Redhat Linux vulnerabilities
213 known vulnerabilities affecting redhat/linux.
Total CVEs
213
CISA KEV
0
Public exploits
72
Exploited in wild
4
Severity breakdown
CRITICAL34HIGH86MEDIUM56LOW37
Vulnerabilities
Page 10 of 11
CVE-2000-0364P4MEDIUMCVSS 4.6v6.01999-06-01
CVE-2000-0364 [MEDIUM] CVE-2000-0364: screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows loca
screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to other ttys.
nvd
CVE-2003-0464P4MEDIUMCVSS 4.6v7.1v7.2+3 more2003-08-27
CVE-2003-0464 [MEDIUM] CVE-2003-0464: The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow loc
The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd.
nvd
CVE-2001-0635P4MEDIUMCVSS 4.6v7.12001-08-14
CVE-2001-0635 [MEDIUM] CVE-2001-0635: Red Hat Linux 7.1 sets insecure permissions on swap files created during installation, which can all
Red Hat Linux 7.1 sets insecure permissions on swap files created during installation, which can allow a local attacker to gain additional privileges by reading sensitive information from the swap file, such as passwords.
nvd
CVE-2000-0365P4MEDIUMCVSS 4.6v6.01999-06-01
CVE-2000-0365 [MEDIUM] CVE-2000-0365: Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to
Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices.
nvd
CVE-1999-1347P4MEDIUMCVSS 4.6≤ 6.11999-10-07
CVE-1999-1347 [MEDIUM] CVE-1999-1347: Xsession in Red Hat Linux 6.1 and earlier can allow local users with restricted accounts to bypass e
Xsession in Red Hat Linux 6.1 and earlier can allow local users with restricted accounts to bypass execution of the .xsession file by starting kde, gnome or anotherlevel from kdm.
nvd
CVE-1999-0234P4MEDIUMCVSS 4.6v3.0.31996-10-08
CVE-1999-0234 [MEDIUM] CVE-1999-0234: Bash treats any character with a value of 255 as a command separator.
Bash treats any character with a value of 255 as a command separator.
nvd
CVE-1999-1330P4MEDIUMCVSS 4.6v4.21999-12-31
CVE-1999-1330 [MEDIUM] CVE-1999-1330: The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attacke
The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.
nvd
CVE-2002-0080P4LOWCVSS 2.1v6.2v7.0+2 more2002-03-15
CVE-2002-0080 [LOW] CWE-269 CVE-2002-0080: rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, whi
rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.
nvd
CVE-2001-0946P4LOWCVSS 3.6v7.22001-12-04
CVE-2001-0946 [LOW] CVE-2001-0946: apmscript in Apmd in Red Hat 7.2 "Enigma" allows local users to create or change the modification da
apmscript in Apmd in Red Hat 7.2 "Enigma" allows local users to create or change the modification dates of arbitrary files via a symlink attack on the LOW_POWER temporary file, which could be used to cause a denial of service, e.g. by creating /etc/nologin and disabling logins.
nvd
CVE-2002-1509P4LOWCVSS 3.6v7.2v7.3+1 more2003-03-03
CVE-2002-1509 [LOW] CVE-2002-1509: A patch for shadow-utils 20000902 causes the useradd command to create a mail spool files with read/
A patch for shadow-utils 20000902 causes the useradd command to create a mail spool files with read/write privileges of the new user's group (mode 660), which allows other users in the same group to read or modify the new user's incoming email.
nvd
CVE-2000-0604P4MEDIUMCVSS 4.6v6.22000-06-21
CVE-2000-0604 [MEDIUM] CVE-2000-0604: gkermit in Red Hat Linux is improperly installed with setgid uucp, which allows local users to modif
gkermit in Red Hat Linux is improperly installed with setgid uucp, which allows local users to modify files owned by uucp.
nvd
CVE-1999-1407P4LOWCVSS 2.1v5.01998-03-09
CVE-1999-1407 [LOW] CVE-1999-1407: ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arb
ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.
nvd
CVE-1999-1348P4LOWCVSS 2.1≤ 6.01999-06-30
CVE-1999-1348 [LOW] CVE-1999-1348: Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdow
Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service.
nvd
CVE-2002-0044P4LOWCVSS 3.6v6.0v6.1+4 more2002-01-31
CVE-2002-0044 [LOW] CVE-2002-0044: GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user
GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.
nvd
CVE-2001-0139P4LOWCVSS 1.2v7.02001-03-12
CVE-2001-0139 [LOW] CVE-2001-0139: inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configuration
inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
nvd
CVE-2001-0143P4LOWCVSS 1.2v7.02001-03-12
CVE-2001-0143 [LOW] CVE-2001-0143: vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a
vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.
nvd
CVE-2001-0142P4LOWCVSS 1.2v7.02001-03-12
CVE-2001-0142 [LOW] CVE-2001-0142: squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some c
squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.
nvd
CVE-2001-0120P4LOWCVSS 1.2v7.02001-03-12
CVE-2001-0120 [LOW] CVE-2001-0120: useradd program in shadow-utils program may allow local users to overwrite arbitrary files via a sym
useradd program in shadow-utils program may allow local users to overwrite arbitrary files via a symlink attack.
nvd
CVE-2001-0116P4LOWCVSS 1.2v7.02001-03-12
CVE-2001-0116 [LOW] CVE-2001-0116: gpm 1.19.3 allows local users to overwrite arbitrary files via a symlink attack.
gpm 1.19.3 allows local users to overwrite arbitrary files via a symlink attack.
nvd
CVE-2001-0138P4LOWCVSS 1.2v7.02001-03-12
CVE-2001-0138 [LOW] CVE-2001-0138: privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a sy
privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.
nvd