VendorsRed Hatenterprise_linuxall versions
Vulnerabilities

Red Hat Enterprise Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2269CVEs
CVE-2022-30597
A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
Published 2022-05-18 · Modified
5.3EPSS 0.013
CVE-2023-34968
Samba: spotlight server-side share path disclosure
Published 2023-07-20 · Modified
5.3EPSS 0.013
CVE-2025-32989
Gnutls: vulnerability in gnutls sct extension parsing
Published 2025-07-10 · Modified
5.3EPSS 0.013
CVE-2011-2207
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate.
Published 2019-11-27 · Modified
5.3EPSS 0.012
CVE-2023-51765
sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports <LF>.<CR><LF> but some other popular e-mail servers do not. This is resolved in 8.18 and later versions with 'o' in srv_features.
Published 2023-12-24 · Modified
5.3EPSS 0.011
CVE-2017-2623
It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic Host, where certificate pinning is used by default.
Published 2018-07-27 · Modified
5.3EPSS 0.010
CVE-2023-3153
Service monitor mac flow is not rate limited
Published 2023-10-04 · Modified
5.3EPSS 0.010
CVE-2020-4635
IBM Resilient SOAR 40 and earlier could disclose sensitive information by allowing a user to enumerate usernames.
Published 2021-03-19 · Modified
5.3EPSS 0.009
CVE-2023-7250
Iperf3: possible denial of service
Published 2024-03-18 · Modified
5.3EPSS 0.009
CVE-2023-5871
Libnbd: malicious nbd server may crash libnbd
Published 2023-11-27 · Modified
5.3EPSS 0.009
CVE-2019-3897
It has been discovered in redhat-certification that any unauthorized user may download any file under /var/www/rhcert, provided they know its name. Red Hat Certification 6 and 7 is vulnerable to this issue.
Published 2021-03-16 · Modified
5.3EPSS 0.009
CVE-2023-7216
Cpio: extraction allows symlinks which enables remote command execution
Published 2024-02-05 · Modified
5.3EPSS 0.009
CVE-2023-6681
Jwcrypto: denail of service via specifically crafted jwe
Published 2024-02-12 · Modified
5.3EPSS 0.009
CVE-2020-12826
A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can send an arbitrary signal to a parent process in a different security domain. Exploitation limitations include the amount of elapsed time before an integer overflow occurs, and the lack of scenarios where signals to a parent process present a substantial operational threat.
Published 2020-05-12 · Modified
5.3EPSS 0.007
CVE-2026-59848
Libssh: libssh: denial of service via sftp responses with unknown request ids
Published 2026-07-21 · Modified
5.3EPSS 0.006
CVE-2023-1672
Race condition exists in the key generation and rotation functionality
Published 2023-07-11 · Modified
5.3EPSS 0.006
CVE-2023-4693
Grub2: out-of-bounds read at fs/ntfs.c
Published 2023-10-25 · Modified
5.3EPSS 0.005
CVE-2026-59842
Libssh: libssh: information disclosure via short gssapi curve25519 public key
Published 2026-07-21 · Analyzed
5.3EPSS 0.005
CVE-2026-14940
389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued rdn
Published 2026-07-07 · Analyzed
5.3EPSS 0.005
CVE-2026-2443
Libsoup: out-of-bounds read in libsoup handle_partial_get() leading to heap information disclosure
Published 2026-02-13 · Modified
5.3EPSS 0.004
CVE-2026-2708
Libsoup: libsoup: http request smuggling via duplicate content-length headers
Published 2026-04-23 · Analyzed
5.3EPSS 0.004
CVE-2026-12969
Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation
Published 2026-06-23 · Analyzed
5.3EPSS 0.004
CVE-2023-6693
Qemu: virtio-net: stack buffer overflow in virtio_net_flush_tx()
Published 2024-01-02 · Modified
5.3EPSS 0.003
CVE-2024-49394
Mutt: neomutt: in-reply-to email header field it not protected by cryptograpic signing
Published 2024-11-12 · Modified
5.3EPSS 0.003
CVE-2018-1113
setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates security assumptions made by pam_shells and some daemons which allow access based on a user's shell being listed in /etc/shells. Under some circumstances, users which had their shell changed to /sbin/nologin could still access the system.
Published 2018-07-02 · Modified
5.3EPSS 0.003
CVE-2024-49395
Mutt: neomutt: bcc email header field is indirectly leaked by cryptographic info block
Published 2024-11-12 · Modified
5.3EPSS 0.003
CVE-2019-14838
A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server
Published 2019-10-14 · Modified
5.2EPSS 0.011
CVE-2019-3811
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.
Published 2019-01-15 · Modified
5.2EPSS 0.007
CVE-2013-1862
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
Published 2013-06-10 · Modified
5.1EPSS 0.249
CVE-2004-0802
Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.
Published 2004-09-24 · Modified
5.1EPSS 0.034
CVE-2005-0667
Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to the message.
Published 2005-03-07 · Modified
5.1EPSS 0.032
CVE-2016-0641
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect confidentiality and availability via vectors related to MyISAM.
Published 2016-04-21 · Modified
5.1EPSS 0.015
CVE-2019-2634
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 5.1 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published 2019-04-23 · Modified
5.1EPSS 0.004
CVE-2023-40551
Shim: out of bounds read when parsing mz binaries
Published 2024-01-29 · Modified
5.1EPSS 0.004
CVE-2022-3500
A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in an attested state but not verifying that anymore.
Published 2022-11-22 · Modified
5.1EPSS 0.003
CVE-2026-71227
Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return
Published 2026-08-05 · Modified
5.1EPSS 0.002
CVE-2026-57965
Spice-vdagent: integer overflow in udscs_write() leading to heap buffer overflow
Published 2026-06-29 · Analyzed
5.1EPSS 0.002
CVE-2015-2808
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.
Published 2015-04-01 · Modified
5.0EPSS 0.739
CVE-2013-4124
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.
Published 2013-08-05 · Modified
5.01 PoCEPSS 0.690
CVE-2013-5704
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
Published 2014-04-15 · Modified
5.0EPSS 0.526
← Prev44 / 57Next →