Redhat Linux vulnerabilities
213 known vulnerabilities affecting redhat/linux.
Total CVEs
213
CISA KEV
0
Public exploits
72
Exploited in wild
4
Severity breakdown
CRITICAL34HIGH86MEDIUM56LOW37
Vulnerabilities
Page 5 of 11
CVE-2001-0869P4HIGHCVSS 7.5v7.0v7.22001-12-21
CVE-2001-0869 [HIGH] CVE-2001-0869: Format string vulnerability in the default logging callback function _sasl_syslog in common.c in Cyr
Format string vulnerability in the default logging callback function _sasl_syslog in common.c in Cyrus SASL library (cyrus-sasl) may allow remote attackers to execute arbitrary commands.
nvd
CVE-2001-0473P4HIGHCVSS 7.5v5.2v6.0+3 more2001-06-27
CVE-2001-0473 [HIGH] CVE-2001-0473: Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute ar
Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands.
nvd
CVE-2000-0093P4CRITICALCVSS 10.0v6.12000-01-21
CVE-2000-0093 [CRITICAL] CVE-2000-0093: An installation of Red Hat uses DES password encryption with crypt() for the initial password, inste
An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5.
nvd
CVE-2004-1025P4CRITICALCVSS 10.0v7.3v9.02005-01-10
CVE-2004-1025 [CRITICAL] CVE-2004-1025: Multiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and sever
Multiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.
nvd
CVE-2004-1026P4CRITICALCVSS 10.0v7.3v9.02005-01-10
CVE-2004-1026 [CRITICAL] CVE-2004-1026: Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrel
Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.
nvd
CVE-2000-0336P4LOWCVSS 2.1PoCv6.1v6.22000-04-21
CVE-2000-0336 [LOW] CVE-2000-0336: Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.
Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.
nvd
CVE-2002-0067P4HIGHCVSS 7.5v6.2v7.0+2 more2002-03-08
CVE-2002-0067 [HIGH] CVE-2002-0067: Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified i
Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified in squid.conf, which could allow remote attackers to bypass intended access restrictions.
nvd
CVE-2004-0079P4HIGHCVSS 7.5v7.2v7.3+1 more2004-11-23
CVE-2004-0079 [HIGH] CWE-476 CVE-2004-0079: The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
nvd
CVE-2004-1335P4LOWCVSS 2.1PoCv7.3v9.02004-12-15
CVE-2004-1335 [LOW] CVE-2004-1335: Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to c
Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function.
nvd
CVE-2001-0736P4LOWCVSS 2.1PoCv5.2v6.2+1 more2001-10-18
CVE-2001-0736 [LOW] CVE-2001-0736: Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local user
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.
nvd
CVE-1999-1299P4CRITICALCVSS 10.0v4.01997-02-03
CVE-1999-1299 [CRITICAL] CVE-1999-1299: rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of
rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system calls, which causes the calls to fail to modify the ownership of the file.
nvd
CVE-2007-5079P4MEDIUMCVSS 6.0v4.02007-09-25
CVE-2007-5079 [MEDIUM] CVE-2007-5079: Red Hat Enterprise Linux 4 does not properly compile and link gdm with tcp_wrappers on x86_64 platfo
Red Hat Enterprise Linux 4 does not properly compile and link gdm with tcp_wrappers on x86_64 platforms, which might allow remote attackers to bypass intended access restrictions.
nvd
CVE-1999-1333P4HIGHCVSS 7.5≤ 5.01999-12-31
CVE-1999-1333 [HIGH] CVE-1999-1333: automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote a
automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded.
nvd
CVE-2001-0441P4HIGHCVSS 7.5v6.2v7.02001-06-27
CVE-2001-0441 [HIGH] CVE-2001-0441: Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allo
Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.
nvd
CVE-2000-0263P4LOWCVSS 2.1PoCv6.0v6.1+1 more2000-04-16
CVE-2000-0263 [LOW] CVE-2000-0263: The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a mal
The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.
nvd
CVE-2000-0531P4LOWCVSS 2.1PoCv6.0v6.11999-11-23
CVE-2000-0531 [LOW] CVE-2000-0531: Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device
Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets.
nvd
CVE-1999-0832P4CRITICALCVSS 10.0v5.21999-11-09
CVE-1999-0832 [CRITICAL] CVE-1999-0832: Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname.
Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname.
nvd
CVE-2023-5981P4MEDIUMCVSS 5.9v8.0v9.02023-11-28
CVE-2023-5981 [MEDIUM] CWE-208 CVE-2023-5981: A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExcha
A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
nvd
CVE-2003-0354P4HIGHCVSS 7.5v7.1v7.2+3 more2003-06-16
CVE-2003-0354 [HIGH] CVE-2003-0354: Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands,
Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.
nvd
CVE-2000-0829P4LOWCVSS 2.1PoCv6.12000-11-14
CVE-2000-0829 [LOW] CVE-2000-0829: The tmpwatch utility in Red Hat Linux forks a new process for each directory level, which allows loc
The tmpwatch utility in Red Hat Linux forks a new process for each directory level, which allows local users to cause a denial of service by creating deeply nested directories in /tmp or /var/tmp/.
nvd