Redhat Linux vulnerabilities
213 known vulnerabilities affecting redhat/linux.
Total CVEs
213
CISA KEV
0
Public exploits
72
Exploited in wild
4
Severity breakdown
CRITICAL34HIGH86MEDIUM56LOW37
Vulnerabilities
Page 9 of 11
CVE-2003-0551P4MEDIUMCVSS 5.0v2.4.22003-08-27
CVE-2003-0551 [MEDIUM] CVE-2003-0551: The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could
The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could allow attackers to cause a denial of service.
nvd
CVE-2001-0309P4MEDIUMCVSS 5.0v6.22001-06-02
CVE-2001-0309 [MEDIUM] CVE-2001-0309: inetd in Red Hat 6.2 does not properly close sockets for internal services such as chargen, daytime,
inetd in Red Hat 6.2 does not properly close sockets for internal services such as chargen, daytime, echo, etc., which allows remote attackers to cause a denial of service via a series of connections to the internal services.
nvd
CVE-2000-0934P4HIGHCVSS 7.2v5.22000-12-19
CVE-2000-0934 [HIGH] CVE-2000-0934: Glint in Red Hat Linux 5.2 allows local users to overwrite arbitrary files and cause a denial of ser
Glint in Red Hat Linux 5.2 allows local users to overwrite arbitrary files and cause a denial of service via a symlink attack.
nvd
CVE-2001-0886P4MEDIUMCVSS 4.6≤ 7.2v6.2+2 more2001-12-21
CVE-2001-0886 [MEDIUM] CVE-2001-0886: Buffer overflow in glob function of glibc allows attackers to cause a denial of service (crash) and
Buffer overflow in glob function of glibc allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a glob pattern that ends in a brace "{" character.
nvd
CVE-1999-1048P4MEDIUMCVSS 4.6v4.21998-09-05
CVE-1999-1048 [MEDIUM] CVE-1999-1048: Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges
Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that directory.
nvd
CVE-2000-0356P4MEDIUMCVSS 4.6v6.11999-10-13
CVE-2000-0356 [MEDIUM] CVE-2000-0356: Pluggable Authentication Modules (PAM) in Red Hat Linux 6.1 does not properly lock access to disable
Pluggable Authentication Modules (PAM) in Red Hat Linux 6.1 does not properly lock access to disabled NIS accounts.
nvd
CVE-2002-0638P4MEDIUMCVSS 6.2v6.0v6.1+5 more2002-08-12
CVE-2002-0638 [MEDIUM] CVE-2002-0638: setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operat
setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary file when modifying /etc/passwd, which may allow local users to gain privileges via a complex race condition that uses an open file descriptor in utility programs such as chfn and chsh.
nvd
CVE-2002-0069P4LOWCVSS 2.6v6.2v7.0+2 more2002-03-08
CVE-2002-0069 [LOW] CVE-2002-0069: Memory leak in SNMP in Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of se
Memory leak in SNMP in Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service.
nvd
CVE-2002-2185P4MEDIUMCVSS 4.9v6.2v7.0+3 more2002-12-31
CVE-2002-2185 [MEDIUM] CVE-2002-2185: The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
nvd
CVE-2000-0315P4MEDIUMCVSS 5.0v2.0.342001-03-12
CVE-2000-0315 [MEDIUM] CVE-2000-0315: traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source ad
traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.
nvd
CVE-2004-1613P4MEDIUMCVSS 5.0v7.3v9.02004-10-18
CVE-2004-1613 [MEDIUM] CVE-2004-1613: Mozilla allows remote attackers to cause a denial of service (application crash from null dereferenc
Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.
nvd
CVE-1999-0011P4MEDIUMCVSS 5.4v4.2v5.01998-04-08
CVE-1999-0011 [MEDIUM] CWE-1067 CVE-1999-0011: Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer
Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.
nvd
CVE-2000-1214P4MEDIUMCVSS 4.6v6.2v7.02000-10-18
CVE-2000-1214 [MEDIUM] CVE-2000-1214: Buffer overflows in the (1) outpack or (2) buf variables of ping in iputils before 20001010, as dist
Buffer overflows in the (1) outpack or (2) buf variables of ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, may allow local users to gain privileges.
nvd
CVE-2001-0496P4MEDIUMCVSS 4.6v7.12001-06-27
CVE-2001-0496 [MEDIUM] CVE-2001-0496: kdesu in kdelibs package creates world readable temporary files containing authentication info, whic
kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.
nvd
CVE-1999-0010P4MEDIUMCVSS 5.0v4.2v5.01998-04-08
CVE-1999-0010 [MEDIUM] CVE-1999-0010: Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.
nvd
CVE-2000-0566P4HIGHCVSS 7.2v5.2v6.0+2 more2000-07-03
CVE-2000-0566 [HIGH] CVE-2000-0566: makewhatis in Linux man package allows local users to overwrite files via a symlink attack.
makewhatis in Linux man package allows local users to overwrite files via a symlink attack.
nvd
CVE-1999-0740P4MEDIUMCVSS 6.4v4.2v5.2+1 more1999-08-19
CVE-1999-0740 [MEDIUM] CVE-1999-0740: Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed
Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.
nvd
CVE-2000-0031P4MEDIUMCVSS 6.2v6.0v6.12000-10-20
CVE-2000-0031 [MEDIUM] CVE-2000-0031: The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack.
The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack.
nvd
CVE-2001-1375P4MEDIUMCVSS 4.6v7.02001-07-19
CVE-2001-1375 [MEDIUM] CVE-2001-1375: tcl/tk package (tcltk) 8.3.1 searches for its libraries in the current working directory before othe
tcl/tk package (tcltk) 8.3.1 searches for its libraries in the current working directory before other directories, which could allow local users to execute arbitrary code via a Trojan horse library that is under a user-controlled directory.
nvd
CVE-2003-0194P4MEDIUMCVSS 4.6v7.1v7.2+3 more2003-06-09
CVE-2003-0194 [MEDIUM] CVE-2003-0194: tcpdump does not properly drop privileges to the pcap user when starting up.
tcpdump does not properly drop privileges to the pcap user when starting up.
nvd