VendorsRed Hatenterprise_linux8.0
Vulnerabilities

Red Hat Enterprise Linux 8.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1167CVEs
CVE-2020-36329
A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2021-05-21 · Modified
9.8EPSS 0.023
CVE-2019-9788
Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Published 2019-04-26 · Modified
9.8EPSS 0.022
CVE-2018-25014
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
Published 2021-05-21 · Modified
9.8EPSS 0.022
CVE-2019-10212
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
Published 2019-10-02 · Modified
9.8EPSS 0.019
CVE-2026-5121
Libarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing
Published 2026-03-30 · Modified
9.8EPSS 0.014
CVE-2022-30599
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
Published 2022-05-18 · Modified
9.8EPSS 0.014
CVE-2019-0160
Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access.
Published 2019-03-27 · Modified
9.8EPSS 0.013
CVE-2020-27836
A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability..
Published 2022-08-22 · Modified
9.8EPSS 0.012
CVE-2026-42010
Gnutls: gnutls: authentication bypass via nul character in username
Published 2026-05-07 · Modified
9.8EPSS 0.009
CVE-2023-0923
Odh-notebook-controller-container: missing authorization allows for file contents disclosure
Published 2023-09-15 · Modified
9.8EPSS 0.009
CVE-2025-14087
Glib: glib: buffer underflow in gvariant parser leads to heap corruption
Published 2025-12-10 · Modified
9.8EPSS 0.008
CVE-2022-4039
Rhsso-container-image: unsecured management interface exposed to adjecent network
Published 2023-09-22 · Modified
9.8EPSS 0.008
CVE-2024-44070
An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
Published 2024-08-19 · Modified
9.8EPSS 0.006
CVE-2026-53006
ipv6: fix possible UAF in icmpv6_rcv()
Published 2026-06-24 · Modified
9.8EPSS 0.005
CVE-2026-53002
netfilter: conntrack: remove sprintf usage
Published 2026-06-24 · Modified
9.8EPSS 0.005
CVE-2026-11861
Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships
Published 2026-08-20 · Modified
9.6EPSS 0.002
CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
Published 2019-02-11 · Modified
9.32 PoCEPSS 0.985
CVE-2020-0603
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.
Published 2020-01-14 · Modified
9.3EPSS 0.210
CVE-2019-3855
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
Published 2019-03-21 · Modified
9.3EPSS 0.093
CVE-2023-46846
Squid: request/response smuggling in http/1.1 and icap
Published 2023-11-03 · Modified
9.3EPSS 0.062
CVE-2020-10696
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
Published 2020-03-31 · Modified
9.3EPSS 0.027
CVE-2021-3621
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2021-12-23 · Modified
9.3EPSS 0.025
CVE-2026-9256
NGINX ngx_http_rewrite_module vulnerability
Published 2026-05-22 · Modified
9.2EPSS 0.027
CVE-2026-42055
NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
Published 2026-06-17 · Modified
9.2EPSS 0.024
CVE-2019-20445
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
Published 2020-01-29 · Modified
9.1EPSS 0.135
CVE-2019-20444
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."
Published 2020-01-29 · Modified
9.1EPSS 0.089
CVE-2022-1586
An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.
Published 2022-05-16 · Analyzed
9.1EPSS 0.034
CVE-2021-4048
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory.
Published 2021-12-08 · Modified
9.1EPSS 0.026
CVE-2020-36331
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.
Published 2021-05-21 · Modified
9.1EPSS 0.023
CVE-2018-25010
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().
Published 2021-05-21 · Modified
9.1EPSS 0.022
CVE-2020-36330
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.
Published 2021-05-21 · Modified
9.1EPSS 0.022
CVE-2018-25009
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().
Published 2021-05-21 · Modified
9.1EPSS 0.021
CVE-2019-17631
From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks.
Published 2019-10-17 · Modified
9.1EPSS 0.021
CVE-2018-25012
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
Published 2021-05-21 · Modified
9.1EPSS 0.021
CVE-2018-25013
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().
Published 2021-05-21 · Modified
9.1EPSS 0.021
CVE-2023-0118
Foreman: arbitrary code execution through templates
Published 2023-09-20 · Modified
9.1EPSS 0.014
CVE-2026-58016
Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
Published 2026-06-30 · Modified
9.1EPSS 0.010
CVE-2026-33845
Gnutls: gnutls: denial of service via dtls zero-length fragment
Published 2026-04-30 · Modified
9.1EPSS 0.009
CVE-2026-34002
Xorg: xwayland: x.org x server: information disclosure or denial of service via out-of-bounds read in xkb modifier map handling
Published 2026-05-05 · Modified
9.1EPSS 0.005
CVE-2026-34000
Xwayland: xorg: x.org x server: information disclosure and denial of service via out-of-bounds read in xkb geometry processing.
Published 2026-05-05 · Modified
9.1EPSS 0.005
← Prev2 / 30Next →