Redhat Enterprise Linux Server vulnerabilities
1,891 known vulnerabilities affecting redhat/enterprise_linux_server.
Total CVEs
1,891
CISA KEV
58
actively exploited
Public exploits
136
Exploited in wild
77
Severity breakdown
CRITICAL348HIGH709MEDIUM733LOW101
Vulnerabilities
Page 94 of 95
CVE-2019-3815P4LOWCVSS 3.3v7.02019-01-28
CVE-2019-3815 [LOW] CVE-2019-3815: A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux
A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A local attacker may use this flaw to make systemd-journald crash. This issue only affects versions shipped with Re
nvd
CVE-2017-5081P4LOWCVSS 3.3v6.02017-10-27
CVE-2017-5081 [LOW] CWE-20 CVE-2017-5081: Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac,
Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed an attacker with local write access to modify extensions by modifying extension files.
nvd
CVE-2019-13762P4LOWCVSS 3.3v6.02019-12-10
CVE-2019-13762 [LOW] CWE-667 CVE-2019-13762: Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allow
Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code.
nvd
CVE-2014-0181P4LOWCVSS 2.1v5.02014-04-27
CVE-2014-0181 [LOW] CWE-264 CVE-2014-0181: The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for autho
The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.
nvd
CVE-2017-3317P4MEDIUMCVSS 4.0v7.02017-01-27
CVE-2017-3317 [MEDIUM] CVE-2017-3317: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Logging). Supported versi
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Logging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attac
nvd
CVE-2011-1182P4LOWCVSS 3.6v5.02013-03-01
CVE-2011-1182 [LOW] CVE-2011-1182: kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a s
kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call.
nvd
CVE-2018-6053P4LOWCVSS 3.3v6.02018-09-25
CVE-2018-6053 [LOW] CWE-200 CVE-2018-6053: Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local
Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing browser data via a crafted HTML page.
nvd
CVE-2016-4455P4LOWCVSS 3.3v6.0v7.02017-04-14
CVE-2016-4455 [LOW] CWE-264 CVE-2016-4455: The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak
The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain sensitive information by reading files in the directories.
nvd
CVE-2014-9585P4LOWCVSS 2.1v6.0v7.02015-01-09
CVE-2014-9585 [LOW] CVE-2014-9585: The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly c
The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.
nvd
CVE-2012-1717P4LOWCVSS 2.1v5.0v6.02012-06-16
CVE-2012-1717 [LOW] CVE-2012-1717: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows local users to affect confidentiality via unknown vectors related to printing on Solaris or Linux.
nvd
CVE-2015-5006P4LOWCVSS 2.1v5.0v6.0+1 more2015-12-07
CVE-2015-5006 [LOW] CWE-200 CVE-2015-5006: IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20,
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16 FP15 allow physically proximate attackers to obtain sensitive information by reading the Kerberos Credential Cache.
nvd
CVE-2014-9584P4LOWCVSS 2.1v6.0v7.02015-01-09
CVE-2014-9584 [LOW] CWE-20 CVE-2014-9584: The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 do
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.
nvd
CVE-2009-2910P4LOWCVSS 2.1v5.02009-10-20
CVE-2009-2910 [LOW] CWE-200 CVE-2009-2910: arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear
arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to 64-bit mode.
nvd
CVE-2014-3640P4LOWCVSS 2.1v7.02014-11-07
CVE-2014-3640 [LOW] CWE-476 CVE-2014-3640: The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of se
The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket.
nvd
CVE-2014-4652P4LOWCVSS 1.9v6.02014-07-03
CVE-2014-4652 [LOW] CWE-362 CVE-2014-4652: Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/
Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allows local users to obtain sensitive information from kernel memory by leveraging /dev/snd/controlCX access.
nvd
CVE-2013-2391P4LOWCVSS 3.0v6.02013-04-17
CVE-2013-2391 [LOW] CVE-2013-2391: Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and ear
Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows local users to affect confidentiality and integrity via unknown vectors related to Server Install.
nvd
CVE-2010-3881P4LOWCVSS 2.1v6.02010-12-23
CVE-2010-3881 [LOW] CWE-200 CVE-2010-3881: arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members
arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.
nvd
CVE-2014-3615P4LOWCVSS 2.1v7.02014-11-01
CVE-2014-3615 [LOW] CWE-200 CVE-2014-3615: The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a hi
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
nvd
CVE-2007-6206P4LOWCVSS 2.1v4.02007-12-04
CVE-2007-6206 [LOW] CWE-200 CVE-2007-6206: The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly
The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.
nvd
CVE-2011-1163P4LOWCVSS 2.1v5.0v6.02011-04-10
CVE-2011-1163 [LOW] CWE-20 CVE-2011-1163: The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properl
The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vectors related to partition-table parsing.
nvd