VendorsRed Hatenterprise_linux7.0
Vulnerabilities

Red Hat Enterprise Linux 7.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1016CVEs
CVE-2017-12167
It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.
Published 2018-07-26 · Modified
5.5EPSS 0.004
CVE-2022-0852
There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the password via the process command line via e.g. htop or ps. The specific impact varies upon the privileges of the Red Hat account in question, but it could affect the integrity, availability, and/or data confidentiality of other systems that are administered by that account. This occurs regardless of how the password is supplied to convert2rhel.
Published 2022-08-29 · Modified
5.5EPSS 0.004
CVE-2014-8181
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.
Published 2019-11-06 · Modified
5.5EPSS 0.004
CVE-2018-10894
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.
Published 2018-08-01 · Modified
5.5EPSS 0.004
CVE-2026-3632
Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
Published 2026-03-17 · Analyzed
5.5EPSS 0.003
CVE-2026-6695
Gimp: gimp: remote code execution via crafted paa file
Published 2026-08-03 · Analyzed
5.5EPSS 0.003
CVE-2024-0408
Xorg-x11-server: selinux unlabeled glx pbuffer
Published 2024-01-18 · Modified
5.5EPSS 0.003
CVE-2019-10140
A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in ovl_posix_acl_create function in fs/overlayfs/dir.c. This can allow attackers with ability to create directories on overlayfs to crash the kernel creating a denial of service (DOS).
Published 2019-08-15 · Modified
5.5EPSS 0.003
CVE-2023-3164
Heap-buffer-overflow in extractimagesection()
Published 2023-11-02 · Modified
5.5EPSS 0.003
CVE-2022-0851
There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the activation key via the process command line via e.g. htop or ps. The specific impact varies upon the subscription, but generally this would allow an attacker to register systems purchased by the victim until discovered; a form of fraud. This could occur regardless of how the activation key is supplied to convert2rhel because it involves how convert2rhel provides it to subscription-manager.
Published 2022-08-29 · Modified
5.5EPSS 0.003
CVE-2022-2873
An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data. This flaw allows a local user to crash the system.
Published 2022-08-22 · Modified
5.5EPSS 0.003
CVE-2024-45778
Grub2: fs/bfs: integer overflow in the bfs parser.
Published 2025-03-03 · Modified
5.5EPSS 0.003
CVE-2021-3669
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
Published 2022-08-26 · Modified
5.5EPSS 0.003
CVE-2024-8354
Qemu-kvm: usb: assertion failure in usb_ep_get()
Published 2024-09-19 · Modified
5.5EPSS 0.003
CVE-2025-46398
Xfig: fig2dev stack-overflow via read_objects
Published 2025-04-23 · Modified
5.5EPSS 0.003
CVE-2021-3659
A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from this vulnerability is to system availability.
Published 2022-08-22 · Modified
5.5EPSS 0.003
CVE-2021-20320
A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem.
Published 2022-02-18 · Modified
5.5EPSS 0.003
CVE-2026-40918
Gimp: gimp: denial of service via crafted pvr image file
Published 2026-04-15 · Analyzed
5.5EPSS 0.003
CVE-2024-2496
Libvirt: null pointer dereference in udevconnectlistallinterfaces()
Published 2024-03-18 · Analyzed
5.5EPSS 0.003
CVE-2022-3560
A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.
Published 2023-02-02 · Modified
5.5EPSS 0.002
CVE-2025-46400
Xfig: fig2dev segmentation fault in read_arcobject
Published 2025-04-23 · Modified
5.5EPSS 0.002
CVE-2025-46399
Xfig: transfig: fig2dev segmentation fault vulnerability
Published 2025-04-23 · Modified
5.5EPSS 0.002
CVE-2023-39328
Openjpeg: denail of service via crafted image file
Published 2024-07-09 · Modified
5.5EPSS 0.002
CVE-2025-6196
Libgepub: integer overflow in libgepub's epub archive handling
Published 2025-06-17 · Analyzed
5.5EPSS 0.002
CVE-2026-66757
Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi images
Published 2026-07-27 · Analyzed
5.5EPSS 0.002
CVE-2026-40916
Gimp: gimp: denial of service due to stack buffer overflow in tim image loader
Published 2026-04-15 · Analyzed
5.5EPSS 0.002
CVE-2026-6694
Gimp: gimp file-png plugin: denial of service via oversized apng trns chunk
Published 2026-08-03 · Analyzed
5.5EPSS 0.002
CVE-2026-54231
Abrt: unsanitized systemd journal content written to dump directory files enables content injection
Published 2026-06-13 · Modified
5.5EPSS 0.002
CVE-2026-50263
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow()
Published 2026-06-05 · Modified
5.5EPSS 0.002
CVE-2026-4948
Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
Published 2026-03-27 · Modified
5.5EPSS 0.002
CVE-2026-50262
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes
Published 2026-06-05 · Modified
5.5EPSS 0.002
CVE-2026-5745
Libarchive: a null pointer dereference vulnerability exists in the acl parser of libarchive
Published 2026-04-07 · Modified
5.5EPSS 0.002
CVE-2026-19548
Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing
Published 2026-08-12 · Analyzed
5.5EPSS 0.002
CVE-2026-4897
Polkit: polkit: denial of service via unbounded input processing through standard input
Published 2026-03-26 · Modified
5.5EPSS 0.002
CVE-2026-6245
Sssd: out-of-bounds read in the sssd
Published 2026-04-15 · Analyzed
5.5EPSS 0.001
CVE-2026-6844
Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2026-6843
Nano: nano: format string vulnerability leads to denial of service
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2026-19617
Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser
Published 2026-08-14 · Analyzed
5.5EPSS 0.001
CVE-2026-68742
Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr
Published 2026-08-03 · Analyzed
5.5EPSS 0.001
CVE-2016-4428
Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form.
Published 2016-07-12 · Modified
5.4EPSS 0.021
← Prev21 / 26Next →