VendorsRed Hatenterprise_linux9.0
Vulnerabilities

Red Hat Enterprise Linux 9.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

601CVEs
CVE-2026-73434
Gstreamer1-plugins-good: gstreamer: out-of-bounds read in avidemux vprp video field descriptor parsing
Published 2026-08-12 · Undergoing Analysis
6.1EPSS 0.001
CVE-2026-55655
Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions
Published 2026-06-23 · Modified
6.1EPSS 0.001
CVE-2023-39189
Kernel: netfilter: nftables out-of-bounds read in nf_osf_match_one()
Published 2023-10-09 · Modified
6.0EPSS 0.004
CVE-2021-4158
A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition.
Published 2022-08-24 · Modified
6.0EPSS 0.004
CVE-2023-5090
Kernel: kvm: svm: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs
Published 2023-11-06 · Modified
6.0EPSS 0.002
CVE-2023-48795
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.
Published 2023-12-18 · Modified
5.9EPSS 0.933
CVE-2023-4813
Glibc: potential use-after-free in gaih_inet()
Published 2023-09-12 · Modified
5.9EPSS 0.019
CVE-2022-2127
Samba: out-of-bounds read in winbind auth_crap
Published 2023-07-20 · Modified
5.9EPSS 0.017
CVE-2023-4806
Glibc: potential use-after-free in getaddrinfo()
Published 2023-09-18 · Modified
5.9EPSS 0.016
CVE-2023-5992
Opensc: side-channel leaks while stripping encryption pkcs#1 padding
Published 2024-01-31 · Modified
5.9EPSS 0.012
CVE-2026-0990
Libxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processing
Published 2026-01-15 · Analyzed
5.9EPSS 0.010
CVE-2024-0914
Opencryptoki: timing side-channel in handling of rsa pkcs#1 v1.5 padded ciphertexts (marvin)
Published 2024-01-31 · Modified
5.9EPSS 0.009
CVE-2022-4132
Memory leak on tls connections
Published 2023-10-04 · Modified
5.9EPSS 0.007
CVE-2024-3049
Booth: specially crafted hash can lead to invalid hmac being accepted by booth server
Published 2024-06-06 · Modified
5.9EPSS 0.005
CVE-2026-12725
Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies
Published 2026-06-22 · Analyzed
5.9EPSS 0.005
CVE-2023-3347
Samba: smb2 packet signing is not enforced when "server signing = required" is set
Published 2023-07-20 · Modified
5.9EPSS 0.004
CVE-2026-59845
Libssh: libssh: denial of service via unchecked proxycommand fork() failure
Published 2026-07-21 · Modified
5.9EPSS 0.001
CVE-2026-1467
Libsoup: libsoup: http header injection via specially crafted urls when an http proxy is configured
Published 2026-01-27 · Analyzed
5.8EPSS 0.004
CVE-2026-1536
Libsoup: libsoup: http header injection or response splitting via crlf injection in content-disposition header
Published 2026-01-28 · Analyzed
5.8EPSS 0.003
CVE-2026-1539
Libsoup: libsoup: credential leakage via http redirects
Published 2026-01-28 · Analyzed
5.8EPSS 0.003
CVE-2023-1206
A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of the server that accepts IPV6 connections up to 95%.
Published 2023-06-30 · Modified
5.7EPSS 0.005
CVE-2022-2393
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content.
Published 2022-07-14 · Modified
5.7EPSS 0.003
CVE-2023-3301
Triggerable assertion due to race condition in hot-unplug
Published 2023-09-13 · Modified
5.6EPSS 0.003
CVE-2026-1764
Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow leads to denial of service or information disclosure when parsing mp3 files
Published 2026-06-16 · Analyzed
5.6EPSS 0.002
CVE-2025-5916
Libarchive: integer overflow while reading warc files at archive_read_support_format_warc.c
Published 2025-06-09 · Modified
5.6EPSS 0.002
CVE-2023-4155
Sev-es / sev-snp vmgexit double fetch vulnerability
Published 2023-09-13 · Modified
5.6EPSS 0.002
CVE-2023-1183
Arbitrary file write
Published 2023-07-10 · Modified
5.5EPSS 0.646
CVE-2021-3997
A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time when too many nested directories are created in /tmp.
Published 2022-08-23 · Modified
5.5EPSS 0.017
CVE-2022-2078
A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allows an attacker to trigger a buffer overflow via nft_set_desc_concat_parse() , causing a denial of service and possibly to run code.
Published 2022-06-30 · Modified
5.5EPSS 0.010
CVE-2023-1289
A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When ImageMagick crashes, it generates a lot of trash files. These trash files can be large if the SVG file contains many render actions. In a denial of service attack, if a remote attacker uploads an SVG file of size t, ImageMagick generates files of size 103*t. If an attacker uploads a 100M SVG, the server will generate about 10G.
Published 2023-03-23 · Modified
5.5EPSS 0.009
CVE-2022-1354
A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.
Published 2022-08-31 · Modified
5.5EPSS 0.006
CVE-2022-25309
A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap-rtl.c file. This flaw allows an attacker to pass a specially crafted file to the Fribidi application with the '--caprtl' option, leading to a crash and causing a denial of service.
Published 2022-09-06 · Modified
5.5EPSS 0.005
CVE-2022-25310
A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file. This flaw allows an attacker to pass a specially crafted file to Fribidi, leading to a crash and causing a denial of service.
Published 2022-09-06 · Modified
5.5EPSS 0.005
CVE-2022-2153
A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of service.
Published 2022-08-31 · Modified
5.5EPSS 0.005
CVE-2023-43786
Libx11: stack exhaustion from infinite recursion in putsubimage()
Published 2023-10-10 · Modified
5.5EPSS 0.005
CVE-2023-3772
Kernel: xfrm: null pointer dereference in xfrm_update_ae_params()
Published 2023-07-25 · Modified
5.5EPSS 0.005
CVE-2024-3567
Qemu-kvm: net: assertion failure in update_sctp_checksum()
Published 2024-04-10 · Modified
5.5EPSS 0.004
CVE-2022-4285
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.
Published 2023-01-27 · Modified
5.5EPSS 0.004
CVE-2022-1263
A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of service.
Published 2022-08-31 · Modified
5.5EPSS 0.004
CVE-2023-38559
Ghostscript: out-of-bound read in base/gdevdevn.c:1973 in devn_pcx_write_rle could result in dos
Published 2023-08-01 · Modified
5.5EPSS 0.004
← Prev11 / 16Next →