VendorsRed Hatenterprise_linux8.0
Vulnerabilities

Red Hat Enterprise Linux 8.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1167CVEs
CVE-2018-14464
The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().
Published 2019-10-03 · Modified
7.5EPSS 0.040
CVE-2018-14461
The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().
Published 2019-10-03 · Modified
7.5EPSS 0.040
CVE-2018-14466
The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert().
Published 2019-10-03 · Modified
7.5EPSS 0.040
CVE-2018-14467
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP).
Published 2019-10-03 · Modified
7.5EPSS 0.040
CVE-2018-14468
The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().
Published 2019-10-03 · Modified
7.5EPSS 0.040
CVE-2018-14462
The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().
Published 2019-10-03 · Modified
7.5EPSS 0.040
CVE-2018-14470
The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2().
Published 2019-10-03 · Modified
7.5EPSS 0.040
CVE-2022-27191
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
Published 2022-03-18 · Modified
7.5EPSS 0.039
CVE-2020-25648
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
Published 2020-10-20 · Modified
7.5EPSS 0.039
CVE-2019-10184
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
Published 2019-07-25 · Modified
7.5EPSS 0.035
CVE-2020-25643
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2020-10-06 · Modified
7.5EPSS 0.033
CVE-2020-27827
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
Published 2021-03-18 · Modified
7.5EPSS 0.032
CVE-2021-41817
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
Published 2022-01-01 · Modified
7.5EPSS 0.032
CVE-2021-41819
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
Published 2022-01-01 · Modified
7.5EPSS 0.029
CVE-2021-3610
A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.
Published 2022-02-24 · Modified
7.5EPSS 0.028
CVE-2021-20270
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
Published 2021-03-23 · Modified
7.5EPSS 0.028
CVE-2021-3580
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service.
Published 2021-08-05 · Modified
7.5EPSS 0.027
CVE-2019-14494
An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.
Published 2019-08-01 · Modified
7.5EPSS 0.027
CVE-2023-3223
Undertow: outofmemoryerror due to @multipartconfig handling
Published 2023-09-27 · Modified
7.5EPSS 0.027
CVE-2020-8595
Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even if they are configured to be only accessed after presenting a valid JWT token. For example, an attacker can add a ? or # character to a URI that would otherwise satisfy an exact-path match.
Published 2020-02-12 · Modified
7.5EPSS 0.026
CVE-2019-10245
In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.
Published 2019-04-19 · Modified
7.5EPSS 0.025
CVE-2022-0934
A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a crafted packet processed by dnsmasq, potentially causing a denial of service.
Published 2022-08-29 · Modified
7.5EPSS 0.025
CVE-2018-10393
bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.
Published 2018-04-26 · Modified
7.5EPSS 0.024
CVE-2025-9784
Undertow: undertow madeyoureset http/2 ddos vulnerability
Published 2025-09-02 · Modified
7.5EPSS 0.023
CVE-2024-12087
Rsync: path traversal vulnerability in rsync
Published 2025-01-14 · Modified
7.5EPSS 0.023
CVE-2020-27778
A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service.
Published 2020-12-03 · Modified
7.5EPSS 0.022
CVE-2023-52356
Libtiff: segment fault in libtiff in tiffreadrgbatileext() leading to denial of service
Published 2024-01-25 · Modified
7.5EPSS 0.022
CVE-2023-5157
Mariadb: node crashes with transport endpoint is not connected mysqld got signal 6
Published 2023-09-26 · Modified
7.5EPSS 0.020
CVE-2022-2509
A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.
Published 2022-08-01 · Modified
7.5EPSS 0.020
CVE-2020-36332
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
Published 2021-05-21 · Modified
7.5EPSS 0.020
CVE-2023-44488
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
Published 2023-09-30 · Modified
7.5EPSS 0.019
CVE-2023-2953
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
Published 2023-05-30 · Modified
7.5EPSS 0.019
CVE-2023-52355
Libtiff: tiffrasterscanlinesize64 produce too-big size and could cause oom
Published 2024-01-25 · Modified
7.5EPSS 0.018
CVE-2023-1108
Undertow: infinite loop in sslconduit during close
Published 2023-09-14 · Modified
7.5EPSS 0.018
CVE-2020-14372
A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System Description Table (SSDT) containing code to overwrite the Linux kernel lockdown variable content directly into memory. The table is further loaded and executed by the kernel, defeating its Secure Boot lockdown and allowing the attacker to load unsigned code. The highest threat from this vulnerability is to data confidentiality and integrity, as well as system availability.
Published 2021-03-03 · Modified
7.5EPSS 0.017
CVE-2021-3690
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
Published 2022-08-23 · Modified
7.5EPSS 0.017
CVE-2023-3138
A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.
Published 2023-06-28 · Modified
7.5EPSS 0.017
CVE-2020-25708
A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a floating point exception, resulting in a denial of service.
Published 2020-11-27 · Modified
7.5EPSS 0.016
CVE-2021-4213
A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.
Published 2022-08-24 · Modified
7.5EPSS 0.016
CVE-2024-0553
Gnutls: incomplete fix for cve-2023-5981
Published 2024-01-16 · Modified
7.5EPSS 0.016
← Prev10 / 30Next →