cbcvebase.

Redhat Enterprise Linux Server vulnerabilities

1,891 known vulnerabilities affecting redhat/enterprise_linux_server.

Total CVEs
1,891
CISA KEV
58
actively exploited
Public exploits
136
Exploited in wild
77
Severity breakdown
CRITICAL348HIGH709MEDIUM733LOW101

Vulnerabilities

Page 62 of 95
CVE-2020-6397P4MEDIUMCVSS 6.5v6.02020-02-11
CVE-2020-6397 [MEDIUM] CVE-2020-6397: Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote atta Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2018-6137P4MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6137 [MEDIUM] CWE-200 CVE-2018-6137: CSS Paint API in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to leak cros CSS Paint API in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6393P4MEDIUMCVSS 6.5v6.02020-02-11
CVE-2020-6393 [MEDIUM] CWE-862 CVE-2020-6393: Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote att Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-2629P4MEDIUMCVSS 5.3v6.0v7.02018-01-18
CVE-2018-2629 [MEDIUM] CVE-2018-2629: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: J Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java S
nvd
CVE-2019-5773P4MEDIUMCVSS 6.5v6.02019-02-19
CVE-2019-5773 [MEDIUM] CWE-346 CVE-2019-5773: Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.
nvd
CVE-2019-13752P4MEDIUMCVSS 6.5v6.02019-12-10
CVE-2019-13752 [MEDIUM] CWE-125 CVE-2019-13752: Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obt Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2019-13753P4MEDIUMCVSS 6.5v6.02019-12-10
CVE-2019-13753 [MEDIUM] CWE-125 CVE-2019-13753: Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obt Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2018-6079P4MEDIUMCVSS 6.5v6.02018-11-14
CVE-2018-6079 [MEDIUM] CWE-200 CVE-2018-6079: Inappropriate sharing of TEXTURE_2D_ARRAY/TEXTURE_3D data between tabs in WebGL in Google Chrome pri Inappropriate sharing of TEXTURE_2D_ARRAY/TEXTURE_3D data between tabs in WebGL in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2017-5071P4MEDIUMCVSS 6.3v6.02017-10-27
CVE-2017-5071 [MEDIUM] CWE-20 CVE-2017-5071: Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.86 for Linux, W Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2018-6109P4MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6109 [MEDIUM] CWE-200 CVE-2018-6109: readAsText() can indefinitely read the file picked by the user, rather than only once at the time th readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit consent via a crafted HTML page.
nvd
CVE-2018-6080P4MEDIUMCVSS 6.5v6.02018-11-14
CVE-2018-6080 [MEDIUM] CWE-269 CVE-2018-6080: Lack of access control checks in Instrumentation in Google Chrome prior to 65.0.3325.146 allowed a r Lack of access control checks in Instrumentation in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to obtain memory metadata from privileged processes .
nvd
CVE-2019-13742P4MEDIUMCVSS 6.5v6.02019-12-10
CVE-2019-13742 [MEDIUM] CVE-2019-13742: Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote atta Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2018-6179P4MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6179 [MEDIUM] CWE-200 CVE-2018-6179: Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chr Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.
nvd
CVE-2017-15906P4MEDIUMCVSS 5.3v7.02017-10-26
CVE-2017-15906 [MEDIUM] CWE-732 CVE-2017-15906: The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write ope The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
nvd
CVE-2018-7643P4HIGHCVSS 7.8v7.02018-03-02
CVE-2018-7643 [HIGH] CWE-190 CVE-2018-7643: The display_debug_ranges function in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a The display_debug_ranges function in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact via a crafted ELF file, as demonstrated by objdump.
nvd
CVE-2015-7702P4MEDIUMCVSS 6.5v6.0v7.02017-08-07
CVE-2015-7702 [MEDIUM] CVE-2015-7702: The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750.
nvd
CVE-2015-8241P4MEDIUMCVSS 6.4v6.02015-12-15
CVE-2015-8241 [MEDIUM] CWE-119 CVE-2015-8241: The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-de The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
nvd
CVE-2014-9664P4MEDIUMCVSS 6.8v6.0v7.02015-02-08
CVE-2014-9664 [MEDIUM] CWE-119 CVE-2014-9664: FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which a FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c.
nvd
CVE-2018-11212P4MEDIUMCVSS 6.5v6.0v7.02018-05-16
CVE-2018-11212 [MEDIUM] CWE-369 CVE-2018-11212: An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote a An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
nvd
CVE-2014-9666P4MEDIUMCVSS 6.8v6.0v7.02015-02-08
CVE-2014-9666 [MEDIUM] CWE-189 CVE-2014-9666: The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to-size association without restricting the count value, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted embedded bitmap.
nvd
Redhat Enterprise Linux Server vulnerabilities | cvebase