VendorsRed Hatenterprise_linux7.0
Vulnerabilities

Red Hat Enterprise Linux 7.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1016CVEs
CVE-2021-3717
A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This flaw affects wildfly-core versions prior to 17.0.
Published 2022-05-24 · Modified
7.8EPSS 0.003
CVE-2022-2964
A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes.
Published 2022-09-09 · Modified
7.8EPSS 0.003
CVE-2023-0664
A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows installer via repair custom actions to elevate their privileges on the system.
Published 2023-03-29 · Modified
7.8EPSS 0.003
CVE-2020-14351
A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monitor perf events to corrupt memory and possibly escalate privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2020-12-03 · Modified
7.8EPSS 0.003
CVE-2025-46397
Xfig: xfig: stack-overflow allows possible code execution via local input manipulation
Published 2025-04-23 · Modified
7.8EPSS 0.003
CVE-2026-6384
Gimp: gimp: arbitrary code execution or denial of service via buffer overflow in gif image processing
Published 2026-04-15 · Modified
7.8EPSS 0.003
CVE-2025-0678
Grub2: squash4: integer overflow may lead to heap based out-of-bounds write when reading data
Published 2025-03-03 · Modified
7.8EPSS 0.003
CVE-2019-19354
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Published 2021-03-24 · Modified
7.8EPSS 0.003
CVE-2023-34318
Heap-buffer-overflow in src/hcom.c
Published 2023-07-10 · Modified
7.8EPSS 0.003
CVE-2023-3972
Insights-client: unsafe handling of temporary files and directories
Published 2023-11-01 · Modified
7.8EPSS 0.003
CVE-2026-48864
Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
Published 2026-05-26 · Modified
7.8EPSS 0.003
CVE-2026-50259
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing
Published 2026-06-05 · Modified
7.8EPSS 0.002
CVE-2024-45782
Grub2: fs/hfs: strcpy() using the volume name (fs/hfs.c:382)
Published 2025-03-03 · Modified
7.8EPSS 0.002
CVE-2026-50258
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levels
Published 2026-06-05 · Modified
7.8EPSS 0.002
CVE-2026-50256
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch
Published 2026-06-05 · Modified
7.8EPSS 0.002
CVE-2026-50264
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds heap write in dri2 drigetbuffers/drigetbufferswithformat
Published 2026-06-05 · Modified
7.8EPSS 0.002
CVE-2026-50257
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence()
Published 2026-06-05 · Modified
7.8EPSS 0.002
CVE-2026-50260
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter()
Published 2026-06-05 · Modified
7.8EPSS 0.002
CVE-2026-50261
Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter()
Published 2026-06-05 · Modified
7.8EPSS 0.002
CVE-2026-42170
Gimp: gimp dds plug-in heap-based buffer overflow via bpp mismatch in load_layer() (ddsread.c)
Published 2026-08-08 · Analyzed
7.8EPSS 0.002
CVE-2026-53009
ice: fix double-free of tx_buf skb
Published 2026-06-24 · Modified
7.8EPSS 0.002
CVE-2026-54230
Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites
Published 2026-06-13 · Modified
7.8EPSS 0.002
CVE-2026-53145
drm/gem: Try to fix change_handle ioctl, attempt 4
Published 2026-06-25 · Analyzed
7.8EPSS 0.001
CVE-2015-3456
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM.
Published 2015-05-13 · Modified
7.71 PoCEPSS 0.153
CVE-2019-3900
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scenario.
Published 2019-04-25 · Modified
7.7EPSS 0.043
CVE-2020-1711
An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote user could use this flaw to crash the QEMU process, resulting in a denial of service or potential execution of arbitrary code with privileges of the QEMU process on the host.
Published 2020-02-11 · Modified
7.7EPSS 0.040
CVE-2018-1000026
Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM..
Published 2018-02-09 · Modified
7.7EPSS 0.040
CVE-2017-2595
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
Published 2018-07-27 · Modified
7.7EPSS 0.031
CVE-2023-6563
Keycloak: offline session token dos
Published 2023-12-14 · Modified
7.7EPSS 0.012
CVE-2017-10661
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.
Published 2017-08-19 · Modified
7.61 PoCEPSS 0.134
CVE-2015-2775
Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.
Published 2015-04-13 · Modified
7.6EPSS 0.079
CVE-2023-6478
Xorg-x11-server: out-of-bounds memory read in rrchangeoutputproperty and rrchangeproviderproperty
Published 2023-12-13 · Modified
7.6EPSS 0.016
CVE-2020-25647
A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assumes the USB device is providing sane values. If properly exploited, an attacker could trigger memory corruption leading to arbitrary code execution allowing a bypass of the Secure Boot mechanism. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2021-03-03 · Modified
7.6EPSS 0.008
CVE-2023-50387
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
Published 2024-02-14 · Modified
7.5EPSS 1.000
CVE-2016-2183
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.
Published 2016-09-01 · Modified
7.5EPSS 0.947
CVE-2019-11478
SACK can cause extensive memory use via fragmented resend queue
Published 2019-06-18 · Modified
7.5EPSS 0.947
CVE-2019-11479
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commits 967c05aee439e6e5d7d805e195b3a20ef5c433d6 and 5f3e2bf008c2221478101ee72f5cb4654b9fc363.
Published 2019-06-18 · Modified
7.5EPSS 0.917
CVE-2020-9490
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
Published 2020-08-07 · Modified
7.5EPSS 0.888
CVE-2016-9079
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
Published 2018-06-11 · Analyzed
7.5KEV2 PoCEPSS 0.874
CVE-2023-50868
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
Published 2024-02-14 · Analyzed
7.5EPSS 0.817
← Prev9 / 26Next →