VendorsRed Hatenterprise_linux9.0
Vulnerabilities

Red Hat Enterprise Linux 9.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

601CVEs
CVE-2023-4459
Kernel: vmxnet3: null pointer dereference in vmxnet3_rq_cleanup()
Published 2023-08-21 · Modified
5.5EPSS 0.002
CVE-2022-3560
A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.
Published 2023-02-02 · Modified
5.5EPSS 0.002
CVE-2025-46399
Xfig: transfig: fig2dev segmentation fault vulnerability
Published 2025-04-23 · Modified
5.5EPSS 0.002
CVE-2025-46400
Xfig: fig2dev segmentation fault in read_arcobject
Published 2025-04-23 · Modified
5.5EPSS 0.002
CVE-2023-39328
Openjpeg: denail of service via crafted image file
Published 2024-07-09 · Modified
5.5EPSS 0.002
CVE-2026-66757
Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi images
Published 2026-07-27 · Analyzed
5.5EPSS 0.002
CVE-2023-4133
Kernel: cxgb4: use-after-free in ch_flower_stats_cb()
Published 2023-08-03 · Modified
5.5EPSS 0.002
CVE-2022-3707
A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resource overload, causing a fail in the intel_gvt_dma_map_guest_page function. This issue could allow a local user to crash the system.
Published 2023-03-06 · Modified
5.5EPSS 0.002
CVE-2026-0967
Libssh: libssh: denial of service via inefficient regular expression processing
Published 2026-03-26 · Modified
5.5EPSS 0.002
CVE-2026-40916
Gimp: gimp: denial of service due to stack buffer overflow in tim image loader
Published 2026-04-15 · Analyzed
5.5EPSS 0.002
CVE-2023-1095
In nf_tables_updtable, if nf_tables_table_enable returns an error, nft_trans_destroy is called to free the transaction object. nft_trans_destroy() calls list_del(), but the transaction was never placed on a list -- the list head is all zeroes, this results in a NULL pointer dereference.
Published 2023-02-28 · Modified
5.5EPSS 0.002
CVE-2026-6694
Gimp: gimp file-png plugin: denial of service via oversized apng trns chunk
Published 2026-08-03 · Analyzed
5.5EPSS 0.002
CVE-2023-3161
A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined behavior and possible denial of service.
Published 2023-06-12 · Modified
5.5EPSS 0.002
CVE-2023-28327
A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Kernel. The newly allocated skb does not have sk, leading to a NULL pointer. This flaw allows a local user to crash or potentially cause a denial of service.
Published 2023-04-19 · Modified
5.5EPSS 0.002
CVE-2026-50263
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow()
Published 2026-06-05 · Modified
5.5EPSS 0.002
CVE-2026-50262
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes
Published 2026-06-05 · Modified
5.5EPSS 0.002
CVE-2024-0639
Kernel: potential deadlock on &net->sctp.addr_wq_lock leading to dos
Published 2024-01-17 · Modified
5.5EPSS 0.002
CVE-2026-5745
Libarchive: a null pointer dereference vulnerability exists in the acl parser of libarchive
Published 2026-04-07 · Modified
5.5EPSS 0.002
CVE-2024-0641
Kernel: deadlock leading to denial of service in tipc_crypto_key_revoke
Published 2024-01-17 · Modified
5.5EPSS 0.002
CVE-2026-19548
Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing
Published 2026-08-12 · Analyzed
5.5EPSS 0.002
CVE-2026-4897
Polkit: polkit: denial of service via unbounded input processing through standard input
Published 2026-03-26 · Modified
5.5EPSS 0.002
CVE-2026-6245
Sssd: out-of-bounds read in the sssd
Published 2026-04-15 · Analyzed
5.5EPSS 0.001
CVE-2026-6843
Nano: nano: format string vulnerability leads to denial of service
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2026-6844
Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2026-19617
Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser
Published 2026-08-14 · Analyzed
5.5EPSS 0.001
CVE-2026-68742
Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr
Published 2026-08-03 · Analyzed
5.5EPSS 0.001
CVE-2026-2625
Rust-rpm-sequoia: rust-rpm-sequoia: denial of service via crafted rpm file during signature verification
Published 2026-04-03 · Analyzed
5.5EPSS 0.001
CVE-2023-6710
Mod_cluster/mod_proxy_cluster: stored cross site scripting
Published 2023-12-12 · Modified
5.41 PoCEPSS 0.022
CVE-2023-6134
Keycloak: reflected xss via wildcard in oidc redirect_uri
Published 2023-12-14 · Modified
5.4EPSS 0.013
CVE-2022-1274
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.
Published 2023-03-29 · Modified
5.4EPSS 0.007
CVE-2023-2455
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy.
Published 2023-06-09 · Modified
5.4EPSS 0.007
CVE-2026-18651
389-ds-base: 389-ds-base: sasl plain bind installs connection credentials before account-lock check, allowing continued access as a locked account
Published 2026-08-03 · Analyzed
5.4EPSS 0.003
CVE-2026-12528
389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()
Published 2026-06-17 · Analyzed
5.4EPSS 0.002
CVE-2026-2376
Mirror-registry: quay: quay: server-side request forgery via open redirect vulnerability in web interface
Published 2026-03-12 · Analyzed
5.4EPSS 0.002
CVE-2023-34967
Samba: type confusion in mdssvc rpc service for spotlight
Published 2023-07-20 · Modified
5.3EPSS 0.612
CVE-2023-51764
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Postfix supports <LF>.<CR><LF> but some other popular e-mail servers do not. To prevent attack variants (by always disallowing <LF> without <CR>), a different solution is required, such as the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23, 3.6.13, 3.7.9, 3.8.4, or 3.9.
Published 2023-12-24 · Modified
5.3EPSS 0.026
CVE-2023-6918
Libssh: missing checks for return values for digests
Published 2023-12-18 · Modified
5.3EPSS 0.014
CVE-2023-34968
Samba: spotlight server-side share path disclosure
Published 2023-07-20 · Modified
5.3EPSS 0.013
CVE-2025-32989
Gnutls: vulnerability in gnutls sct extension parsing
Published 2025-07-10 · Modified
5.3EPSS 0.013
CVE-2023-51765
sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports <LF>.<CR><LF> but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.
Published 2023-12-24 · Modified
5.3EPSS 0.011
← Prev13 / 16Next →