Redhat Enterprise Linux Workstation vulnerabilities

1,845 known vulnerabilities affecting redhat/enterprise_linux_workstation.

Total CVEs
1,845
CISA KEV
57
actively exploited
Public exploits
136
Exploited in wild
62
Severity breakdown
CRITICAL335HIGH699MEDIUM713LOW98

Vulnerabilities

Page 20 of 93
CVE-2018-15127CRITICALCVSS 9.8v7.02018-12-19
CVE-2018-15127 [CRITICAL] CWE-787 CVE-2018-15127: LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulne LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution
nvd
CVE-2018-19039MEDIUMCVSS 6.5v7.02018-12-13
CVE-2018-19039 [MEDIUM] CWE-200 CVE-2018-19039: Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
nvd
CVE-2018-20097MEDIUMCVSS 6.5v7.02018-12-12
CVE-2018-20097 [MEDIUM] CWE-119 CVE-2018-20097: There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
nvd
CVE-2018-18397MEDIUMCVSS 5.5PoCv7.02018-12-12
CVE-2018-18397 [MEDIUM] CWE-863 CVE-2018-18397: The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certa The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and mm/userfaultfd.c.
nvd
CVE-2018-18354HIGHCVSS 8.8v6.02018-12-11
CVE-2018-18354 [HIGH] CWE-20 CVE-2018-18354: Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior t Insufficient validate of external protocols in Shell Integration in Google Chrome on Windows prior to 71.0.3578.80 allowed a remote attacker to launch external programs via a crafted HTML page.
nvd
CVE-2018-18335HIGHCVSS 8.8v6.02018-12-11
CVE-2018-18335 [HIGH] CWE-787 CVE-2018-18335: Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to pot Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-18342HIGHCVSS 8.8v6.02018-12-11
CVE-2018-18342 [HIGH] CWE-787 CVE-2018-18342: Execution of user supplied Javascript during object deserialization can update object length leading Execution of user supplied Javascript during object deserialization can update object length leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2018-17480HIGHCVSS 8.8KEVv6.02018-12-11
CVE-2018-17480 [HIGH] CWE-787 CVE-2018-17480: Execution of user supplied Javascript during array deserialization leading to an out of bounds write Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2018-18356HIGHCVSS 8.8v6.0v7.02018-12-11
CVE-2018-18356 [HIGH] CWE-190 CVE-2018-18356: An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0 An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-18358MEDIUMCVSS 5.7v6.02018-12-11
CVE-2018-18358 [MEDIUM] CWE-20 CVE-2018-18358: Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.
nvd
CVE-2018-18357MEDIUMCVSS 4.3v6.02018-12-11
CVE-2018-18357 [MEDIUM] CVE-2018-18357: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2018-18355MEDIUMCVSS 4.3v6.02018-12-11
CVE-2018-18355 [MEDIUM] CVE-2018-18355: Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2018-18348MEDIUMCVSS 4.3v6.02018-12-11
CVE-2018-18348 [MEDIUM] CVE-2018-18348: Incorrect handling of bidirectional domain names with RTL characters in Omnibox in Google Chrome pri Incorrect handling of bidirectional domain names with RTL characters in Omnibox in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
nvd
CVE-2018-18350MEDIUMCVSS 6.5v6.02018-12-11
CVE-2018-18350 [MEDIUM] CVE-2018-18350: Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.357 Incorrect handling of CSP enforcement during navigations in Blink in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2018-18345MEDIUMCVSS 6.5v6.02018-12-11
CVE-2018-18345 [MEDIUM] CVE-2018-18345: Incorrect handling of blob URLS in Site Isolation in Google Chrome prior to 71.0.3578.80 allowed a r Incorrect handling of blob URLS in Site Isolation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker who had compromised the renderer process to bypass site isolation protections via a crafted HTML page.
nvd
CVE-2018-18353MEDIUMCVSS 6.5v6.02018-12-11
CVE-2018-18353 [MEDIUM] CVE-2018-18353: Failure to dismiss http auth dialogs on navigation in Network Authentication in Google Chrome on And Failure to dismiss http auth dialogs on navigation in Network Authentication in Google Chrome on Android prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of an auto dialog via a crafted HTML page.
nvd
CVE-2018-18352MEDIUMCVSS 6.5v6.02018-12-11
CVE-2018-18352 [MEDIUM] CWE-732 CVE-2018-18352: Service works could inappropriately gain access to cross origin audio in Media in Google Chrome prio Service works could inappropriately gain access to cross origin audio in Media in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass same origin policy for audio content via a crafted HTML page.
nvd
CVE-2018-18351MEDIUMCVSS 6.5v6.02018-12-11
CVE-2018-18351 [MEDIUM] CWE-20 CVE-2018-18351: Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google C Lack of proper validation of ancestor frames site when sending lax cookies in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to bypass SameSite cookie policy via a crafted HTML page.
nvd
CVE-2018-18349MEDIUMCVSS 6.5v6.02018-12-11
CVE-2018-18349 [MEDIUM] CWE-732 CVE-2018-18349: Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prio Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.
nvd
CVE-2018-18344MEDIUMCVSS 6.5v6.02018-12-11
CVE-2018-18344 [MEDIUM] CWE-269 CVE-2018-18344: Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Inappropriate allowance of the setDownloadBehavior devtools protocol feature in Extensions in Google Chrome prior to 71.0.3578.80 allowed a remote attacker with control of an installed extension to access files on the local file system via a crafted Chrome Extension.
nvd