cbcvebase.

Redhat Linux vulnerabilities

213 known vulnerabilities affecting redhat/linux.

Total CVEs
213
CISA KEV
0
Public exploits
72
Exploited in wild
4
Severity breakdown
CRITICAL34HIGH86MEDIUM56LOW37

Vulnerabilities

Page 6 of 11
CVE-2005-3625P4CRITICALCVSS 10.0v7.3v9.02005-12-31
CVE-2005-3625 [CRITICAL] CWE-399 CVE-2005-3625: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and oth Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
nvd
CVE-2003-0248P4CRITICALCVSS 10.0v7.1v7.2+3 more2003-06-16
CVE-2003-0248 [CRITICAL] CVE-2003-0248: The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed ad The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.
nvd
CVE-2000-0750P4HIGHCVSS 7.5v6.0v6.1+1 more2000-10-20
CVE-2000-0750 [HIGH] CVE-2000-0750: Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to e Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name.
nvd
CVE-2003-0989P4HIGHCVSS 7.5v9.02004-02-17
CVE-2003-0989 [HIGH] CVE-2003-0989: tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certai tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.
nvd
CVE-2000-0286P4LOWCVSS 2.1PoCv6.0v6.1+1 more2000-04-16
CVE-2000-0286 [LOW] CVE-2000-0286: X fontserver xfs allows local users to cause a denial of service via malformed input to the server. X fontserver xfs allows local users to cause a denial of service via malformed input to the server.
nvd
CVE-2000-0196P4HIGHCVSS 7.5v5.2v6.0+1 more2000-02-28
CVE-2000-0196 [HIGH] CVE-2000-0196: Buffer overflow in mhshow in the Linux nmh package allows remote attackers to execute commands via m Buffer overflow in mhshow in the Linux nmh package allows remote attackers to execute commands via malformed MIME headers in an email message.
nvd
CVE-1999-0706P4HIGHCVSS 7.5v4.1v4.2+4 more2000-04-27
CVE-1999-0706 [HIGH] CVE-1999-0706: Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH envir Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH environmental variables.
nvd
CVE-2005-0206P4HIGHCVSS 7.5v9.02005-04-27
CVE-2005-0206 [HIGH] CVE-2005-0206: The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
nvd
CVE-2001-1030P4HIGHCVSS 7.5v7.02001-07-18
CVE-2001-1030 [HIGH] CVE-2001-1030: Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when th Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.
nvd
CVE-2003-0135P4HIGHCVSS 7.5v9.02003-04-11
CVE-2003-0135 [HIGH] CVE-2003-0135: vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is inst vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended.
nvd
CVE-2000-1213P4HIGHCVSS 7.5v6.2v7.02000-10-18
CVE-2000-1213 [HIGH] CVE-2000-1213: ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping's exposure to bugs that otherwise would occur at lower privileges.
nvd
CVE-1999-0868P4HIGHCVSS 7.2v4.0v4.11997-02-20
CVE-1999-0868 [HIGH] CVE-1999-0868: ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it f ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.
nvd
CVE-2004-0112P4MEDIUMCVSS 5.0v7.2v7.3+1 more2004-11-23
CVE-2004-0112 [MEDIUM] CWE-125 CVE-2004-0112: The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
nvd
CVE-2002-0045P4HIGHCVSS 7.5v7.0v7.1+1 more2002-01-31
CVE-2002-0045 [HIGH] CVE-2002-0045: slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduc slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls without any values, which causes OpenLDAP to delete non-mandatory attributes that would otherwise be protected by ACLs.
nvd
CVE-2003-0370P4HIGHCVSS 7.5v7.1v7.22003-06-16
CVE-2003-0370 [HIGH] CVE-2003-0370: Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
nvd
CVE-1999-0434P4HIGHCVSS 7.5v5.11999-03-30
CVE-1999-0434 [HIGH] CVE-1999-0434: XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restr XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.
nvd
CVE-2001-0872P4HIGHCVSS 7.2v7.0v7.1+1 more2001-12-21
CVE-2001-0872 [HIGH] CVE-2001-0872: OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment varia OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges.
nvd
CVE-2000-0392P4HIGHCVSS 7.2v6.22000-05-16
CVE-2000-0392 [HIGH] CVE-2000-0392: Buffer overflow in ksu in Kerberos 5 allows local users to gain root privileges. Buffer overflow in ksu in Kerberos 5 allows local users to gain root privileges.
nvd
CVE-2000-0357P4HIGHCVSS 7.5v6.11999-12-03
CVE-2000-0357 [HIGH] CVE-2000-0357: ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local use ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.
nvd
CVE-1999-1346P4HIGHCVSS 7.5≤ 6.11999-10-07
CVE-1999-1346 [HIGH] CVE-1999-1346: PAM configuration file for rlogin in Red Hat Linux 6.1 and earlier includes a less restrictive rule PAM configuration file for rlogin in Red Hat Linux 6.1 and earlier includes a less restrictive rule before a more restrictive one, which allows users to access the host via rlogin even if rlogin has been explicitly disabled using the /etc/nologin file.
nvd
Redhat Linux vulnerabilities | cvebase