CVE-2004-0968: The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink
The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.
nvd
CVE-2005-0757P4LOWCVSS 2.1v3.02005-05-18
CVE-2005-0757 [LOW] CVE-2005-0757: The xattr file system code, as backported in Red Hat Enterprise Linux 3 on 64-bit systems, does not
The xattr file system code, as backported in Red Hat Enterprise Linux 3 on 64-bit systems, does not properly handle certain offsets, which allows local users to cause a denial of service (system crash) via certain actions on an ext3 file system with extended attributes enabled.
nvd
CVE-2003-1295P4LOWCVSS 2.1v3.02003-12-31
CVE-2003-1295 [LOW] CVE-2003-1295: Unspecified vulnerability in xscreensaver 4.12, and possibly other versions, allows attackers to cau
Unspecified vulnerability in xscreensaver 4.12, and possibly other versions, allows attackers to cause xscreensaver to crash via unspecified vectors "while verifying the user-password."
nvd
CVE-2012-6546P4LOWCVSS 1.9v5v6.02013-03-15
CVE-2012-6546 [LOW] CWE-200 CVE-2012-6546: The ATM implementation in the Linux kernel before 3.6 does not initialize certain structures, which
The ATM implementation in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
nvd
CVE-2012-6544P4LOWCVSS 1.9v5v6.02013-03-15
CVE-2012-6544 [LOW] CWE-200 CVE-2012-6544: The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain str
The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that targets the (1) L2CAP or (2) HCI implementation.
nvd
CVE-2012-6542P4LOWCVSS 1.9v5v6.02013-03-15
CVE-2012-6542 [LOW] CWE-200 CVE-2012-6542: The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 has an incorrect retu
The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 has an incorrect return value in certain circumstances, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that leverages an uninitialized pointer argument.
nvd
CVE-2013-2217P4LOWCVSS 1.2v5v6.02013-09-23
CVE-2013-2217 [LOW] CWE-59 CVE-2013-2217: cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and p
cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.
nvd
CVE-1999-1572P4LOWCVSS 2.1v4.01996-07-16
CVE-1999-1572 [LOW] CVE-1999-1572: cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask wh
cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.
nvd
CVE-2013-2164P4LOWCVSS 2.1v5v5.0+1 more2013-07-04
CVE-2013-2164 [LOW] CWE-200 CVE-2013-2164: The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux kernel through 3.10 all
The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux kernel through 3.10 allows local users to obtain sensitive information from kernel memory via a read operation on a malfunctioning CD-ROM drive.
nvd
CVE-2004-1237P4LOWCVSS 2.1v3.02005-04-14
CVE-2004-1237 [LOW] CVE-2004-1237: Unknown vulnerability in the system call filtering code in the audit subsystem for Red Hat Enterpris
Unknown vulnerability in the system call filtering code in the audit subsystem for Red Hat Enterprise Linux 3 allows local users to cause a denial of service (system crash) via unknown vectors.
nvd
CVE-2012-6545P4LOWCVSS 1.9v5v6.02013-03-15
CVE-2012-6545 [LOW] CWE-200 CVE-2012-6545: The Bluetooth RFCOMM implementation in the Linux kernel before 3.6 does not properly initialize cert
The Bluetooth RFCOMM implementation in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel memory via a crafted application.
nvd
CVE-2011-2693P4LOWCVSS 1.9v6.02013-06-08
CVE-2011-2693 [LOW] CVE-2011-2693: The perf subsystem in the kernel package 2.6.32-122.el6.x86_64 in Red Hat Enterprise Linux (RHEL) 6
The perf subsystem in the kernel package 2.6.32-122.el6.x86_64 in Red Hat Enterprise Linux (RHEL) 6 does not properly handle NMIs, which might allow local users to cause a denial of service (excessive log messages) via unspecified vectors.
nvd
CVE-2005-1038P4LOWCVSS 2.1v4.02005-05-02
CVE-2005-1038 [LOW] CVE-2005-1038: crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron file
crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron files of other users by changing the file being edited to a symlink. NOTE: there is insufficient information to know whether this is a duplicate of CVE-2001-0235.
nvd
CVE-2007-3379P4LOWCVSS 2.1v4.02007-09-17
CVE-2007-3379 [LOW] CVE-2007-3379: Unspecified vulnerability in the kernel in Red Hat Enterprise Linux (RHEL) 4 on the x86_64 platform
Unspecified vulnerability in the kernel in Red Hat Enterprise Linux (RHEL) 4 on the x86_64 platform allows local users to cause a denial of service (OOPS) via unspecified vectors related to the get_gate_vma function and the fuser command.
nvd
CVE-2012-6548P4LOWCVSS 1.9v6.02013-03-15
CVE-2012-6548 [LOW] CWE-200 CVE-2012-6548: The udf_encode_fh function in fs/udf/namei.c in the Linux kernel before 3.6 does not initialize a ce
The udf_encode_fh function in fs/udf/namei.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application.
nvd
CVE-2012-6537P4LOWCVSS 1.9v5v6.02013-03-15
CVE-2012-6537 [LOW] CWE-200 CVE-2012-6537: net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not initialize certain structures, which al
net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability.
nvd
CVE-2012-6538P4LOWCVSS 1.9v6.02013-03-15
CVE-2012-6538 [LOW] CWE-200 CVE-2012-6538: The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorr
The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability.
nvd