VendorsRed Hatenterprise_linux8.0
Vulnerabilities

Red Hat Enterprise Linux 8.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1167CVEs
CVE-2026-19548
Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing
Published 2026-08-12 · Analyzed
5.5EPSS 0.002
CVE-2026-4897
Polkit: polkit: denial of service via unbounded input processing through standard input
Published 2026-03-26 · Modified
5.5EPSS 0.002
CVE-2026-6245
Sssd: out-of-bounds read in the sssd
Published 2026-04-15 · Analyzed
5.5EPSS 0.001
CVE-2021-3446
A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were used. Instead of returning the last IV it returned the initial IV to the caller, thus weakening the subsequent encryption and decryption steps. The highest threat from this vulnerability is to data confidentiality.
Published 2021-03-25 · Modified
5.5EPSS 0.001
CVE-2026-6843
Nano: nano: format string vulnerability leads to denial of service
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2026-6844
Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2026-19617
Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser
Published 2026-08-14 · Analyzed
5.5EPSS 0.001
CVE-2026-68742
Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr
Published 2026-08-03 · Analyzed
5.5EPSS 0.001
CVE-2023-6134
Keycloak: reflected xss via wildcard in oidc redirect_uri
Published 2023-12-14 · Modified
5.4EPSS 0.013
CVE-2020-1722
A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.
Published 2020-04-27 · Modified
5.4EPSS 0.012
CVE-2022-30596
A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.
Published 2022-05-18 · Modified
5.4EPSS 0.009
CVE-2022-1274
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.
Published 2023-03-29 · Modified
5.4EPSS 0.007
CVE-2019-3872
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unauthorized information or conduct further attacks.
Published 2019-06-12 · Modified
5.4EPSS 0.007
CVE-2023-2455
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy.
Published 2023-06-09 · Modified
5.4EPSS 0.007
CVE-2023-0119
Foreman: stored cross-site scripting in host tab
Published 2023-09-12 · Modified
5.4EPSS 0.006
CVE-2026-18651
389-ds-base: 389-ds-base: sasl plain bind installs connection credentials before account-lock check, allowing continued access as a locked account
Published 2026-08-03 · Analyzed
5.4EPSS 0.003
CVE-2026-12528
389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()
Published 2026-06-17 · Analyzed
5.4EPSS 0.002
CVE-2026-2376
Mirror-registry: quay: quay: server-side request forgery via open redirect vulnerability in web interface
Published 2026-03-12 · Analyzed
5.4EPSS 0.002
CVE-2023-34967
Samba: type confusion in mdssvc rpc service for spotlight
Published 2023-07-20 · Modified
5.3EPSS 0.612
CVE-2019-7317
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
Published 2019-02-04 · Modified
5.3EPSS 0.094
CVE-2019-2762
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Published 2019-07-23 · Modified
5.3EPSS 0.044
CVE-2019-2769
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Published 2019-07-23 · Modified
5.3EPSS 0.044
CVE-2019-11038
Uninitialized read in gdImageCreateFromXbm
Published 2019-06-18 · Modified
5.3EPSS 0.043
CVE-2019-6465
Zone transfer controls for writable DLZ zones were not effective
Published 2019-10-09 · Modified
5.3EPSS 0.037
CVE-2018-20685
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
Published 2019-01-10 · Modified
5.3EPSS 0.037
CVE-2021-4189
A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible.
Published 2022-08-24 · Modified
5.3EPSS 0.032
CVE-2020-1730
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.
Published 2020-04-13 · Modified
5.3EPSS 0.031
CVE-2021-20201
A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection.
Published 2021-05-28 · Modified
5.3EPSS 0.027
CVE-2023-51764
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Postfix supports <LF>.<CR><LF> but some other popular e-mail servers do not. To prevent attack variants (by always disallowing <LF> without <CR>), a different solution is required, such as the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23, 3.6.13, 3.7.9, 3.8.4, or 3.9.
Published 2023-12-24 · Modified
5.3EPSS 0.026
CVE-2020-10693
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages.
Published 2020-05-06 · Modified
5.3EPSS 0.024
CVE-2021-42778
A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.
Published 2022-04-18 · Modified
5.3EPSS 0.021
CVE-2021-42779
A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.
Published 2022-04-18 · Modified
5.3EPSS 0.021
CVE-2021-32672
Vulnerability in Lua Debugger in Redis
Published 2021-10-04 · Modified
5.3EPSS 0.019
CVE-2019-2623
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published 2019-04-23 · Modified
5.3EPSS 0.018
CVE-2020-35518
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database.
Published 2021-03-26 · Modified
5.3EPSS 0.015
CVE-2023-6918
Libssh: missing checks for return values for digests
Published 2023-12-18 · Modified
5.3EPSS 0.014
CVE-2020-14370
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.
Published 2020-09-23 · Modified
5.3EPSS 0.014
CVE-2022-30597
A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
Published 2022-05-18 · Modified
5.3EPSS 0.013
CVE-2023-34968
Samba: spotlight server-side share path disclosure
Published 2023-07-20 · Modified
5.3EPSS 0.013
CVE-2025-32989
Gnutls: vulnerability in gnutls sct extension parsing
Published 2025-07-10 · Modified
5.3EPSS 0.013
← Prev24 / 30Next →