Redhat Linux vulnerabilities
213 known vulnerabilities affecting redhat/linux.
Total CVEs
213
CISA KEV
0
Public exploits
72
Exploited in wild
4
Severity breakdown
CRITICAL34HIGH86MEDIUM56LOW37
Vulnerabilities
Page 2 of 11
CVE-1999-0042P3CRITICALCVSS 10.0PoCv2.0v4.01997-04-07
CVE-1999-0042 [CRITICAL] CVE-1999-0042: Buffer overflow in University of Washington's implementation of IMAP and POP servers.
Buffer overflow in University of Washington's implementation of IMAP and POP servers.
nvd
CVE-1999-0710P3HIGHCVSS 7.5PoCv5.2v6.01999-07-25
CVE-1999-0710 [HIGH] CVE-1999-0710: The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a
The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.
nvd
CVE-2002-0068P3HIGHCVSS 7.5PoCv6.2v7.0+2 more2002-03-08
CVE-2002-0068 [HIGH] CVE-2002-0068: Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and p
Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an ftp:// URL with a larger number of special characters, which exceed the buffer when Squid URL-escapes the characters.
nvd
CVE-2018-20346P3HIGHCVSS 8.1v6.02018-12-21
CVE-2018-20346 [HIGH] CWE-190 CVE-2018-20346: SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and result
SQLite before 3.25.3, when the FTS3 extension is enabled, encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables, allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases), aka Magell
nvd
CVE-2002-0002P3HIGHCVSS 7.5PoCv7.22002-01-31
CVE-2002-0002 [HIGH] CVE-2002-0002: Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, o
Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code.
nvd
CVE-1999-0041P4HIGHCVSS 7.5PoCv4.01997-02-13
CVE-1999-0041 [HIGH] CVE-1999-0041: Buffer overflow in NLS (Natural Language Service).
Buffer overflow in NLS (Natural Language Service).
nvd
CVE-1999-0997P4HIGHCVSS 7.5PoCv5.2v6.0+1 more1999-12-20
CVE-1999-0997 [HIGH] CVE-1999-0997: wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name
wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.
nvd
CVE-1999-0043P3CRITICALCVSS 9.8v4.0v4.11996-12-04
CVE-1999-0043 [CRITICAL] CWE-78 CVE-1999-0043: Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" contro
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
nvd
CVE-1999-0704P4CRITICALCVSS 9.3PoCv4.2v5.0+3 more1999-09-16
CVE-1999-0704 [CRITICAL] CVE-1999-0704: Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils
Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others.
nvd
CVE-2005-0750P4HIGHCVSS 7.2PoCv7.3v9.02005-03-27
CVE-2005-0750 [HIGH] CVE-2005-0750: The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.
nvd
CVE-1999-0768P4HIGHCVSS 7.5PoCv4.2v5.2+1 more1999-08-25
CVE-1999-0768 [HIGH] CVE-1999-0768: Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.
Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.
nvd
CVE-2000-0668P4MEDIUMCVSS 5.0PoCv6.0v6.1+1 more2000-07-27
CVE-2000-0668 [MEDIUM] CVE-2000-0668: pam_console PAM module in Linux systems allows a user to access the system console and reboot the sy
pam_console PAM module in Linux systems allows a user to access the system console and reboot the system when a display manager such as gdm or kdm has XDMCP enabled.
nvd
CVE-2004-1235P4MEDIUMCVSS 6.2PoCv7.3v9.02005-04-14
CVE-2004-1235 [MEDIUM] CVE-2004-1235: Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux ke
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
nvd
CVE-2000-0229P4HIGHCVSS 7.2PoCv6.0v6.1+1 more2000-03-22
CVE-2000-0229 [HIGH] CVE-2000-0229: gpm-root in the gpm package does not properly drop privileges, which allows local users to gain priv
gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a utility from gpm-root.
nvd
CVE-2000-0170P4HIGHCVSS 7.2PoCv4.0v4.1+6 more2000-02-26
CVE-2000-0170 [HIGH] CVE-2000-0170: Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER e
Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable.
nvd
CVE-1999-1491P4HIGHCVSS 7.2PoCv2.11996-02-02
CVE-1999-1491 [HIGH] CVE-1999-1491: abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which al
abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.
nvd
CVE-2000-1095P4HIGHCVSS 7.2PoCv7.02001-01-09
CVE-2000-1095 [HIGH] CVE-2000-1095: modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary com
modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.
nvd
CVE-1999-0130P4HIGHCVSS 7.2PoCv4.01996-11-16
CVE-1999-0130 [HIGH] CVE-1999-0130: Local users can start Sendmail in daemon mode and gain root privileges.
Local users can start Sendmail in daemon mode and gain root privileges.
nvd
CVE-2003-0019P4HIGHCVSS 7.2PoCv8.02003-02-19
CVE-2003-0019 [HIGH] CVE-2003-0019: uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, whic
uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.
nvd
CVE-2002-0004P4HIGHCVSS 7.2PoCv6.2v7.0+2 more2002-02-27
CVE-2002-0004 [HIGH] CVE-2002-0004: Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.
nvd