Redhat Linux vulnerabilities
213 known vulnerabilities affecting redhat/linux.
Total CVEs
213
CISA KEV
0
Public exploits
72
Exploited in wild
0
Severity breakdown
CRITICAL34HIGH86MEDIUM56LOW37
Vulnerabilities
Page 2 of 11
CVE-2004-0619HIGHCVSS 7.2v8.02004-12-06
CVE-2004-0619 [HIGH] CVE-2004-0619: Integer overflow in the ubsec_keysetup function for Linux Broadcom 5820 cryptonet driver allows loca
Integer overflow in the ubsec_keysetup function for Linux Broadcom 5820 cryptonet driver allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a negative add_dsa_buf_bytes variable, which leads to a buffer overflow.
nvd
CVE-2004-0079HIGHCVSS 7.5v7.2v7.3+1 more2004-11-23
CVE-2004-0079 [HIGH] CWE-476 CVE-2004-0079: The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
nvd
CVE-2004-0081MEDIUMCVSS 5.0v7.2v7.3+1 more2004-11-23
CVE-2004-0081 [MEDIUM] CVE-2004-0081: OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote atta
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
nvd
CVE-2004-0112MEDIUMCVSS 5.0v7.2v7.3+1 more2004-11-23
CVE-2004-0112 [MEDIUM] CWE-125 CVE-2004-0112: The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
nvd
CVE-2004-1613MEDIUMCVSS 5.0v7.3v9.02004-10-18
CVE-2004-1613 [MEDIUM] CVE-2004-1613: Mozilla allows remote attackers to cause a denial of service (application crash from null dereferenc
Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.
nvd
CVE-2004-0905MEDIUMCVSS 4.6v7.3v9.02004-09-14
CVE-2004-0905 [MEDIUM] CVE-2004-0905: Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
nvd
CVE-2003-0989HIGHCVSS 7.5v9.02004-02-17
CVE-2003-0989 [HIGH] CVE-2003-0989: tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certai
tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.
nvd
CVE-2003-0464MEDIUMCVSS 4.6v7.1v7.2+3 more2003-08-27
CVE-2003-0464 [MEDIUM] CVE-2003-0464: The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow loc
The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd.
nvd
CVE-2003-0552MEDIUMCVSS 5.0v2.4.22003-08-27
CVE-2003-0552 [MEDIUM] CVE-2003-0552: Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose so
Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose source addresses are the same as the target.
nvd
CVE-2003-0551MEDIUMCVSS 5.0v2.4.22003-08-27
CVE-2003-0551 [MEDIUM] CVE-2003-0551: The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could
The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could allow attackers to cause a denial of service.
nvd
CVE-2003-0550MEDIUMCVSS 5.0v2.4.22003-08-27
CVE-2003-0550 [MEDIUM] CVE-2003-0550: The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which a
The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which allows attackers to modify the bridge topology.
nvd
CVE-2003-0461LOWCVSS 2.1v7.1v7.2+3 more2003-08-27
CVE-2003-0461 [LOW] CVE-2003-0461: /proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links,
/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.
nvd
CVE-2003-0434HIGHCVSS 7.5PoCv7.1v7.2+3 more2003-07-24
CVE-2003-0434 [HIGH] CVE-2003-0434: Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to exe
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
nvd
CVE-2003-0442MEDIUMCVSS 4.3PoCv8.0v9.02003-07-24
CVE-2003-0442 [MEDIUM] CVE-2003-0442: Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.
Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.
nvd
CVE-2003-0248CRITICALCVSS 10.0v7.1v7.2+3 more2003-06-16
CVE-2003-0248 [CRITICAL] CVE-2003-0248: The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed ad
The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.
nvd
CVE-2003-0354HIGHCVSS 7.5v7.1v7.2+3 more2003-06-16
CVE-2003-0354 [HIGH] CVE-2003-0354: Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands,
Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.
nvd
CVE-2002-1155HIGHCVSS 7.2PoCv7.1v7.2+3 more2003-06-16
CVE-2002-1155 [HIGH] CVE-2002-1155: Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a lo
Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command line argument.
nvd
CVE-2003-0370HIGHCVSS 7.5v7.1v7.22003-06-16
CVE-2003-0370 [HIGH] CVE-2003-0370: Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
nvd
CVE-2003-0364MEDIUMCVSS 5.0v7.1v7.2+3 more2003-06-16
CVE-2003-0364 [MEDIUM] CVE-2003-0364: The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a d
The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a denial of service (CPU consumption) via certain packets that cause a large number of hash table collisions.
nvd
CVE-2003-0247MEDIUMCVSS 5.0v7.1v7.2+3 more2003-06-16
CVE-2003-0247 [MEDIUM] CVE-2003-0247: Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of
Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops").
nvd