cbcvebase.

Redhat Enterprise Linux Workstation vulnerabilities

1,845 known vulnerabilities affecting redhat/enterprise_linux_workstation.

Total CVEs
1,845
CISA KEV
57
actively exploited
Public exploits
138
Exploited in wild
75
Severity breakdown
CRITICAL336HIGH698MEDIUM712LOW99

Vulnerabilities

Page 80 of 93
CVE-2019-5779P4MEDIUMCVSS 4.3v6.02019-02-19
CVE-2019-5779 [MEDIUM] CWE-862 CVE-2019-5779: Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a rem Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2018-6082P4MEDIUMCVSS 4.7v6.02018-11-14
CVE-2018-6082 [MEDIUM] CWE-200 CVE-2018-6082: Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325 Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially enumerate internal host services via a crafted HTML page.
nvd
CVE-2013-5614P4MEDIUMCVSS 4.3v5.0v6.02013-12-11
CVE-2013-5614 [MEDIUM] CWE-1021 CVE-2013-5614: Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended sandbox restrictions via a crafted web site.
nvd
CVE-2012-0867P4MEDIUMCVSS 4.3v6.02012-07-18
CVE-2012-0867 [MEDIUM] CWE-20 CVE-2012-0867: PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters.
nvd
CVE-2016-5444P4LOWCVSS 3.7v7.02016-07-21
CVE-2016-5444 [LOW] CVE-2016-5444: Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and ear Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to Server: Connection.
nvd
CVE-2017-5065P4MEDIUMCVSS 4.7v6.02017-10-27
CVE-2017-5065 [MEDIUM] CWE-20 CVE-2017-5065: Lack of an appropriate action on page navigation in Blink in Google Chrome prior to 58.0.3029.81 for Lack of an appropriate action on page navigation in Blink in Google Chrome prior to 58.0.3029.81 for Windows and Mac allowed a remote attacker to potentially confuse a user into making an incorrect security decision via a crafted HTML page.
nvd
CVE-2015-4830P4MEDIUMCVSS 4.0v7.02015-10-21
CVE-2015-4830 [MEDIUM] CVE-2015-4830: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2017-10105P4MEDIUMCVSS 4.3v6.0v7.02017-08-08
CVE-2017-10105 [MEDIUM] CVE-2017-10105: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versi Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than
nvd
CVE-2018-5170P4MEDIUMCVSS 4.3v6.0v7.02018-06-11
CVE-2018-5170 [MEDIUM] CWE-20 CVE-2018-5170: It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
nvd
CVE-2011-1745P4MEDIUMCVSS 6.9v5.02011-05-09
CVE-2011-1745 [MEDIUM] CWE-190 CVE-2011-1745: Integer overflow in the agp_generic_insert_memory function in drivers/char/agp/generic.c in the Linu Integer overflow in the agp_generic_insert_memory function in drivers/char/agp/generic.c in the Linux kernel before 2.6.38.5 allows local users to gain privileges or cause a denial of service (system crash) via a crafted AGPIOC_BIND agp_ioctl ioctl call.
nvd
CVE-2018-13033P4MEDIUMCVSS 5.5v7.02018-07-01
CVE-2018-13033 [MEDIUM] CWE-770 CVE-2018-13033: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows r The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_parse_attributes in elf-attrs.c and bfd_malloc in libbfd.c. This can occur during execution of nm.
nvd
CVE-2018-10372P4MEDIUMCVSS 5.5v7.02018-04-25
CVE-2018-10372 [MEDIUM] CWE-125 CVE-2018-10372: process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of ser process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted binary file, as demonstrated by readelf.
nvd
CVE-2014-6568P4LOWCVSS 3.5v5.0v7.02015-01-21
CVE-2014-6568 [LOW] CVE-2014-6568: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DML.
nvd
CVE-2018-1094P4MEDIUMCVSS 5.5v7.02018-04-02
CVE-2018-1094 [MEDIUM] CWE-476 CVE-2018-1094: The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.15.15 does not always The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.15.15 does not always initialize the crc32c checksum driver, which allows attackers to cause a denial of service (ext4_xattr_inode_hash NULL pointer dereference and system crash) via a crafted ext4 image.
nvd
CVE-2013-6425P4MEDIUMCVSS 5.0v5.0v6.02014-01-18
CVE-2013-6425 [MEDIUM] CWE-191 CVE-2013-6425: Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used i Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.
nvd
CVE-2017-3243P4MEDIUMCVSS 4.4v7.02017-01-27
CVE-2017-3243 [MEDIUM] CVE-2017-3243: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets). Suppor Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets). Supported versions that are affected are 5.5.53 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2018-16541P4MEDIUMCVSS 5.5v7.02018-09-05
CVE-2018-16541 [MEDIUM] CWE-416 CVE-2018-16541: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use inco In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter.
nvd
CVE-2019-7150P4MEDIUMCVSS 5.5v7.02019-01-29
CVE-2019-7150 [MEDIUM] CWE-125 CVE-2019-7150: An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlat An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted input can cause a program crash, leading to denial-of-service, as demonstrated by eu-stack.
nvd
CVE-2018-2771P4MEDIUMCVSS 4.4v7.02018-04-19
CVE-2018-2771 [MEDIUM] CVE-2018-2771: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Locking). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Locking). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulne
nvd
CVE-2018-7858P4MEDIUMCVSS 5.5v6.0v7.02018-03-12
CVE-2018-7858 [MEDIUM] CWE-125 CVE-2018-7858: Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local g Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.
nvd
Redhat Enterprise Linux Workstation vulnerabilities | cvebase