VendorsRed Hatlinux6.0
Vulnerabilities

Red Hat Linux 6.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

59CVEs
CVE-1999-0872
Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.
Published 2000-02-04 · Modified
7.2EPSS 0.004
CVE-1999-0740
Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.
Published 2000-03-22 · Modified
6.4EPSS 0.021
CVE-2002-0638
setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary file when modifying /etc/passwd, which may allow local users to gain privileges via a complex race condition that uses an open file descriptor in utility programs such as chfn and chsh.
Published 2003-04-02 · Modified
6.2EPSS 0.005
CVE-2000-0031
The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack.
Published 2000-03-22 · Modified
6.2EPSS 0.003
CVE-2018-7110
A remote unauthorized disclosure of information vulnerability was identified in HPE Service Governance Framework (SGF) version 4.2, 4.3. A race condition under high load in SGF exists where SGF transferred different parameter to the enabler.
Published 2018-10-17 · Modified
5.9EPSS 0.007
CVE-2018-14655
A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascript-Code via the 'state'-parameter in the authentication URL. This allows an XSS-Attack upon succesfully login.
Published 2018-11-13 · Modified
5.4EPSS 0.012
CVE-2000-0508
rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request.
Published 2000-10-13 · Modified
5.01 PoCEPSS 0.086
CVE-2000-0668
pam_console PAM module in Linux systems allows a user to access the system console and reboot the system when a display manager such as gdm or kdm has XDMCP enabled.
Published 2000-10-13 · Modified
5.01 PoCEPSS 0.072
CVE-1999-0804
Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.
Published 2000-01-04 · Modified
5.01 PoCEPSS 0.056
CVE-2000-0289
IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection.
Published 2000-10-13 · Modified
5.0EPSS 0.026
CVE-2000-0364
screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to other ttys.
Published 2000-05-24 · Modified
4.6EPSS 0.004
CVE-2000-0365
Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices.
Published 2000-05-24 · Modified
4.6EPSS 0.004
CVE-2002-0044
GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.
Published 2002-06-25 · Modified
3.6EPSS 0.004
CVE-2000-0263
The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.
Published 2000-10-13 · Modified
2.11 PoCEPSS 0.010
CVE-2000-0531
Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets.
Published 2000-07-12 · Modified
2.11 PoCEPSS 0.009
CVE-2001-0169
When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
Published 2001-05-07 · Modified
2.11 PoCEPSS 0.009
CVE-2000-0286
X fontserver xfs allows local users to cause a denial of service via malformed input to the server.
Published 2000-04-26 · Modified
2.11 PoCEPSS 0.007
CVE-1999-1496
Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.
Published 2001-09-12 · Modified
2.1EPSS 0.005
CVE-2000-0633
Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.
Published 2000-10-13 · Modified
2.1EPSS 0.004
← Prev2 / 2