VendorsRed Hatenterprise_linux_for_power_little_endian_eusall versions
Vulnerabilities

Red Hat Enterprise Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

99CVEs
CVE-2024-12085
Rsync: info leak via uninitialized stack contents
Published 2025-01-14 · Modified
7.5EPSS 0.088
CVE-2019-6470
dhcpd: use-after-free error leads crash in IPv6 mode when using mismatched BIND libraries
Published 2019-11-01 · Analyzed
7.5EPSS 0.088
CVE-2019-19906
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
Published 2019-12-19 · Modified
7.5EPSS 0.080
CVE-2024-12088
Rsync: --safe-links option bypass leads to path traversal
Published 2025-01-14 · Modified
7.5EPSS 0.047
CVE-2024-12087
Rsync: path traversal vulnerability in rsync
Published 2025-01-14 · Modified
7.5EPSS 0.023
CVE-2023-5157
Mariadb: node crashes with transport endpoint is not connected mysqld got signal 6
Published 2023-09-26 · Modified
7.5EPSS 0.020
CVE-2023-6536
Kernel: null pointer dereference in __nvmet_req_complete
Published 2024-02-07 · Modified
7.5EPSS 0.015
CVE-2023-6535
Kernel: null pointer dereference in nvmet_tcp_execute_request
Published 2024-02-07 · Modified
7.5EPSS 0.015
CVE-2024-7006
Libtiff: null pointer dereference in tif_dirinfo.c
Published 2024-08-08 · Modified
7.5EPSS 0.015
CVE-2023-6356
Kernel: null pointer dereference in nvmet_tcp_build_iovec
Published 2024-02-07 · Modified
7.5EPSS 0.015
CVE-2023-38200
Keylime: registrar is subject to a dos against ssl connections
Published 2023-07-24 · Modified
7.5EPSS 0.014
CVE-2022-27649
A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Published 2022-04-04 · Modified
7.5EPSS 0.014
CVE-2025-6021
Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2
Published 2025-06-12 · Modified
7.5EPSS 0.014
CVE-2026-42009
Gnutls: gnutls: denial of service via dtls packet reordering vulnerability
Published 2026-05-18 · Modified
7.5EPSS 0.013
CVE-2026-59849
Libssh: libssh: denial of service via automatic certificate authentication loop
Published 2026-07-21 · Analyzed
7.5EPSS 0.003
CVE-2025-3155
Yelp: arbitrary file read
Published 2025-04-03 · Modified
7.4EPSS 0.142
CVE-2026-15370
Libssh: libssh: stack buffer overflow in sftp server longname construction
Published 2026-07-21 · Analyzed
7.3EPSS 0.002
CVE-2023-3758
Sssd: race condition during authorization leads to gpo policies functioning inconsistently
Published 2024-04-18 · Modified
7.1EPSS 0.010
CVE-2025-2784
Libsoup: heap buffer over-read in `skip_insignificant_space` when sniffing content
Published 2025-04-03 · Modified
7.0EPSS 0.008
CVE-2021-3697
A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.
Published 2022-07-06 · Modified
7.0EPSS 0.005
CVE-2021-3609
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.
Published 2022-03-03 · Modified
7.0EPSS 0.004
CVE-2023-1476
Kpatch: mm/mremap.c: incomplete fix for cve-2022-41222
Published 2023-11-03 · Modified
7.0EPSS 0.002
CVE-2021-3696
A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitrary code execution and/or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.
Published 2022-07-06 · Modified
6.9EPSS 0.005
CVE-2021-3672
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
Published 2021-11-23 · Modified
6.8EPSS 0.028
CVE-2021-3733
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
Published 2022-03-07 · Modified
6.5EPSS 0.047
CVE-2023-42669
Samba: "rpcecho" development server allows denial of service via sleep() call on ad dc
Published 2023-11-06 · Modified
6.5EPSS 0.017
CVE-2023-4527
Glibc: stack read overflow in getaddrinfo in no-aaaa mode
Published 2023-09-18 · Modified
6.5EPSS 0.017
CVE-2021-3975
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged client with a read-only connection could use this flaw to perform a denial of service attack by causing the libvirt daemon to crash.
Published 2022-08-23 · Modified
6.5EPSS 0.015
CVE-2024-9676
Podman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can cause denial of service (dos)
Published 2024-10-15 · Modified
6.5EPSS 0.013
CVE-2020-14301
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.
Published 2021-05-27 · Modified
6.5EPSS 0.012
CVE-2022-24808
net-snmp: A malformed OID in a SET request to NET-SNMP-AGENT-MIB::nsLogTable can cause a NULL pointer dereference
Published 2024-04-16 · Analyzed
6.5EPSS 0.011
CVE-2022-24809
net-snmp: A malformed OID in a SET request to NET-SNMP-AGENT-MIB::nsLogTable can cause a NULL pointer dereference
Published 2024-04-16 · Analyzed
6.5EPSS 0.011
CVE-2022-24806
net-snmp vulnerable to Improper Input Validation when SETing malformed OIDs in master agent and subagent simultaneously
Published 2024-04-16 · Analyzed
6.5EPSS 0.011
CVE-2022-24807
net-snmp: A malformed OID in a SET request to SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable can cause an out-of-bounds memory access
Published 2024-04-16 · Analyzed
6.5EPSS 0.010
CVE-2023-5455
Ipa: invalid csrf protection
Published 2024-01-10 · Modified
6.5EPSS 0.006
CVE-2023-38201
Keylime: challenge-response protocol bypass during agent registration
Published 2023-08-25 · Modified
6.5EPSS 0.005
CVE-2023-4813
Glibc: potential use-after-free in gaih_inet()
Published 2023-09-12 · Modified
5.9EPSS 0.019
CVE-2016-2124
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
Published 2022-02-18 · Modified
5.9EPSS 0.018
CVE-2023-4806
Glibc: potential use-after-free in getaddrinfo()
Published 2023-09-18 · Modified
5.9EPSS 0.016
CVE-2023-5992
Opensc: side-channel leaks while stripping encryption pkcs#1 padding
Published 2024-01-31 · Modified
5.9EPSS 0.012
← Prev2 / 3Next →