VendorsRed Hatenterprise_linuxall versions
Vulnerabilities

Red Hat Enterprise Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2269CVEs
CVE-2023-4065
Operator: plaintext password in operator log
Published 2023-09-26 · Modified
5.5EPSS 0.002
CVE-2023-39328
Openjpeg: denail of service via crafted image file
Published 2024-07-09 · Modified
5.5EPSS 0.002
CVE-2025-6196
Libgepub: integer overflow in libgepub's epub archive handling
Published 2025-06-17 · Analyzed
5.5EPSS 0.002
CVE-2026-66757
Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi images
Published 2026-07-27 · Analyzed
5.5EPSS 0.002
CVE-2023-4133
Kernel: cxgb4: use-after-free in ch_flower_stats_cb()
Published 2023-08-03 · Modified
5.5EPSS 0.002
CVE-2022-3707
A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resource overload, causing a fail in the intel_gvt_dma_map_guest_page function. This issue could allow a local user to crash the system.
Published 2023-03-06 · Modified
5.5EPSS 0.002
CVE-2026-40916
Gimp: gimp: denial of service due to stack buffer overflow in tim image loader
Published 2026-04-15 · Analyzed
5.5EPSS 0.002
CVE-2026-0967
Libssh: libssh: denial of service via inefficient regular expression processing
Published 2026-03-26 · Modified
5.5EPSS 0.002
CVE-2023-28328
A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel. The message from user space is not checked properly before transferring into the device. This flaw allows a local user to crash the system or potentially cause a denial of service.
Published 2023-04-19 · Modified
5.5EPSS 0.002
CVE-2023-1095
In nf_tables_updtable, if nf_tables_table_enable returns an error, nft_trans_destroy is called to free the transaction object. nft_trans_destroy() calls list_del(), but the transaction was never placed on a list -- the list head is all zeroes, this results in a NULL pointer dereference.
Published 2023-02-28 · Modified
5.5EPSS 0.002
CVE-2023-31022
CVE
Published 2023-11-02 · Modified
5.5EPSS 0.002
CVE-2026-6694
Gimp: gimp file-png plugin: denial of service via oversized apng trns chunk
Published 2026-08-03 · Analyzed
5.5EPSS 0.002
CVE-2023-3161
A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font, since there are no checks in place, a shift-out-of-bounds occurs leading to undefined behavior and possible denial of service.
Published 2023-06-12 · Modified
5.5EPSS 0.002
CVE-2026-54231
Abrt: unsanitized systemd journal content written to dump directory files enables content injection
Published 2026-06-13 · Modified
5.5EPSS 0.002
CVE-2023-28327
A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Kernel. The newly allocated skb does not have sk, leading to a NULL pointer. This flaw allows a local user to crash or potentially cause a denial of service.
Published 2023-04-19 · Modified
5.5EPSS 0.002
CVE-2026-50263
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow()
Published 2026-06-05 · Modified
5.5EPSS 0.002
CVE-2026-4948
Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
Published 2026-03-27 · Modified
5.5EPSS 0.002
CVE-2026-50262
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes
Published 2026-06-05 · Modified
5.5EPSS 0.002
CVE-2024-0639
Kernel: potential deadlock on &net->sctp.addr_wq_lock leading to dos
Published 2024-01-17 · Modified
5.5EPSS 0.002
CVE-2023-31021
CVE
Published 2023-11-02 · Modified
5.5EPSS 0.002
CVE-2026-5745
Libarchive: a null pointer dereference vulnerability exists in the acl parser of libarchive
Published 2026-04-07 · Modified
5.5EPSS 0.002
CVE-2023-4066
Operator: passwords defined in secrets shown in statefulset yaml
Published 2023-09-27 · Modified
5.5EPSS 0.002
CVE-2026-11819
Community.general: community.general keyring_info — os keyring passphrase returned in plaintext
Published 2026-06-23 · Analyzed
5.5EPSS 0.002
CVE-2024-0641
Kernel: deadlock leading to denial of service in tipc_crypto_key_revoke
Published 2024-01-17 · Modified
5.5EPSS 0.002
CVE-2026-19548
Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing
Published 2026-08-12 · Analyzed
5.5EPSS 0.002
CVE-2026-4897
Polkit: polkit: denial of service via unbounded input processing through standard input
Published 2026-03-26 · Modified
5.5EPSS 0.002
CVE-2021-3446
A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were used. Instead of returning the last IV it returned the initial IV to the caller, thus weakening the subsequent encryption and decryption steps. The highest threat from this vulnerability is to data confidentiality.
Published 2021-03-25 · Modified
5.5EPSS 0.001
CVE-2026-6245
Sssd: out-of-bounds read in the sssd
Published 2026-04-15 · Analyzed
5.5EPSS 0.001
CVE-2026-6843
Nano: nano: format string vulnerability leads to denial of service
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2026-6844
Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2026-19617
Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser
Published 2026-08-14 · Analyzed
5.5EPSS 0.001
CVE-2026-68742
Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr
Published 2026-08-03 · Analyzed
5.5EPSS 0.001
CVE-2026-2625
Rust-rpm-sequoia: rust-rpm-sequoia: denial of service via crafted rpm file during signature verification
Published 2026-04-03 · Analyzed
5.5EPSS 0.001
CVE-2026-26104
Udisks: missing authorization check allows unprivileged users to back up luks headers via udisks d-bus api
Published 2026-02-25 · Modified
5.5EPSS 0.001
CVE-2023-6710
Mod_cluster/mod_proxy_cluster: stored cross site scripting
Published 2023-12-12 · Modified
5.41 PoCEPSS 0.022
CVE-2016-4428
Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form.
Published 2016-07-12 · Modified
5.4EPSS 0.021
CVE-2023-6134
Keycloak: reflected xss via wildcard in oidc redirect_uri
Published 2023-12-14 · Modified
5.4EPSS 0.013
CVE-2020-1722
A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of service and the website becoming unresponsive. The highest threat from this vulnerability is to system availability.
Published 2020-04-27 · Modified
5.4EPSS 0.012
CVE-2023-5546
Moodle: stored xss in quiz grading report via user id number
Published 2023-11-09 · Modified
5.4EPSS 0.012
CVE-2022-30596
A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.
Published 2022-05-18 · Modified
5.4EPSS 0.009
← Prev42 / 57Next →