VendorsRed Hatenterprise_linuxall versions
Vulnerabilities

Red Hat Enterprise Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2269CVEs
CVE-2023-46847
Squid: denial of service in http digest authentication
Published 2023-11-03 · Modified
8.6EPSS 0.884
CVE-2021-3517
There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read. The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application.
Published 2021-05-19 · Modified
8.6EPSS 0.170
CVE-2023-46848
Squid: denial of service in ftp
Published 2023-11-03 · Modified
8.6EPSS 0.102
CVE-2015-1779
The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.
Published 2016-01-12 · Modified
8.6EPSS 0.074
CVE-2022-2132
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
Published 2022-08-31 · Modified
8.6EPSS 0.022
CVE-2017-5448
An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Published 2018-06-11 · Modified
8.6EPSS 0.021
CVE-2021-43860
Permissions granted to applications can be hidden from the user at install time
Published 2022-01-12 · Modified
8.6EPSS 0.013
CVE-2022-4904
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.
Published 2023-03-06 · Modified
8.6EPSS 0.012
CVE-2026-58014
Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"
Published 2026-06-30 · Modified
8.6EPSS 0.007
CVE-2022-1055
Use after Free in tc_new_tfilter allowing for privilege escalation in Linux Kernel
Published 2022-03-29 · Analyzed
8.6EPSS 0.005
CVE-2007-1351
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.
Published 2007-04-06 · Modified
8.5EPSS 0.056
CVE-2021-3682
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping packets during a bulk transfer from a SPICE client due to the packet queue being full. A malicious SPICE client could use this flaw to make QEMU call free() with faked heap chunk metadata, resulting in a crash of QEMU or potential code execution with the privileges of the QEMU process on the host.
Published 2021-08-05 · Modified
8.5EPSS 0.029
CVE-2008-2112
Unspecified vulnerability in Sun Ray Kiosk Mode 4.0 allows local and remote authenticated Sun Ray administrators to gain root privileges via unknown vectors related to utconfig.
Published 2008-05-08 · Modified
8.5EPSS 0.025
CVE-2020-25717
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
Published 2022-02-18 · Modified
8.5EPSS 0.016
CVE-2016-2857
The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.
Published 2016-04-08 · Modified
8.4EPSS 0.006
CVE-2016-6322
Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password for the deployed system by reading the file.
Published 2016-09-22 · Modified
8.4EPSS 0.004
CVE-2016-6340
The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force attack.
Published 2016-09-22 · Modified
8.4EPSS 0.004
CVE-2023-40547
Shim: rce in http boot support may lead to secure boot bypass
Published 2024-01-25 · Modified
8.3EPSS 0.054
CVE-2019-9503
Broadcom brcmfmac driver is vulnerable to a frame validation bypass
Published 2020-01-16 · Modified
8.3EPSS 0.033
CVE-2012-1168
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
Published 2019-11-14 · Modified
8.2EPSS 0.023
CVE-2019-19340
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active, an attacker could guess the password and gain access to the system.
Published 2019-12-19 · Modified
8.2EPSS 0.015
CVE-2025-32988
Gnutls: vulnerability in gnutls othername san export
Published 2025-07-10 · Modified
8.2EPSS 0.013
CVE-2026-3497
Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH upstream project itself. The usage of sshpkt_disconnect() on an error, which does not terminate the process, allows an attacker to send an unexpected GSSAPI message type during the GSSAPI key exchange to the server, which will call the underlying function and continue the execution of the program without setting the related connection variables. As the variables are not initialized to NULL the code later accesses those uninitialized variables, accessing random memory, which could lead to undefined behavior. The recommended workaround is to use ssh_packet_disconnect() instead, which does terminate the process. The impact of the vulnerability depends heavily on the compiler flag hardening configuration.
Published 2026-03-12 · Modified
8.2EPSS 0.013
CVE-2023-1668
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow.
Published 2023-04-10 · Modified
8.2EPSS 0.012
CVE-2020-25632
A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2021-03-03 · Modified
8.2EPSS 0.012
CVE-2026-35091
Corosync: corosync: denial of service and information disclosure via crafted udp packet
Published 2026-04-01 · Modified
8.2EPSS 0.011
CVE-2024-9341
Podman: buildah: cri-o: fips crypto-policy directory mounting issue in containers/common go library
Published 2024-10-01 · Modified
8.2EPSS 0.010
CVE-2026-58010
Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()
Published 2026-06-30 · Modified
8.2EPSS 0.009
CVE-2026-58012
Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()
Published 2026-06-30 · Modified
8.2EPSS 0.009
CVE-2026-58013
Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"
Published 2026-06-30 · Modified
8.2EPSS 0.009
CVE-2021-4206
A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
Published 2022-04-29 · Modified
8.2EPSS 0.008
CVE-2018-11806
m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.
Published 2018-06-13 · Modified
8.2EPSS 0.008
CVE-2025-32990
Gnutls: vulnerability in gnutls certtool template parsing
Published 2025-07-10 · Modified
8.2EPSS 0.008
CVE-2021-20233
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2021-03-03 · Modified
8.2EPSS 0.006
CVE-2026-0966
Libssh: libssh: denial of service via zero-length input in ssh_get_hexa()
Published 2026-03-26 · Modified
8.2EPSS 0.006
CVE-2021-3750
A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointer overlaps with its MMIO region when it transfers the USB packets. Crafted content may be written to the controller's registers and trigger undesirable actions (such as reset) while the device is still transferring packets. This can ultimately lead to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition, or potentially execute arbitrary code within the context of the QEMU process on the host. This flaw affects QEMU versions before 7.0.0.
Published 2022-05-02 · Modified
8.2EPSS 0.005
CVE-2023-39191
Kernel: ebpf: insufficient stack type checks in dynptr
Published 2023-10-04 · Modified
8.2EPSS 0.005
CVE-2026-2436
Libsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake
Published 2026-03-26 · Analyzed
8.2EPSS 0.004
CVE-2021-4207
A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious privileged guest user could use this flaw to crash the QEMU process on the host or potentially execute arbitrary code within the context of the QEMU process.
Published 2022-04-29 · Modified
8.2EPSS 0.004
CVE-2026-5119
Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment
Published 2026-03-30 · Modified
8.2EPSS 0.003
← Prev9 / 57Next →