VendorsRed Hatenterprise_linux9.0
Vulnerabilities

Red Hat Enterprise Linux 9.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

601CVEs
CVE-2026-11789
389-ds-base: 389-ds-base: smd5 password storage plugin salt length integer underflow crash
Published 2026-06-09 · Modified
6.5EPSS 0.003
CVE-2026-11611
389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditions
Published 2026-06-08 · Modified
6.5EPSS 0.002
CVE-2026-18726
Open-iscsi: open-iscsi: denial of service in iscsiuio router advertisement parsing
Published 2026-08-12 · Analyzed
6.5EPSS 0.002
CVE-2026-18728
Open-iscsi: open-iscsi: integer underflow in iscsiuio ipv4 dhcp parsing
Published 2026-08-13 · Analyzed
6.5EPSS 0.002
CVE-2026-18727
Open-iscsi: open-iscsi: integer underflow in iscsiuio dhcpv6 parsing
Published 2026-08-12 · Analyzed
6.5EPSS 0.002
CVE-2026-11786
389-ds-base: 389-ds-base: heap out-of-bounds read in ldif parser str2entry_state_information_from_type()
Published 2026-06-09 · Modified
6.5EPSS 0.002
CVE-2023-40661
Opensc: multiple memory issues with pkcs15-init (enrollment tool)
Published 2023-11-06 · Modified
6.4EPSS 0.012
CVE-2023-33203
The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device.
Published 2023-05-18 · Modified
6.4EPSS 0.003
CVE-2021-35937
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2022-08-25 · Modified
6.4EPSS 0.003
CVE-2026-12610
Sssd: use-after-free crash in sssd' 'sssd_pam' process
Published 2026-06-30 · Undergoing Analysis
6.4EPSS 0.001
CVE-2023-5115
Ansible: malicious role archive can cause ansible-galaxy to overwrite arbitrary files
Published 2023-12-18 · Modified
6.3EPSS 0.010
CVE-2023-4380
Platform: token exposed at importing project
Published 2023-10-04 · Modified
6.3EPSS 0.006
CVE-2026-0964
Libssh: improper sanitation of paths received from scp servers
Published 2026-03-26 · Modified
6.3EPSS 0.004
CVE-2022-1462
An out-of-bounds read flaw was found in the Linux kernel’s TeleTYpe subsystem. The issue occurs in how a user triggers a race condition using ioctls TIOCSPTLCK and TIOCGPTPEER and TIOCSTI and TCXONC with leakage of memory in the flush_to_ldisc function. This flaw allows a local user to crash the system or read unauthorized random data from memory.
Published 2022-05-31 · Modified
6.3EPSS 0.003
CVE-2026-11787
389-ds-base: 389-ds-base: heap buffer over-read in ldap_utf8prev() via str2simple filter parsing
Published 2026-06-09 · Modified
6.3EPSS 0.002
CVE-2026-73585
Sblim-cmpi-base: insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack
Published 2026-08-13 · Analyzed
6.3EPSS 0.001
CVE-2026-71222
Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing
Published 2026-09-03 · Analyzed
6.3EPSS 0.001
CVE-2026-73584
Sblim-sfcb: sblim-sfcb: privileged file corruption and denial of service via insecure temporary file handling
Published 2026-08-13 · Analyzed
6.3EPSS 0.001
CVE-2023-40546
Shim: out-of-bounds read printing error messages
Published 2024-01-29 · Modified
6.2EPSS 0.004
CVE-2023-40549
Shim: out-of-bounds read in verify_buffer_authenticode() malformed pe file
Published 2024-01-29 · Modified
6.2EPSS 0.004
CVE-2022-4900
Potential buffer overflow in php_cli_server_startup_workers
Published 2023-11-02 · Modified
6.2EPSS 0.004
CVE-2023-38471
Reachable assertion in dbus_set_host_name
Published 2023-11-02 · Modified
6.2EPSS 0.003
CVE-2023-38469
Reachable assertion in avahi_dns_packet_append_record
Published 2023-11-02 · Modified
6.2EPSS 0.003
CVE-2023-38470
Reachable assertion in avahi_escape_label
Published 2023-11-02 · Modified
6.2EPSS 0.003
CVE-2023-38472
Reachable assertion in avahi_rdata_parse
Published 2023-11-02 · Modified
6.2EPSS 0.003
CVE-2023-38473
Reachable assertion in avahi_alternative_host_name
Published 2023-11-02 · Modified
6.2EPSS 0.003
CVE-2023-6915
Kernel: null pointer dereference vulnerability in ida_free in lib/idr.c
Published 2024-01-15 · Modified
6.2EPSS 0.003
CVE-2024-8235
Libvirt: crash of virtinterfaced via virconnectlistinterfaces()
Published 2024-08-30 · Modified
6.2EPSS 0.002
CVE-2026-13757
P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing
Published 2026-06-29 · Modified
6.2EPSS 0.002
CVE-2022-1355
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.
Published 2022-08-31 · Modified
6.1EPSS 0.006
CVE-2023-39193
Kernel: netfilter: xtables sctp out-of-bounds read in match_flags()
Published 2023-10-09 · Modified
6.1EPSS 0.004
CVE-2024-10033
Aap-gateway: xss on aap-gateway
Published 2024-10-16 · Modified
6.1EPSS 0.004
CVE-2026-40919
Gimp: gimp: denial of service via specially crafted seattle filmworks file
Published 2026-04-15 · Analyzed
6.1EPSS 0.003
CVE-2026-82324
Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=0
Published 2026-08-28 · Analyzed
6.1EPSS 0.003
CVE-2026-82343
Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handling
Published 2026-08-28 · Analyzed
6.1EPSS 0.003
CVE-2026-82330
Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check
Published 2026-08-28 · Analyzed
6.1EPSS 0.003
CVE-2026-82328
Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count
Published 2026-08-28 · Analyzed
6.1EPSS 0.003
CVE-2026-78475
Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader
Published 2026-08-24 · Analyzed
6.1EPSS 0.003
CVE-2026-4647
Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library
Published 2026-03-23 · Modified
6.1EPSS 0.002
CVE-2026-1766
Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and information disclosure via malformed mp3 files.
Published 2026-06-16 · Analyzed
6.1EPSS 0.002
← Prev10 / 16Next →