VendorsRed Hatlinuxall versions
Vulnerabilities

Red Hat Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

252CVEs
CVE-2000-0917
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
Published 2001-01-22 · Modified
10.04 PoCEPSS 0.787
CVE-2000-0248
The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.
Published 2000-04-26 · Modified
10.02 PoCEPSS 0.737
CVE-1999-0043
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
Published 1999-09-29 · Modified
10.0EPSS 0.446
CVE-2000-0322
The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execute arbitrary commands via shell metacharacters.
Published 2000-10-13 · Modified
10.01 PoCEPSS 0.416
CVE-1999-0368
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
Published 1999-09-29 · Modified
10.02 PoCEPSS 0.398
CVE-1999-0009
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Published 1999-09-29 · Modified
10.02 PoCEPSS 0.290
CVE-1999-0002
Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.
Published 1999-09-29 · Modified
10.01 PoCEPSS 0.279
CVE-2000-0666
rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.
Published 2000-10-13 · Modified
10.03 PoCEPSS 0.263
CVE-2000-1221
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP.
Published 2005-04-21 · Modified
10.01 PoCEPSS 0.167
CVE-2000-0389
Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.
Published 2000-07-12 · Modified
10.03 PoCEPSS 0.165
CVE-2000-0844
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
Published 2001-01-22 · Modified
10.011 PoCEPSS 0.156
CVE-2002-0083
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
Published 2002-06-25 · Modified
10.01 PoCEPSS 0.147
CVE-2001-0233
Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field.
Published 2001-05-07 · Modified
10.01 PoCEPSS 0.146
CVE-2000-1220
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.
Published 2005-04-21 · Modified
10.01 PoCEPSS 0.142
CVE-2001-0197
Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands.
Published 2001-05-07 · Modified
10.01 PoCEPSS 0.131
CVE-1999-0042
Buffer overflow in University of Washington's implementation of IMAP and POP servers.
Published 1999-09-29 · Modified
10.01 PoCEPSS 0.127
CVE-2004-0902
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII hostname.
Published 2004-09-24 · Modified
10.0EPSS 0.101
CVE-1999-0192
Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.
Published 1999-09-29 · Modified
10.02 PoCEPSS 0.100
CVE-2004-0903
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.
Published 2004-09-24 · Modified
10.0EPSS 0.097
CVE-2000-0017
Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter.
Published 2000-02-04 · Modified
10.01 PoCEPSS 0.089
CVE-2004-0904
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
Published 2004-09-24 · Modified
10.0EPSS 0.080
CVE-1999-0011
Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.
Published 1999-09-29 · Modified
10.0EPSS 0.055
CVE-2004-1025
Multiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.
Published 2004-12-15 · Modified
10.0EPSS 0.052
CVE-2004-1026
Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cause a denial of service (application crash) and execute arbitrary code via certain image files.
Published 2004-12-10 · Modified
10.0EPSS 0.049
CVE-2000-1010
Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters.
Published 2001-01-22 · Modified
10.0EPSS 0.046
CVE-2000-0391
Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.
Published 2000-07-12 · Modified
10.0EPSS 0.040
CVE-2000-0390
Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.
Published 2000-07-12 · Modified
10.0EPSS 0.040
CVE-2005-3625
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
Published 2006-01-06 · Modified
10.0EPSS 0.038
CVE-2003-0248
The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.
Published 2003-06-05 · Modified
10.0EPSS 0.037
CVE-2003-0041
Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.
Published 2003-02-01 · Modified
10.0EPSS 0.035
CVE-1999-0832
Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname.
Published 2000-06-02 · Modified
10.0EPSS 0.035
CVE-1999-1542
RPMMail before 1.4 allows remote attackers to execute commands via an e-mail message with shell metacharacters in the "MAIL FROM" command.
Published 2002-03-09 · Modified
10.0EPSS 0.034
CVE-1999-0814
Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.
Published 2000-01-04 · Modified
10.0EPSS 0.022
CVE-1999-0894
Red Hat Linux screen program does not use Unix98 ptys, allowing local users to write to other terminals.
Published 2000-01-04 · Modified
10.0EPSS 0.019
CVE-1999-1299
rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system calls, which causes the calls to fail to modify the ownership of the file.
Published 2001-09-12 · Modified
10.0EPSS 0.018
CVE-1999-0798
Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.
Published 2000-02-04 · Modified
10.0EPSS 0.016
CVE-2000-0093
An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5.
Published 2000-02-08 · Modified
10.0EPSS 0.014
CVE-2008-2427
Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote attackers to execute arbitrary code via a crafted format keyword in a Sun TAAC file.
Published 2008-06-24 · Modified
9.31 PoCEPSS 0.161
CVE-1999-0704
Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others.
Published 2000-01-04 · Modified
9.32 PoCEPSS 0.045
CVE-2025-36049
IBM webMethods Integration Sever XML external entity injection
Published 2025-06-18 · Analyzed
8.8EPSS 0.006
1 / 7Next →