VendorsRed Hatenterprise_linux9.0
Vulnerabilities

Red Hat Enterprise Linux 9.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

601CVEs
CVE-2023-3171
Eap-7: heap exhaustion via deserialization
Published 2023-12-27 · Modified
7.5EPSS 0.009
CVE-2026-15722
389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsing
Published 2026-07-31 · Modified
7.5EPSS 0.008
CVE-2026-58011
Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime
Published 2026-06-30 · Modified
7.5EPSS 0.008
CVE-2023-5625
Python-eventlet: patch regression for cve-2021-21419 in some red hat builds
Published 2023-11-01 · Modified
7.5EPSS 0.008
CVE-2024-6239
Poppler: pdfinfo: crash in broken documents when using -dests parameter
Published 2024-06-21 · Modified
7.5EPSS 0.008
CVE-2023-4503
Eap-galleon: custom provisioning creates unsecured http-invoker
Published 2024-02-06 · Modified
7.5EPSS 0.007
CVE-2026-59850
Libssh: libssh: use-after-free via data callbacks on closed channels
Published 2026-07-21 · Modified
7.5EPSS 0.006
CVE-2026-59847
Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification
Published 2026-07-21 · Analyzed
7.5EPSS 0.006
CVE-2026-11788
389-ds-base: 389-ds-base: null pointer dereference in deref control plugin ber parser
Published 2026-06-09 · Modified
7.5EPSS 0.006
CVE-2026-11770
389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
Published 2026-07-31 · Modified
7.5EPSS 0.005
CVE-2023-3089
Ocp & fips mode
Published 2023-07-05 · Modified
7.5EPSS 0.005
CVE-2026-19654
Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd
Published 2026-08-12 · Modified
7.5EPSS 0.005
CVE-2023-39198
Kernel: qxl: race condition leading to use-after-free in qxl_mode_dumb_create()
Published 2023-11-09 · Modified
7.5EPSS 0.004
CVE-2026-73198
Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read
Published 2026-08-20 · Modified
7.5EPSS 0.004
CVE-2026-73197
Ipa: freeipa: unauthenticated dos in `/ipa/migration/migration.py` via unbounded request body read
Published 2026-08-20 · Modified
7.5EPSS 0.004
CVE-2026-1940
Gstreamer: incomplete fix of cve-2026-1940
Published 2026-03-23 · Analyzed
7.5EPSS 0.002
CVE-2025-3155
Yelp: arbitrary file read
Published 2025-04-03 · Modified
7.4EPSS 0.142
CVE-2023-0361
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.
Published 2023-02-15 · Modified
7.4EPSS 0.014
CVE-2026-3833
Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison
Published 2026-04-30 · Modified
7.4EPSS 0.009
CVE-2023-3971
Controller: html injection in custom login info
Published 2023-10-04 · Modified
7.3EPSS 0.008
CVE-2026-3099
Libsoup: libsoup: authentication bypass via digest authentication replay attack
Published 2026-03-12 · Analyzed
7.3EPSS 0.005
CVE-2026-58381
Gimp: gimp: double-free in read_layer_block()
Published 2026-07-02 · Analyzed
7.3EPSS 0.003
CVE-2025-62231
Xorg: xmayland: value overflow in xkbsetcompatmap()
Published 2025-10-30 · Analyzed
7.3EPSS 0.003
CVE-2025-62230
Xorg: xwayland: use-after-free in xkb client resource removal
Published 2025-10-30 · Analyzed
7.3EPSS 0.003
CVE-2026-71226
Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path
Published 2026-08-05 · Modified
7.3EPSS 0.002
CVE-2023-2454
schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.
Published 2023-06-09 · Modified
7.2EPSS 0.012
CVE-2026-66338
Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked()
Published 2026-07-24 · Analyzed
7.2EPSS 0.003
CVE-2023-1380
A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service.
Published 2023-03-27 · Modified
7.1EPSS 0.165
CVE-2021-4204
An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or leak internal information.
Published 2022-08-24 · Modified
7.1EPSS 0.012
CVE-2023-6291
Keycloak: redirect_uri validation bypass
Published 2024-01-26 · Modified
7.1EPSS 0.010
CVE-2026-1933
Samba: missing access check on reparse point operations
Published 2026-05-27 · Modified
7.1EPSS 0.009
CVE-2024-7341
Wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters
Published 2024-09-09 · Modified
7.1EPSS 0.008
CVE-2026-4887
Gimp: gimp:memory disclosure and denial of service via specially crafted pcx image
Published 2026-03-26 · Modified
7.1EPSS 0.005
CVE-2023-6606
Kernel: out-of-bounds read vulnerability in smbcalcsize
Published 2023-12-08 · Modified
7.1EPSS 0.005
CVE-2023-2422
Keycloak: oauth client impersonation
Published 2023-10-04 · Modified
7.1EPSS 0.005
CVE-2023-6610
Kernel: oob access in smb2_dump_detail
Published 2023-12-08 · Modified
7.1EPSS 0.004
CVE-2023-3567
Kernel: use after free in vcs_read in drivers/tty/vt/vc_screen.c due to race
Published 2023-07-24 · Modified
7.1EPSS 0.004
CVE-2023-5366
Openvswitch don't match packets on nd_target field
Published 2023-10-06 · Modified
7.1EPSS 0.004
CVE-2022-2990
An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
Published 2022-09-13 · Modified
7.1EPSS 0.003
CVE-2022-2989
An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
Published 2022-09-13 · Modified
7.1EPSS 0.003
← Prev6 / 16Next →