VendorsRed Hatenterprise_linux9.0
Vulnerabilities

Red Hat Enterprise Linux 9.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

601CVEs
CVE-2022-2211
A vulnerability was found in libguestfs. This issue occurs while calculating the greatest possible number of matching keys in the get_keys() function. This flaw leads to a denial of service, either by mistake or malicious actor.
Published 2022-07-12 · Modified
6.5EPSS 0.009
CVE-2026-2340
Samba: vfs_worm does not block directory modification
Published 2026-05-27 · Modified
6.5EPSS 0.009
CVE-2024-6237
389-ds-base: unauthenticated user can trigger a dos by sending a specific extended search request
Published 2024-07-09 · Modified
6.5EPSS 0.009
CVE-2023-32573
In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled.
Published 2023-05-10 · Modified
6.5EPSS 0.009
CVE-2022-2568
A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions to modify the account settings of the superuser account and also remove the superuser privileges.
Published 2022-08-18 · Modified
6.5EPSS 0.009
CVE-2026-2272
Gimp: gimp: memory corruption due to integer overflow in ico file handling
Published 2026-03-26 · Analyzed
6.5EPSS 0.008
CVE-2023-4061
Wildfly-core: management user rbac permission allows unexpected reading of system-properties to an unauthorized actor
Published 2023-11-08 · Modified
6.5EPSS 0.008
CVE-2024-4629
Keycloak: potential bypass of brute force protection
Published 2024-09-03 · Modified
6.5EPSS 0.008
CVE-2023-3750
Libvirt: improper locking in virstoragepoolobjlistsearch may lead to denial of service
Published 2023-07-24 · Modified
6.5EPSS 0.008
CVE-2023-5215
Libnbd: crash or misbehaviour when nbd server returns an unexpected block size
Published 2023-09-28 · Modified
6.5EPSS 0.007
CVE-2026-59843
Libssh: libssh: denial of service via zero advertised channel packet size
Published 2026-07-21 · Modified
6.5EPSS 0.007
CVE-2026-59844
Libssh: libssh: denial of service via oversized sftp read length
Published 2026-07-21 · Modified
6.5EPSS 0.007
CVE-2023-43785
Libx11: out-of-bounds memory access in _xkbreadkeysyms()
Published 2023-10-10 · Modified
6.5EPSS 0.006
CVE-2024-0564
Kernel: max page sharing of kernel samepage merging (ksm) may cause memory deduplication
Published 2024-01-30 · Modified
6.5EPSS 0.006
CVE-2023-39329
Openjpeg: resource exhaustion will occur in the opj_t1_decode_cblks function in the tcd.c
Published 2024-07-13 · Modified
6.5EPSS 0.006
CVE-2026-9150
Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums
Published 2026-05-20 · Modified
6.5EPSS 0.006
CVE-2025-14512
Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow
Published 2025-12-11 · Modified
6.5EPSS 0.006
CVE-2025-5351
Libssh: double free vulnerability in libssh key export functions
Published 2025-07-04 · Modified
6.5EPSS 0.006
CVE-2023-5455
Ipa: invalid csrf protection
Published 2024-01-10 · Modified
6.5EPSS 0.006
CVE-2026-9149
Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file
Published 2026-05-20 · Modified
6.5EPSS 0.006
CVE-2026-4426
Libarchive: libarchive: denial of service via malformed iso file processing
Published 2026-03-19 · Modified
6.5EPSS 0.006
CVE-2026-71225
Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
Published 2026-08-05 · Modified
6.5EPSS 0.005
CVE-2026-55653
Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service
Published 2026-06-23 · Modified
6.5EPSS 0.005
CVE-2023-38201
Keylime: challenge-response protocol bypass during agent registration
Published 2023-08-25 · Modified
6.5EPSS 0.005
CVE-2026-2239
Gimp: gimp: application crash (dos) via crafted psd file due to heap-buffer-overflow
Published 2026-03-26 · Analyzed
6.5EPSS 0.005
CVE-2025-47712
Nbd: nbdkit: integer overflow triggers an assertion resulting in denial of service
Published 2025-06-09 · Modified
6.5EPSS 0.005
CVE-2025-12801
Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
Published 2026-03-04 · Modified
6.5EPSS 0.005
CVE-2025-47711
Nbdkit: nbdkit-server: off-by-one error when processing block status may lead to a denial of service
Published 2025-06-09 · Modified
6.5EPSS 0.005
CVE-2026-5142
Foreman: foreman: cross-tenant private ssh key disclosure via taxonomy scoping bypass
Published 2026-07-01 · Analyzed
6.5EPSS 0.004
CVE-2026-5135
Foreman: foreman: unauthorized modification of host configurations via broken access control
Published 2026-07-01 · Analyzed
6.5EPSS 0.004
CVE-2026-73196
Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encoding
Published 2026-08-20 · Analyzed
6.5EPSS 0.004
CVE-2026-1801
Libsoup: libsoup: http request smuggling via malformed chunk headers
Published 2026-02-03 · Analyzed
6.5EPSS 0.004
CVE-2026-11820
Community.general: community.general nexmo — api credentials exposed in get url query string[security] community.general nexmo — api credentials exposed in get url query string
Published 2026-06-23 · Analyzed
6.5EPSS 0.004
CVE-2026-66339
Libsoup: libsoup: proxy credentials leak to destination server via proxy-authorization header in connect tunnels
Published 2026-07-24 · Analyzed
6.5EPSS 0.004
CVE-2026-66337
Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_read_until()
Published 2026-07-24 · Analyzed
6.5EPSS 0.004
CVE-2026-3633
Libsoup: libsoup: header and http request injection via crlf injection
Published 2026-03-17 · Analyzed
6.5EPSS 0.004
CVE-2025-9572
Foreman: satellite: graphql api permission bypass leads to information disclosure
Published 2026-02-27 · Modified
6.5EPSS 0.003
CVE-2024-49393
Mutt: neomutt: to and cc email header fields are not protected by cryptographic signing
Published 2024-11-12 · Modified
6.5EPSS 0.003
CVE-2023-3019
Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest()
Published 2023-07-24 · Modified
6.5EPSS 0.003
CVE-2026-3634
Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header
Published 2026-03-17 · Analyzed
6.5EPSS 0.003
← Prev9 / 16Next →