Redhat Enterprise Linux Workstation vulnerabilities
1,845 known vulnerabilities affecting redhat/enterprise_linux_workstation.
Total CVEs
1,845
CISA KEV
57
actively exploited
Public exploits
138
Exploited in wild
75
Severity breakdown
CRITICAL336HIGH698MEDIUM712LOW99
Vulnerabilities
Page 62 of 93
CVE-2015-0248P4MEDIUMCVSS 5.0v6.02015-04-08
CVE-2015-0248 [MEDIUM] CWE-399 CVE-2015-0248: The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.
The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related to dynamically evaluated revision numbers.
nvd
CVE-2016-0546P4HIGHCVSS 7.2v7.02016-01-21
CVE-2016-0546 [HIGH] CVE-2016-0546: Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and Mari
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client. NOTE: the previous information is from the January 2016 CPU. Oracle has not commen
nvd
CVE-2012-3515P4HIGHCVSS 7.2v5.0v6.02012-11-23
CVE-2012-3515 [HIGH] CWE-20 CVE-2012-3515: Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a vir
Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."
nvd
CVE-2018-10767P4MEDIUMCVSS 6.5v7.02018-05-06
CVE-2018-10767 [MEDIUM] CWE-125 CVE-2018-10767: There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_ty
There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack.
nvd
CVE-2017-15396P4MEDIUMCVSS 6.5v6.02018-08-28
CVE-2017-15396 [MEDIUM] CWE-119 CVE-2017-15396: A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ b
A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ before 60.2, as used in V8 in Google Chrome prior to 62.0.3202.75 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2013-4344P4HIGHCVSS 7.2v6.02013-10-04
CVE-2013-4344 [HIGH] CWE-120 CVE-2013-4344: Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more
Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
nvd
CVE-2019-13751P4MEDIUMCVSS 6.5v6.02019-12-10
CVE-2019-13751 [MEDIUM] CWE-908 CVE-2019-13751: Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obt
Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2018-6123P4MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6123 [MEDIUM] CWE-416 CVE-2018-6123: A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potent
A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2018-12397P4HIGHCVSS 7.1v6.0v7.02019-02-28
CVE-2018-12397 [HIGH] CWE-200 CVE-2018-12397: A WebExtension can request access to local files without the warning prompt stating that the extensi
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63
nvd
CVE-2018-16078P4MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-16078 [MEDIUM] CWE-200 CVE-2018-16078: Unsafe handling of credit card details in Autofill in Google Chrome prior to 69.0.3497.81 allowed a
Unsafe handling of credit card details in Autofill in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2019-3460P4MEDIUMCVSS 6.5v7.02019-04-11
CVE-2019-3460 [MEDIUM] CWE-20 CVE-2019-3460: A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux ker
A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.
nvd
CVE-2018-2815P4MEDIUMCVSS 5.3v6.0v7.02018-04-19
CVE-2018-2815 [MEDIUM] CVE-2018-2815: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: S
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Ja
nvd
CVE-2017-15415P4MEDIUMCVSS 6.5v6.02018-08-28
CVE-2017-15415 [MEDIUM] CWE-119 CVE-2017-15415: Incorrect serialization in IPC in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to l
Incorrect serialization in IPC in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the value of a pointer via a crafted HTML page.
nvd
CVE-2018-6164P4MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6164 [MEDIUM] CWE-200 CVE-2018-6164: Insufficient origin checks for CSS content in Blink in Google Chrome prior to 68.0.3440.75 allowed a
Insufficient origin checks for CSS content in Blink in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-5766P4MEDIUMCVSS 6.5v6.02019-02-19
CVE-2019-5766 [MEDIUM] CVE-2019-5766: Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed
Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-6036P4MEDIUMCVSS 6.5v6.02018-09-25
CVE-2018-6036 [MEDIUM] CWE-20 CVE-2018-6036: Insufficient data validation in V8 in Google Chrome prior to 64.0.3282.119 allowed a remote attacker
Insufficient data validation in V8 in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user data via a crafted HTML page.
nvd
CVE-2018-6093P4MEDIUMCVSS 6.5v6.02019-01-09
CVE-2018-6093 [MEDIUM] CWE-200 CVE-2018-6093: Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacke
Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-6037P4MEDIUMCVSS 6.5v6.02018-09-25
CVE-2018-6037 [MEDIUM] CWE-200 CVE-2018-6037: Inappropriate implementation in autofill in Google Chrome prior to 64.0.3282.119 allowed a remote at
Inappropriate implementation in autofill in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain autofill data with insufficient user gestures via a crafted HTML page.
nvd
CVE-2019-13749P4MEDIUMCVSS 6.5v6.02019-12-10
CVE-2019-13749 [MEDIUM] CVE-2019-13749: Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote atta
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2018-6045P4MEDIUMCVSS 6.5v6.02018-09-25
CVE-2018-6045 [MEDIUM] CWE-200 CVE-2018-6045: Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote
Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user local file data via a crafted Chrome Extension.
nvd