VendorsRed Hatenterprise_linux_for_ibm_z_systemsall versions
Vulnerabilities

Red Hat Enterprise Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

118CVEs
CVE-2021-31566
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to gain more privileges in a system.
Published 2022-08-23 · Modified
7.8EPSS 0.004
CVE-2022-0330
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system.
Published 2022-03-25 · Analyzed
7.8EPSS 0.004
CVE-2024-0409
Xorg-x11-server: selinux context corruption
Published 2024-01-18 · Modified
7.8EPSS 0.004
CVE-2022-0516
A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linux kernel. This flaw allows a local attacker with a normal user privilege to obtain unauthorized memory write access. This flaw affects Linux kernel versions prior to 5.17-rc4.
Published 2022-03-08 · Modified
7.8EPSS 0.003
CVE-2023-5633
Kernel: vmwgfx: reference count issue leads to use-after-free in surface handling
Published 2023-10-23 · Modified
7.8EPSS 0.003
CVE-2023-3972
Insights-client: unsafe handling of temporary files and directories
Published 2023-11-01 · Modified
7.8EPSS 0.003
CVE-2023-3899
Subscription-manager: inadequate authorization of com.redhat.rhsm1 d-bus interface allows local users to modify configuration
Published 2023-08-23 · Modified
7.8EPSS 0.002
CVE-2021-3551
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this vulnerability is to confidentiality.
Published 2022-02-16 · Modified
7.8EPSS 0.002
CVE-2025-1756
MongoDB Shell may be susceptible to local privilege escalation in Windows
Published 2025-02-27 · Analyzed
7.8EPSS 0.002
CVE-2025-1755
MongoDB Compass may be susceptible to local privilege escalation in Windows
Published 2025-02-27 · Analyzed
7.8EPSS 0.001
CVE-2025-13601
Glib: integer overflow in in g_escape_uri_string()
Published 2025-11-26 · Modified
7.7EPSS 0.003
CVE-2020-9490
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
Published 2020-08-07 · Modified
7.5EPSS 0.888
CVE-2021-3737
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
Published 2022-03-04 · Modified
7.5EPSS 0.116
CVE-2024-12085
Rsync: info leak via uninitialized stack contents
Published 2025-01-14 · Modified
7.5EPSS 0.088
CVE-2019-6470
dhcpd: use-after-free error leads crash in IPv6 mode when using mismatched BIND libraries
Published 2019-11-01 · Analyzed
7.5EPSS 0.088
CVE-2019-19906
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
Published 2019-12-19 · Modified
7.5EPSS 0.080
CVE-2012-2665
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.
Published 2012-08-06 · Modified
7.5EPSS 0.070
CVE-2015-3405
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute force attack with the 93 possible keys.
Published 2017-08-09 · Modified
7.5EPSS 0.053
CVE-2020-8945
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.
Published 2020-02-12 · Modified
7.5EPSS 0.051
CVE-2024-12088
Rsync: --safe-links option bypass leads to path traversal
Published 2025-01-14 · Modified
7.5EPSS 0.047
CVE-2006-5170
pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.
Published 2006-10-04 · Modified
7.5EPSS 0.041
CVE-2024-12087
Rsync: path traversal vulnerability in rsync
Published 2025-01-14 · Modified
7.5EPSS 0.023
CVE-2018-16881
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
Published 2019-01-25 · Modified
7.5EPSS 0.022
CVE-2023-5157
Mariadb: node crashes with transport endpoint is not connected mysqld got signal 6
Published 2023-09-26 · Modified
7.5EPSS 0.020
CVE-2021-4091
A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash.
Published 2022-02-18 · Modified
7.5EPSS 0.020
CVE-2023-38200
Keylime: registrar is subject to a dos against ssl connections
Published 2023-07-24 · Modified
7.5EPSS 0.014
CVE-2022-27649
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Published 2022-04-04 · Modified
7.5EPSS 0.014
CVE-2025-6021
Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2
Published 2025-06-12 · Modified
7.5EPSS 0.014
CVE-2026-42009
Gnutls: gnutls: denial of service via dtls packet reordering vulnerability
Published 2026-05-18 · Modified
7.5EPSS 0.011
CVE-2026-59849
Libssh: libssh: denial of service via automatic certificate authentication loop
Published 2026-07-21 · Analyzed
7.5EPSS 0.004
CVE-2025-3155
Yelp: arbitrary file read
Published 2025-04-03 · Modified
7.4EPSS 0.142
CVE-2026-15370
Libssh: libssh: stack buffer overflow in sftp server longname construction
Published 2026-07-21 · Analyzed
7.3EPSS 0.002
CVE-2023-3758
Sssd: race condition during authorization leads to gpo policies functioning inconsistently
Published 2024-04-18 · Modified
7.1EPSS 0.010
CVE-2025-2784
Libsoup: heap buffer over-read in `skip_insignificant_space` when sniffing content
Published 2025-04-03 · Modified
7.0EPSS 0.008
CVE-2021-3672
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
Published 2021-11-23 · Modified
6.8EPSS 0.028
CVE-2013-1675
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
Published 2013-05-16 · Analyzed
6.5KEVEPSS 0.067
CVE-2021-3733
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
Published 2022-03-07 · Modified
6.5EPSS 0.047
CVE-2023-42669
Samba: "rpcecho" development server allows denial of service via sleep() call on ad dc
Published 2023-11-06 · Modified
6.5EPSS 0.017
CVE-2023-4527
Glibc: stack read overflow in getaddrinfo in no-aaaa mode
Published 2023-09-18 · Modified
6.5EPSS 0.017
CVE-2021-3975
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.
Published 2022-08-23 · Modified
6.5EPSS 0.015
← Prev2 / 3Next →