cbcvebase.

Redhat Linux vulnerabilities

213 known vulnerabilities affecting redhat/linux.

Total CVEs
213
CISA KEV
0
Public exploits
72
Exploited in wild
4
Severity breakdown
CRITICAL34HIGH86MEDIUM56LOW37

Vulnerabilities

Page 8 of 11
CVE-2000-0289P4MEDIUMCVSS 5.0v6.0v6.1+1 more2000-03-27
CVE-2000-0289 [MEDIUM] CVE-2000-0289: IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal int IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection.
nvd
CVE-2004-0905P4MEDIUMCVSS 4.6v7.3v9.02004-09-14
CVE-2004-0905 [MEDIUM] CVE-2004-0905: Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
nvd
CVE-2000-0963P4HIGHCVSS 7.2v6.2v7.02000-12-19
CVE-2000-0963 [HIGH] CVE-2000-0963: Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environ Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.
nvd
CVE-1999-0131P4HIGHCVSS 7.2v3.0.31996-09-11
CVE-1999-0131 [HIGH] CVE-1999-0131: Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root a Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
nvd
CVE-2002-0506P4HIGHCVSS 7.2v6.2v7.0+2 more2002-08-12
CVE-2002-0506 [HIGH] CVE-2002-0506: Buffer overflow in newt.c of newt windowing library (libnewt) 0.50.33 and earlier may allow attacker Buffer overflow in newt.c of newt windowing library (libnewt) 0.50.33 and earlier may allow attackers to cause a denial of service or execute arbitrary code in setuid programs that use libnewt.
nvd
CVE-1999-1182P4HIGHCVSS 7.2v4.0v4.1+1 more1997-07-17
CVE-1999-1182 [HIGH] CVE-1999-1182: Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local user Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error.
nvd
CVE-2001-1028P4HIGHCVSS 7.2v5.0v5.1+4 more2001-05-28
CVE-2001-1028 [HIGH] CVE-2001-1028: Buffer overflow in ultimate_source function of man 1.5 and earlier allows local users to gain privil Buffer overflow in ultimate_source function of man 1.5 and earlier allows local users to gain privileges.
nvd
CVE-2003-0552P4MEDIUMCVSS 5.0v2.4.22003-08-27
CVE-2003-0552 [MEDIUM] CVE-2003-0552: Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose so Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose source addresses are the same as the target.
nvd
CVE-2001-0977P4MEDIUMCVSS 5.0v6.2v7.0+1 more2001-07-16
CVE-2001-0977 [MEDIUM] CVE-2001-0977: slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding Rules (BER) length field.
nvd
CVE-2003-0364P4MEDIUMCVSS 5.0v7.1v7.2+3 more2003-06-16
CVE-2003-0364 [MEDIUM] CVE-2003-0364: The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a d The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a denial of service (CPU consumption) via certain packets that cause a large number of hash table collisions.
nvd
CVE-2005-3624P4MEDIUMCVSS 5.0v7.3v9.02005-12-31
CVE-2005-3624 [MEDIUM] CWE-189 CVE-2005-3624: The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, t The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.
nvd
CVE-2001-0859P4MEDIUMCVSS 5.0v7.12001-12-06
CVE-2001-0859 [MEDIUM] CVE-2001-0859: 2.4.3-12 kernel in Red Hat Linux 7.1 Korean installation program sets the setting default umask for 2.4.3-12 kernel in Red Hat Linux 7.1 Korean installation program sets the setting default umask for init to 000, which installs files with world-writeable permissions.
nvd
CVE-1999-1335P4MEDIUMCVSS 6.4≤ 4.01999-12-31
CVE-1999-1335 [MEDIUM] CVE-1999-1335: snmpd server in cmu-snmp SNMP package before 3.3-1 in Red Hat Linux 4.0 is configured to allow remot snmpd server in cmu-snmp SNMP package before 3.3-1 in Red Hat Linux 4.0 is configured to allow remote attackers to read and write sensitive information.
nvd
CVE-2005-3626P4MEDIUMCVSS 5.0v7.3v9.02005-12-31
CVE-2005-3626 [MEDIUM] CWE-399 CVE-2005-3626: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and oth Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
nvd
CVE-2002-1232P4MEDIUMCVSS 5.0v6.2v7.0+3 more2002-11-04
CVE-2002-1232 [MEDIUM] CVE-2002-1232: Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of requests for a map that does not exist.
nvd
CVE-2003-0247P4MEDIUMCVSS 5.0v7.1v7.2+3 more2003-06-16
CVE-2003-0247 [MEDIUM] CVE-2003-0247: Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops").
nvd
CVE-2003-0550P4MEDIUMCVSS 5.0v2.4.22003-08-27
CVE-2003-0550 [MEDIUM] CVE-2003-0550: The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which a The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which allows attackers to modify the bridge topology.
nvd
CVE-2000-0314P4MEDIUMCVSS 5.0v2.0.342001-03-12
CVE-2000-0314 [MEDIUM] CVE-2000-0314: traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero.
nvd
CVE-2000-0358P4MEDIUMCVSS 5.0v6.11999-12-03
CVE-2000-0358 [MEDIUM] CVE-2000-0358: ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program. ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program.
nvd
CVE-1999-1095P4HIGHCVSS 7.2v4.11997-10-06
CVE-1999-1095 [HIGH] CVE-1999-1095: sort creates temporary files and follows symbolic links, which allows local users to modify arbitrar sort creates temporary files and follows symbolic links, which allows local users to modify arbitrary files that are writable by the user running sort, as observed in updatedb and other programs that use sort.
nvd
Redhat Linux vulnerabilities | cvebase