VendorsRed Hatlinuxall versions
Vulnerabilities

Red Hat Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

252CVEs
CVE-2000-0357
ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.
Published 2000-05-24 · Modified
7.5EPSS 0.016
CVE-1999-1346
PAM configuration file for rlogin in Red Hat Linux 6.1 and earlier includes a less restrictive rule before a more restrictive one, which allows users to access the host via rlogin even if rlogin has been explicitly disabled using the /etc/nologin file.
Published 2001-09-12 · Modified
7.5EPSS 0.015
CVE-1999-0748
Buffer overflows in Red Hat net-tools package.
Published 2000-02-04 · Modified
7.5EPSS 0.015
CVE-2023-3430
Openimageio: heap-buffer-overflow in file src/gif.imageio/gifinput.cpp
Published 2023-12-18 · Modified
7.5EPSS 0.012
CVE-2000-0355
pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files.
Published 2000-05-24 · Modified
7.5EPSS 0.012
CVE-1999-0434
XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.
Published 2000-02-04 · Modified
7.5EPSS 0.011
CVE-2021-20566
IBM Resilient SOAR V38.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 199238.
Published 2021-06-16 · Modified
7.5EPSS 0.007
CVE-2019-0223
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.
Published 2019-04-23 · Modified
7.4EPSS 0.062
CVE-2016-3699
The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the initrd.
Published 2016-10-07 · Modified
7.4EPSS 0.005
CVE-2009-0714
Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Express SSE 4.x before build 46537, allows remote attackers to cause a denial of service (application crash) or read portions of memory via one or more crafted packets.
Published 2009-05-14 · Modified
7.22 PoCEPSS 0.516
CVE-2000-0170
Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable.
Published 2000-04-10 · Modified
7.23 PoCEPSS 0.020
CVE-1999-1491
abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.
Published 2001-09-12 · Modified
7.21 PoCEPSS 0.019
CVE-1999-0868
ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.
Published 2000-01-04 · Modified
7.2EPSS 0.015
CVE-2000-1134
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.
Published 2000-12-19 · Modified
7.22 PoCEPSS 0.014
CVE-2002-0004
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice.
Published 2002-06-25 · Modified
7.21 PoCEPSS 0.013
CVE-1999-0034
Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.
Published 1999-09-29 · Modified
7.24 PoCEPSS 0.012
CVE-2000-1009
dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.
Published 2000-11-29 · Modified
7.22 PoCEPSS 0.011
CVE-2000-0607
Buffer overflow in fld program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via an input file containing long CHARSET_REGISTRY or CHARSET_ENCODING settings.
Published 2000-07-19 · Modified
7.21 PoCEPSS 0.011
CVE-2000-1095
modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.
Published 2001-01-22 · Modified
7.21 PoCEPSS 0.011
CVE-2000-1125
restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.
Published 2000-12-19 · Modified
7.23 PoCEPSS 0.011
CVE-2000-0378
The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in.
Published 2000-10-13 · Modified
7.21 PoCEPSS 0.011
CVE-2002-1155
Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command line argument.
Published 2003-06-05 · Modified
7.22 PoCEPSS 0.011
CVE-1999-0130
Local users can start Sendmail in daemon mode and gain root privileges.
Published 1999-09-29 · Modified
7.21 PoCEPSS 0.011
CVE-2000-0219
Red Hat 6.0 allows local users to gain root access by booting single user and hitting ^C at the password prompt.
Published 2000-03-22 · Modified
7.21 PoCEPSS 0.010
CVE-1999-1490
xosview 1.5.1 in Red Hat 5.1 allows local users to gain root access via a long HOME environmental variable.
Published 2003-04-02 · Modified
7.21 PoCEPSS 0.009
CVE-2000-0230
Buffer overflow in imwheel allows local users to gain root privileges via the imwheel-solo script and a long HOME environmental variable.
Published 2000-06-02 · Modified
7.22 PoCEPSS 0.009
CVE-2000-0052
Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.
Published 2000-04-18 · Modified
7.22 PoCEPSS 0.009
CVE-2003-0019
uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.
Published 2004-09-01 · Modified
7.21 PoCEPSS 0.009
CVE-2001-0872
OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users to gain root privileges.
Published 2002-06-25 · Modified
7.2EPSS 0.009
CVE-2005-0750
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.
Published 2005-04-03 · Modified
7.24 PoCEPSS 0.008
CVE-2000-0229
gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a utility from gpm-root.
Published 2000-06-02 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0769
Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.
Published 2000-01-04 · Modified
7.21 PoCEPSS 0.008
CVE-2000-0118
The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.
Published 2000-02-08 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0405
A buffer overflow in lsof allows local users to obtain root privilege.
Published 1999-09-29 · Modified
7.22 PoCEPSS 0.008
CVE-2000-0963
Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.
Published 2000-11-29 · Modified
7.2EPSS 0.007
CVE-1999-0318
Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.
Published 2000-01-04 · Modified
7.2EPSS 0.006
CVE-1999-0131
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
Published 1999-09-29 · Modified
7.2EPSS 0.006
CVE-2000-0606
Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via a long -StartupMessage parameter.
Published 2000-07-19 · Modified
7.2EPSS 0.006
CVE-2004-0619
Integer overflow in the ubsec_keysetup function for Linux Broadcom 5820 cryptonet driver allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a negative add_dsa_buf_bytes variable, which leads to a buffer overflow.
Published 2004-06-30 · Modified
7.2EPSS 0.005
CVE-2002-0506
Buffer overflow in newt.c of newt windowing library (libnewt) 0.50.33 and earlier may allow attackers to cause a denial of service or execute arbitrary code in setuid programs that use libnewt.
Published 2003-04-02 · Modified
7.2EPSS 0.005
← Prev3 / 7Next →