Redhat Enterprise Linux Server vulnerabilities

1,891 known vulnerabilities affecting redhat/enterprise_linux_server.

Total CVEs
1,891
CISA KEV
58
actively exploited
Public exploits
134
Exploited in wild
63
Severity breakdown
CRITICAL347HIGH710MEDIUM734LOW100

Vulnerabilities

Page 62 of 95
CVE-2017-5205CRITICALCVSS 9.8v7.02017-01-28
CVE-2017-5205 [CRITICAL] CWE-119 CVE-2017-5205: The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print(). The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print().
nvd
CVE-2017-5204CRITICALCVSS 9.8v7.02017-01-28
CVE-2017-5204 [CRITICAL] CWE-119 CVE-2017-5204: The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print(). The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print().
nvd
CVE-2017-5202CRITICALCVSS 9.8v7.02017-01-28
CVE-2017-5202 [CRITICAL] CWE-119 CVE-2017-5202: The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print(). The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print().
nvd
CVE-2016-9634CRITICALCVSS 9.8v6.02017-01-27
CVE-2016-9634 [CRITICAL] CWE-119 CVE-2016-9634: Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC d Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via the start_line parameter.
nvd
CVE-2016-9635CRITICALCVSS 9.8v6.02017-01-27
CVE-2016-9635 [CRITICAL] CWE-119 CVE-2016-9635: Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC d Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'skip count' that goes beyond initialized buffer.
nvd
CVE-2016-9636CRITICALCVSS 9.8v6.02017-01-27
CVE-2016-9636 [CRITICAL] CWE-119 CVE-2016-9636: Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC d Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'write count' that goes beyond the initialized buffer.
nvd
CVE-2017-3243MEDIUMCVSS 4.4v7.02017-01-27
CVE-2017-3243 [MEDIUM] CVE-2017-3243: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets). Suppor Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets). Supported versions that are affected are 5.5.53 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2017-3258MEDIUMCVSS 6.5v7.02017-01-27
CVE-2017-3258 [MEDIUM] CWE-20 CVE-2017-3258: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this
nvd
CVE-2017-3244MEDIUMCVSS 6.5v7.02017-01-27
CVE-2017-3244 [MEDIUM] CVE-2017-3244: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulner
nvd
CVE-2017-3313MEDIUMCVSS 4.7v5.0v6.02017-01-27
CVE-2017-3313 [MEDIUM] CVE-2017-3313: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supporte Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful
nvd
CVE-2016-5824MEDIUMCVSS 5.5v6.0v7.02017-01-27
CVE-2016-5824 [MEDIUM] CWE-416 CVE-2016-5824: libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.
nvd
CVE-2017-3265MEDIUMCVSS 5.6v7.02017-01-27
CVE-2017-3265 [MEDIUM] CVE-2017-3265: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Succes
nvd
CVE-2017-3291MEDIUMCVSS 6.3v7.02017-01-27
CVE-2017-3291 [MEDIUM] CVE-2017-3291: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Succes
nvd
CVE-2017-3318MEDIUMCVSS 4.0v7.02017-01-27
CVE-2017-3318 [MEDIUM] CVE-2017-3318: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Error Handling). Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Error Handling). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Su
nvd
CVE-2017-3238MEDIUMCVSS 6.5v7.02017-01-27
CVE-2017-3238 [MEDIUM] CVE-2017-3238: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this
nvd
CVE-2017-3317MEDIUMCVSS 4.0v7.02017-01-27
CVE-2017-3317 [MEDIUM] CVE-2017-3317: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Logging). Supported versi Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Logging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attac
nvd
CVE-2016-9446HIGHCVSS 7.5v7.02017-01-23
CVE-2016-9446 [HIGH] CWE-665 CVE-2016-9446: The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attacke The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
nvd
CVE-2016-9401MEDIUMCVSS 5.5v6.0v7.02017-01-23
CVE-2016-9401 [MEDIUM] CWE-416 CVE-2016-9401: popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
nvd
CVE-2016-7545HIGHCVSS 8.8v6.0v7.02017-01-19
CVE-2016-7545 [HIGH] CWE-284 CVE-2016-7545: SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
nvd
CVE-2016-5198HIGHCVSS 8.8KEVv6.02017-01-19
CVE-2016-5198 [HIGH] CWE-125 CVE-2016-5198: V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.
nvd