cbcvebase.

Redhat Linux vulnerabilities

213 known vulnerabilities affecting redhat/linux.

Total CVEs
213
CISA KEV
0
Public exploits
72
Exploited in wild
4
Severity breakdown
CRITICAL34HIGH86MEDIUM56LOW37

Vulnerabilities

Page 1 of 11
CVE-2000-0248P2CRITICALCVSS 10.0ExploitedPoCv6.22000-04-24
CVE-2000-0248 [CRITICAL] CVE-2000-0248: The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a b The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.
nvd
CVE-1999-0502P2HIGHCVSS 7.5ExploitedPoCv6.01998-03-01
CVE-1999-0502 [HIGH] CVE-1999-0502: A Unix account has a default, null, blank, or missing password. A Unix account has a default, null, blank, or missing password.
nvd
CVE-2000-0322P2CRITICALCVSS 10.0ExploitedPoCv6.22000-04-24
CVE-2000-0322 [CRITICAL] CVE-2000-0322: The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execu The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execute arbitrary commands via shell metacharacters.
nvd
CVE-1999-0192P2CRITICALCVSS 10.0ExploitedPoCv4.0v4.1+5 more1997-10-18
CVE-1999-0192 [CRITICAL] CVE-1999-0192: Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.
nvd
CVE-2000-0917P2CRITICALCVSS 10.0PoCv7.02000-12-19
CVE-2000-0917 [CRITICAL] CVE-2000-0917: Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to exec Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
nvd
CVE-2003-0434P3HIGHCVSS 7.5PoCv7.1v7.2+3 more2003-07-24
CVE-2003-0434 [HIGH] CVE-2003-0434: Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to exe Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
nvd
CVE-2000-0666P3CRITICALCVSS 10.0PoCv6.0v6.1+1 more2000-07-16
CVE-2000-0666 [CRITICAL] CVE-2000-0666: rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untruste rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.
nvd
CVE-1999-0368P3CRITICALCVSS 10.0PoCv5.0v5.11999-02-09
CVE-1999-0368 [CRITICAL] CVE-1999-0368: Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
nvd
CVE-2000-0389P3CRITICALCVSS 10.0PoCv6.22000-05-16
CVE-2000-0389 [CRITICAL] CVE-2000-0389: Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root priv Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.
nvd
CVE-1999-0002P3CRITICALCVSS 10.0PoCv2.0v2.1+6 more1998-10-12
CVE-1999-0002 [CRITICAL] CWE-119 CVE-1999-0002: Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems. Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.
nvd
CVE-2001-0197P3CRITICALCVSS 10.0PoCv6.0v6.1+2 more2001-03-26
CVE-2001-0197 [CRITICAL] CVE-2001-0197: Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attacker Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands.
nvd
CVE-2002-0083P3CRITICALCVSS 9.8PoCv7.0v7.1+1 more2002-03-15
CVE-2002-0083 [CRITICAL] CWE-193 CVE-2002-0083: Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malic Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
nvd
CVE-2000-1220P3CRITICALCVSS 10.0PoCv4.0v4.1+6 more2000-01-08
CVE-2000-1220 [CRITICAL] CVE-2000-1220: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local us The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.
nvd
CVE-1999-0009P3CRITICALCVSS 10.0PoCv4.0v4.1+2 more1998-04-08
CVE-1999-0009 [CRITICAL] CVE-1999-0009: Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
nvd
CVE-2000-1221P3CRITICALCVSS 10.0PoCv4.1v4.2+4 more2000-01-08
CVE-2000-1221 [CRITICAL] CVE-2000-1221: The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates b The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP.
nvd
CVE-2000-0844P3CRITICALCVSS 10.0PoCv5.0v5.1+4 more2000-11-14
CVE-2000-0844 [CRITICAL] CWE-264 CVE-2000-0844: Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected fo Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
nvd
CVE-2001-1013P3MEDIUMCVSS 5.0PoCv7.02001-09-12
CVE-2001-1013 [MEDIUM] CVE-2001-1013: Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.
nvd
CVE-2001-0233P3CRITICALCVSS 10.0PoCv6.0v6.1+2 more2001-03-26
CVE-2001-0233 [CRITICAL] CVE-2001-0233: Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of servic Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field.
nvd
CVE-2001-1002P3HIGHCVSS 7.5PoCv6.2v7.0+1 more2001-08-31
CVE-2001-1002 [HIGH] CVE-2001-1002: The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not The default configuration of the DVI print filter (dvips) in Red Hat Linux 7.0 and earlier does not run dvips in secure mode when dvips is executed by lpd, which could allow remote attackers to gain privileges by printing a DVI file that contains malicious commands.
nvd
CVE-2000-0751P3HIGHCVSS 7.5PoCv6.0v6.1+1 more2000-10-20
CVE-2000-0751 [HIGH] CVE-2000-0751: mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands.
nvd
1 / 11Next →
Redhat Linux vulnerabilities | cvebase