VendorsRed Hatenterprise_linux8.0
Vulnerabilities

Red Hat Enterprise Linux 8.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1167CVEs
CVE-2023-3354
Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of service
Published 2023-07-11 · Modified
7.5EPSS 0.016
CVE-2021-3839
A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.
Published 2022-08-23 · Modified
7.5EPSS 0.016
CVE-2023-5156
Glibc: dos due to memory leak in getaddrinfo.c
Published 2023-09-25 · Modified
7.5EPSS 0.016
CVE-2023-2295
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Published 2023-05-17 · Modified
7.5EPSS 0.016
CVE-2025-3891
Mod_auth_openidc: dos via empty post in mod_auth_openidc with oidcpreservepost enabled
Published 2025-04-29 · Modified
7.5EPSS 0.016
CVE-2023-6536
Kernel: null pointer dereference in __nvmet_req_complete
Published 2024-02-07 · Modified
7.5EPSS 0.015
CVE-2023-6535
Kernel: null pointer dereference in nvmet_tcp_execute_request
Published 2024-02-07 · Modified
7.5EPSS 0.015
CVE-2024-7006
Libtiff: null pointer dereference in tif_dirinfo.c
Published 2024-08-08 · Modified
7.5EPSS 0.015
CVE-2022-1949
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.
Published 2022-06-01 · Modified
7.5EPSS 0.015
CVE-2023-6356
Kernel: null pointer dereference in nvmet_tcp_build_iovec
Published 2024-02-07 · Modified
7.5EPSS 0.015
CVE-2022-27649
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Published 2022-04-04 · Modified
7.5EPSS 0.014
CVE-2022-2963
A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.
Published 2022-10-14 · Modified
7.5EPSS 0.014
CVE-2025-6021
Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2
Published 2025-06-12 · Modified
7.5EPSS 0.014
CVE-2026-4271
Libsoup: libsoup: denial of service via use-after-free in http/2 server
Published 2026-03-17 · Modified
7.5EPSS 0.013
CVE-2026-35092
Corosync: corosync: denial of service via integer overflow in join message validation
Published 2026-04-01 · Modified
7.5EPSS 0.013
CVE-2022-27650
A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Published 2022-04-04 · Modified
7.5EPSS 0.013
CVE-2025-7424
Libxslt: type confusion in xmlnode.psvi between stylesheet and source nodes
Published 2025-07-10 · Modified
7.5EPSS 0.012
CVE-2026-5201
Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image
Published 2026-03-31 · Modified
7.5EPSS 0.012
CVE-2020-10705
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.
Published 2020-06-10 · Modified
7.5EPSS 0.012
CVE-2021-3632
A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.
Published 2022-08-26 · Modified
7.5EPSS 0.011
CVE-2026-42009
Gnutls: gnutls: denial of service via dtls packet reordering vulnerability
Published 2026-05-18 · Modified
7.5EPSS 0.011
CVE-2023-50781
M2crypto: bleichenbacher timing attacks in the rsa decryption api - incomplete fix for cve-2020-25657
Published 2024-02-05 · Analyzed
7.5EPSS 0.011
CVE-2023-50782
Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659
Published 2024-02-05 · Modified
7.5EPSS 0.011
CVE-2021-3445
A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2021-05-19 · Modified
7.5EPSS 0.011
CVE-2024-2002
Libdwarf: crashes randomly on fuzzed object
Published 2024-03-18 · Analyzed
7.5EPSS 0.011
CVE-2026-9064
389-ds-base: 389-ds-base: unbounded ldap controls count in get_ldapmessage_controls_ext() causes cpu and heap amplification (remote dos)
Published 2026-05-20 · Modified
7.5EPSS 0.011
CVE-2026-4424
Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing
Published 2026-03-19 · Modified
7.5EPSS 0.011
CVE-2026-46625
JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection
Published 2026-06-10 · Modified
7.5EPSS 0.010
CVE-2026-6732
Libxml2: libxml2: denial of service via crafted xsd-validated document
Published 2026-04-23 · Analyzed
7.5EPSS 0.009
CVE-2026-58015
Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive
Published 2026-06-30 · Modified
7.5EPSS 0.009
CVE-2023-6476
Cri-o: pods are able to break out of resource confinement on cgroupv2
Published 2024-01-09 · Modified
7.5EPSS 0.009
CVE-2023-0813
Network-observability-console-plugin-container: setting loki authtoken configuration to disable or host mode leads to authentication longer being enforced
Published 2023-09-15 · Modified
7.5EPSS 0.009
CVE-2023-3171
Eap-7: heap exhaustion via deserialization
Published 2023-12-27 · Modified
7.5EPSS 0.009
CVE-2026-15722
389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsing
Published 2026-07-31 · Modified
7.5EPSS 0.008
CVE-2026-58011
Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime
Published 2026-06-30 · Modified
7.5EPSS 0.008
CVE-2023-5625
Python-eventlet: patch regression for cve-2021-21419 in some red hat builds
Published 2023-11-01 · Modified
7.5EPSS 0.008
CVE-2024-6239
Poppler: pdfinfo: crash in broken documents when using -dests parameter
Published 2024-06-21 · Modified
7.5EPSS 0.008
CVE-2023-4503
Eap-galleon: custom provisioning creates unsecured http-invoker
Published 2024-02-06 · Modified
7.5EPSS 0.007
CVE-2021-3698
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.
Published 2022-03-08 · Modified
7.5EPSS 0.007
CVE-2026-59850
Libssh: libssh: use-after-free via data callbacks on closed channels
Published 2026-07-21 · Modified
7.5EPSS 0.006
← Prev11 / 30Next →