cbcvebase.

Redhat Enterprise Linux Desktop vulnerabilities

1,928 known vulnerabilities affecting redhat/enterprise_linux_desktop.

Total CVEs
1,928
CISA KEV
56
actively exploited
Public exploits
143
Exploited in wild
74
Severity breakdown
CRITICAL346HIGH707MEDIUM755LOW120

Vulnerabilities

Page 19 of 97
CVE-2016-7863P3HIGHCVSS 8.8v5.0v6.02016-11-08
CVE-2016-7863 [HIGH] CWE-416 CVE-2016-7863: Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7862P3HIGHCVSS 8.8v5.0v6.02016-11-08
CVE-2016-7862 [HIGH] CWE-416 CVE-2016-7862: Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7864P3HIGHCVSS 8.8v5.0v6.02016-11-08
CVE-2016-7864 [HIGH] CWE-416 CVE-2016-7864: Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7859P3HIGHCVSS 8.8v5.0v6.02016-11-08
CVE-2016-7859 [HIGH] CWE-416 CVE-2016-7859: Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7857P3HIGHCVSS 8.8v5.0v6.02016-11-08
CVE-2016-7857 [HIGH] CWE-416 CVE-2016-7857: Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2016-7858P3HIGHCVSS 8.8v5.0v6.02016-11-08
CVE-2016-7858 [HIGH] CWE-416 CVE-2016-7858: Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2017-1000410P3HIGHCVSS 7.5v6.0v7.02017-12-07
CVE-2017-1000410 [HIGH] CVE-2017-1000410: The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned to an attacker in their uninitialized state. By manipulating the code flows that precede the handling of th
nvd
CVE-2013-0754P3CRITICALCVSS 9.3v5.0v6.02013-01-13
CVE-2013-0754 [CRITICAL] CWE-416 CVE-2013-0754: Use-after-free vulnerability in the ListenerManager implementation in Mozilla Firefox before 18.0, F Use-after-free vulnerability in the ListenerManager implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via vectors involving the trigger
nvd
CVE-2018-2783P3HIGHCVSS 7.4v6.0v7.02018-04-19
CVE-2018-2783 [HIGH] CVE-2018-2783: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: S Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u161 and 8u152; Java SE Embedded: 8u152; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Ja
nvd
CVE-2017-17833P3CRITICALCVSS 9.8v6.0v7.02018-04-23
CVE-2017-17833 [CRITICAL] CWE-119 CVE-2017-17833: OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue whi OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
nvd
CVE-2018-18492P3CRITICALCVSS 9.8v6.0v7.02019-02-28
CVE-2018-18492 [CRITICAL] CWE-416 CVE-2018-18492: A use-after-free vulnerability can occur after deleting a selection element due to a weak reference A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2016-6796P3HIGHCVSS 7.5v7.02017-08-11
CVE-2016-6796 [HIGH] CVE-2016-6796: A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.
nvd
CVE-2017-3143P3MEDIUMCVSS 5.9v6.0v7.02019-01-16
CVE-2017-3143 [MEDIUM] CVE-2017-3143: An attacker who is able to send and receive messages to an authoritative DNS server and who has know An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S
nvd
CVE-2017-15399P3HIGHCVSS 8.8v6.02018-08-28
CVE-2017-15399 [HIGH] CWE-416 CVE-2017-15399: A use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potential A use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-12549P3CRITICALCVSS 9.8v6.0v7.02019-02-11
CVE-2018-12549 [CRITICAL] CWE-111 CVE-2018-12549: In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the r In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when accelerating it.
nvd
CVE-2018-12387P3CRITICALCVSS 9.1v6.0v7.02018-10-18
CVE-2018-12387 [CRITICAL] CWE-20 CVE-2018-12387: A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple argumen A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. This leaks a memory address to the calling function which can be used as part of an exploit inside the sandboxed content process. This vulnerability affects Firefox ESR < 60.2
nvd
CVE-2018-5407P4MEDIUMCVSS 4.7PoCv7.02018-11-15
CVE-2018-5407 [MEDIUM] CWE-200 CVE-2018-5407: Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerab Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
nvd
CVE-2018-1000122P3CRITICALCVSS 9.1v7.02018-03-14
CVE-2018-1000122 [CRITICAL] CWE-125 CVE-2018-1000122: A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage
nvd
CVE-2018-16068P3CRITICALCVSS 9.6v6.02019-01-09
CVE-2018-16068 [CRITICAL] CWE-20 CVE-2018-16068: Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to poten Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2018-18335P3HIGHCVSS 8.8v6.02018-12-11
CVE-2018-18335 [HIGH] CWE-787 CVE-2018-18335: Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to pot Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
Redhat Enterprise Linux Desktop vulnerabilities | cvebase