VendorsRed Hatenterprise_linuxall versions
Vulnerabilities

Red Hat Enterprise Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2269CVEs
CVE-2003-0699
The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0700.
Published 2003-08-22 · Modified
7.5EPSS 0.020
CVE-2023-44488
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
Published 2023-09-30 · Modified
7.5EPSS 0.019
CVE-2023-2953
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
Published 2023-05-30 · Modified
7.5EPSS 0.019
CVE-2023-52355
Libtiff: tiffrasterscanlinesize64 produce too-big size and could cause oom
Published 2024-01-25 · Modified
7.5EPSS 0.018
CVE-2004-1005
Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
Published 2005-01-22 · Modified
7.5EPSS 0.018
CVE-2018-5184
Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.
Published 2018-06-11 · Modified
7.5EPSS 0.018
CVE-2023-1108
Undertow: infinite loop in sslconduit during close
Published 2023-09-14 · Modified
7.5EPSS 0.018
CVE-2020-14372
A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System Description Table (SSDT) containing code to overwrite the Linux kernel lockdown variable content directly into memory. The table is further loaded and executed by the kernel, defeating its Secure Boot lockdown and allowing the attacker to load unsigned code. The highest threat from this vulnerability is to data confidentiality and integrity, as well as system availability.
Published 2021-03-03 · Modified
7.5EPSS 0.017
CVE-2021-3690
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
Published 2022-08-23 · Modified
7.5EPSS 0.017
CVE-2023-3138
A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request, Event, or Error IDs are within the bounds of the arrays that those functions write to, using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol, as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values, an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself, possibly causing the client to crash with this memory corruption.
Published 2023-06-28 · Modified
7.5EPSS 0.017
CVE-2020-25708
A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a floating point exception, resulting in a denial of service.
Published 2020-11-27 · Modified
7.5EPSS 0.016
CVE-2021-4213
A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.
Published 2022-08-24 · Modified
7.5EPSS 0.016
CVE-2004-1004
Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
Published 2005-01-22 · Modified
7.5EPSS 0.016
CVE-2004-1175
fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.
Published 2005-01-22 · Modified
7.5EPSS 0.016
CVE-2004-0494
Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI.
Published 2004-08-05 · Modified
7.5EPSS 0.016
CVE-2024-0553
Gnutls: incomplete fix for cve-2023-5981
Published 2024-01-16 · Modified
7.5EPSS 0.016
CVE-2023-3354
Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of service
Published 2023-07-11 · Modified
7.5EPSS 0.016
CVE-2011-2726
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.
Published 2019-11-15 · Modified
7.5EPSS 0.016
CVE-2021-3839
A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.
Published 2022-08-23 · Modified
7.5EPSS 0.016
CVE-2015-0294
GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.
Published 2020-01-27 · Modified
7.5EPSS 0.016
CVE-2023-5156
Glibc: dos due to memory leak in getaddrinfo.c
Published 2023-09-25 · Modified
7.5EPSS 0.016
CVE-2023-2295
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Published 2023-05-17 · Modified
7.5EPSS 0.016
CVE-2025-3891
Mod_auth_openidc: dos via empty post in mod_auth_openidc with oidcpreservepost enabled
Published 2025-04-29 · Modified
7.5EPSS 0.016
CVE-2018-5742
An oversight while backporting a feature leads to an assertion failure in buffer.c:420
Published 2019-10-30 · Modified
7.5EPSS 0.016
CVE-2023-6535
Kernel: null pointer dereference in nvmet_tcp_execute_request
Published 2024-02-07 · Modified
7.5EPSS 0.015
CVE-2023-6536
Kernel: null pointer dereference in __nvmet_req_complete
Published 2024-02-07 · Modified
7.5EPSS 0.015
CVE-2010-4657
PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.
Published 2019-11-13 · Modified
7.5EPSS 0.015
CVE-2024-7006
Libtiff: null pointer dereference in tif_dirinfo.c
Published 2024-08-08 · Modified
7.5EPSS 0.015
CVE-2022-1949
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database items they do not have access to, including but not limited to potentially userPassword hashes and other sensitive data.
Published 2022-06-01 · Modified
7.5EPSS 0.015
CVE-2023-6356
Kernel: null pointer dereference in nvmet_tcp_build_iovec
Published 2024-02-07 · Modified
7.5EPSS 0.015
CVE-2023-38200
Keylime: registrar is subject to a dos against ssl connections
Published 2023-07-24 · Modified
7.5EPSS 0.014
CVE-2022-27649
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Published 2022-04-04 · Modified
7.5EPSS 0.014
CVE-2022-2963
A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.
Published 2022-10-14 · Modified
7.5EPSS 0.014
CVE-2018-1128
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
Published 2018-07-10 · Modified
7.5EPSS 0.014
CVE-2025-6021
Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2
Published 2025-06-12 · Modified
7.5EPSS 0.014
CVE-2004-0750
Unknown vulnerability in redhat-config-nfs before 1.0.13, when shares are exported to multiple hosts, can produce incorrect permissions and prevent the all_squash option from being applied.
Published 2004-09-24 · Modified
7.5EPSS 0.014
CVE-2020-10772
An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower amplification ratio compared to versions of Unbound that shipped before the mentioned erratum. This issue is about the incomplete fix for CVE-2020-12662, and it does not affect upstream versions of Unbound.
Published 2020-11-27 · Modified
7.5EPSS 0.013
CVE-2026-4271
Libsoup: libsoup: denial of service via use-after-free in http/2 server
Published 2026-03-17 · Modified
7.5EPSS 0.013
CVE-2026-35092
Corosync: corosync: denial of service via integer overflow in join message validation
Published 2026-04-01 · Modified
7.5EPSS 0.013
CVE-2022-4743
A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to cause a denial of service attack. The vulnerability affects SDL2 v2.0.4 and above. SDL-1.x are not affected.
Published 2023-01-12 · Modified
7.5EPSS 0.013
← Prev21 / 57Next →