VendorsRed Hatenterprise_linux9.0
Vulnerabilities

Red Hat Enterprise Linux 9.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

601CVEs
CVE-2025-46397
Xfig: xfig: stack-overflow allows possible code execution via local input manipulation
Published 2025-04-23 · Modified
7.8EPSS 0.003
CVE-2026-6384
Gimp: gimp: arbitrary code execution or denial of service via buffer overflow in gif image processing
Published 2026-04-15 · Modified
7.8EPSS 0.003
CVE-2024-0841
Kernel: hugetlbfs: null pointer dereference in hugetlbfs_fill_super function
Published 2024-01-28 · Modified
7.8EPSS 0.003
CVE-2022-4318
Cri-o: /etc/passwd tampering privesc
Published 2023-09-25 · Modified
7.8EPSS 0.003
CVE-2025-0678
Grub2: squash4: integer overflow may lead to heap based out-of-bounds write when reading data
Published 2025-03-03 · Modified
7.8EPSS 0.003
CVE-2023-5633
Kernel: vmwgfx: reference count issue leads to use-after-free in surface handling
Published 2023-10-23 · Modified
7.8EPSS 0.003
CVE-2023-3972
Insights-client: unsafe handling of temporary files and directories
Published 2023-11-01 · Modified
7.8EPSS 0.003
CVE-2026-48864
Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
Published 2026-05-26 · Modified
7.8EPSS 0.003
CVE-2024-0562
Kernel: use-after-free after removing device in wb_inode_writeback_end in mm/page-writeback.c
Published 2024-01-15 · Modified
7.8EPSS 0.003
CVE-2023-3899
Subscription-manager: inadequate authorization of com.redhat.rhsm1 d-bus interface allows local users to modify configuration
Published 2023-08-23 · Modified
7.8EPSS 0.002
CVE-2022-3424
A use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl function is called by the user, where a fail pass occurs in the gru_check_chiplet_assignment function. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Published 2023-03-06 · Modified
7.8EPSS 0.002
CVE-2024-50074
parport: Proper fix for array out-of-bounds access
Published 2024-10-29 · Modified
7.8EPSS 0.002
CVE-2024-45782
Grub2: fs/hfs: strcpy() using the volume name (fs/hfs.c:382)
Published 2025-03-03 · Modified
7.8EPSS 0.002
CVE-2026-50258
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levels
Published 2026-06-05 · Modified
7.8EPSS 0.002
CVE-2026-50259
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing
Published 2026-06-05 · Modified
7.8EPSS 0.002
CVE-2026-50256
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch
Published 2026-06-05 · Modified
7.8EPSS 0.002
CVE-2026-50264
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds heap write in dri2 drigetbuffers/drigetbufferswithformat
Published 2026-06-05 · Modified
7.8EPSS 0.002
CVE-2026-50257
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence()
Published 2026-06-05 · Modified
7.8EPSS 0.002
CVE-2026-50261
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter()
Published 2026-06-05 · Modified
7.8EPSS 0.002
CVE-2026-50260
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter()
Published 2026-06-05 · Modified
7.8EPSS 0.002
CVE-2026-6846
Binutils: binutils: arbitrary code execution via malformed xcoff object file processing
Published 2026-04-22 · Modified
7.8EPSS 0.002
CVE-2026-42170
Gimp: gimp dds plug-in heap-based buffer overflow via bpp mismatch in load_layer() (ddsread.c)
Published 2026-08-08 · Analyzed
7.8EPSS 0.002
CVE-2026-53009
ice: fix double-free of tx_buf skb
Published 2026-06-24 · Modified
7.8EPSS 0.002
CVE-2026-53000
netfilter: nat: use kfree_rcu to release ops
Published 2026-06-24 · Modified
7.8EPSS 0.002
CVE-2026-5165
Virtio-win: virtio-win: memory corruption via use-after-free in virtio blk device reset
Published 2026-03-30 · Analyzed
7.8EPSS 0.002
CVE-2026-53145
drm/gem: Try to fix change_handle ioctl, attempt 4
Published 2026-06-25 · Analyzed
7.8EPSS 0.001
CVE-2023-6563
Keycloak: offline session token dos
Published 2023-12-14 · Modified
7.7EPSS 0.012
CVE-2023-5557
Tracker-miners: sandbox escape
Published 2023-10-13 · Modified
7.7EPSS 0.009
CVE-2024-3056
Podman: kernel: containers in shared ipc namespace are vulnerable to denial of service attack
Published 2024-08-02 · Modified
7.7EPSS 0.005
CVE-2023-6478
Xorg-x11-server: out-of-bounds memory read in rrchangeoutputproperty and rrchangeproviderproperty
Published 2023-12-13 · Modified
7.6EPSS 0.016
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2023-50387
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
Published 2024-02-14 · Modified
7.5EPSS 1.000
CVE-2023-34966
Samba: infinite loop in mdssvc rpc service for spotlight
Published 2023-07-20 · Modified
7.5EPSS 0.624
CVE-2026-21710
A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`. * This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x**
Published 2026-03-30 · Analyzed
7.5EPSS 0.250
CVE-2024-12085
Rsync: info leak via uninitialized stack contents
Published 2025-01-14 · Modified
7.5EPSS 0.088
CVE-2026-34486
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
Published 2026-04-09 · Analyzed
7.5KEVEPSS 0.066
CVE-2023-2156
A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.
Published 2023-05-09 · Modified
7.5EPSS 0.061
CVE-2023-5824
Squid: dos against http and https
Published 2023-11-03 · Modified
7.5EPSS 0.052
CVE-2024-12088
Rsync: --safe-links option bypass leads to path traversal
Published 2025-01-14 · Modified
7.5EPSS 0.047
CVE-2023-3223
Undertow: outofmemoryerror due to @multipartconfig handling
Published 2023-09-27 · Modified
7.5EPSS 0.027
← Prev4 / 16Next →