VendorsRed Hatlinuxall versions
Vulnerabilities

Red Hat Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

252CVEs
CVE-2025-36048
IBM webMethods Integration Sever code execution
Published 2025-06-18 · Analyzed
7.2EPSS 0.005
CVE-2002-0062
Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling."
Published 2003-04-02 · Modified
7.2EPSS 0.005
CVE-2003-0188
lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.
Published 2003-05-17 · Modified
7.2EPSS 0.004
CVE-2000-1207
userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).
Published 2002-07-31 · Modified
7.2EPSS 0.004
CVE-1999-0390
Buffer overflow in Dosemu Slang library in Linux.
Published 2000-03-22 · Modified
7.2EPSS 0.004
CVE-2000-0392
Buffer overflow in ksu in Kerberos 5 allows local users to gain root privileges.
Published 2000-07-12 · Modified
7.2EPSS 0.004
CVE-2000-1189
Buffer overflow in pam_localuser PAM module in Red Hat Linux 7.x and 6.x allows attackers to gain privileges.
Published 2001-01-22 · Modified
7.2EPSS 0.004
CVE-2002-1160
The default configuration of the pam_xauth module forwards MIT-Magic-Cookies to new X sessions, which could allow local users to gain root privileges by stealing the cookies from a temporary .xauth file, which is created with the original user's credentials after root uses su.
Published 2004-09-01 · Modified
7.2EPSS 0.004
CVE-1999-1327
Buffer overflow in linuxconf 1.11r11-rh2 on Red Hat Linux 5.1 allows local users to gain root privileges via a long LANG environmental variable.
Published 2002-03-09 · Modified
7.2EPSS 0.004
CVE-1999-1182
Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error.
Published 2001-09-12 · Modified
7.2EPSS 0.004
CVE-2001-0128
Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.
Published 2001-05-07 · Modified
7.2EPSS 0.004
CVE-2000-0186
Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument.
Published 2000-04-10 · Modified
7.2EPSS 0.004
CVE-2000-0934
Glint in Red Hat Linux 5.2 allows local users to overwrite arbitrary files and cause a denial of service via a symlink attack.
Published 2001-01-22 · Modified
7.2EPSS 0.004
CVE-1999-1329
Buffer overflow in SysVInit in Red Hat Linux 5.1 and earlier allows local users to gain privileges.
Published 2002-03-09 · Modified
7.2EPSS 0.004
CVE-2000-0867
Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.
Published 2001-01-22 · Modified
7.2EPSS 0.004
CVE-2000-0566
makewhatis in Linux man package allows local users to overwrite files via a symlink attack.
Published 2000-10-13 · Modified
7.2EPSS 0.004
CVE-1999-1186
rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious program using the -print-pipe command line parameter.
Published 2001-09-12 · Modified
7.2EPSS 0.004
CVE-1999-1328
linuxconf before 1.11.r11-rh3 on Red Hat Linux 5.1 allows local users to overwrite arbitrary files and gain root access via a symlink attack.
Published 2002-03-09 · Modified
7.2EPSS 0.004
CVE-2001-1028
Buffer overflow in ultimate_source function of man 1.5 and earlier allows local users to gain privileges.
Published 2003-04-02 · Modified
7.2EPSS 0.004
CVE-1999-0297
Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.
Published 2000-01-04 · Modified
7.2EPSS 0.004
CVE-2001-1374
expect before 5.32 searches for its libraries in /var/tmp before other directories, which could allow local users to gain root privileges via a Trojan horse library that is accessed by mkpasswd.
Published 2003-04-02 · Modified
7.2EPSS 0.004
CVE-2000-1208
Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.
Published 2002-08-01 · Modified
7.2EPSS 0.004
CVE-1999-0872
Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.
Published 2000-02-04 · Modified
7.2EPSS 0.004
CVE-1999-1095
sort creates temporary files and follows symbolic links, which allows local users to modify arbitrary files that are writable by the user running sort, as observed in updatedb and other programs that use sort.
Published 2001-09-12 · Modified
7.2EPSS 0.003
CVE-2004-0217
The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log.
Published 2004-03-16 · Modified
7.0EPSS 0.005
CVE-2014-3250
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.
Published 2017-12-11 · Modified
6.5EPSS 0.009
CVE-1999-0740
Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.
Published 2000-03-22 · Modified
6.4EPSS 0.021
CVE-1999-1335
snmpd server in cmu-snmp SNMP package before 3.3-1 in Red Hat Linux 4.0 is configured to allow remote attackers to read and write sensitive information.
Published 2002-03-09 · Modified
6.4EPSS 0.019
CVE-2004-1235
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
Published 2005-01-20 · Modified
6.23 PoCEPSS 0.029
CVE-2018-10864
An uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A remote attacker may provide an existing but invalid XML file which would be opened and never closed, possibly producing a Denial of Service.
Published 2018-08-13 · Modified
6.2EPSS 0.012
CVE-2007-3103
The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file.
Published 2007-07-15 · Modified
6.21 PoCEPSS 0.009
CVE-2002-0638
setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary file when modifying /etc/passwd, which may allow local users to gain privileges via a complex race condition that uses an open file descriptor in utility programs such as chfn and chsh.
Published 2003-04-02 · Modified
6.2EPSS 0.005
CVE-2000-0031
The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack.
Published 2000-03-22 · Modified
6.2EPSS 0.003
CVE-2001-1383
initscript in setserial 2.17-4 and earlier uses predictable temporary file names, which could allow local users to conduct unauthorized operations on files.
Published 2003-04-02 · Modified
6.2EPSS 0.003
CVE-2007-5079
Red Hat Enterprise Linux 4 does not properly compile and link gdm with tcp_wrappers on x86_64 platforms, which might allow remote attackers to bypass intended access restrictions.
Published 2007-09-25 · Modified
6.0EPSS 0.015
CVE-2023-5981
Gnutls: timing side-channel in the rsa-psk authentication
Published 2023-11-28 · Analyzed
5.9EPSS 0.013
CVE-2018-7110
A remote unauthorized disclosure of information vulnerability was identified in HPE Service Governance Framework (SGF) version 4.2, 4.3. A race condition under high load in SGF exists where SGF transferred different parameter to the enabler.
Published 2018-10-17 · Modified
5.9EPSS 0.007
CVE-2021-23827
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clear cached pictures, even after deletion via normal methodology within the client, or by utilizing the "Explode message/Explode now" functionality. Local filesystem access is needed by the attacker.
Published 2021-02-22 · Modified
5.5EPSS 0.003
CVE-2018-14655
A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascript-Code via the 'state'-parameter in the authentication URL. This allows an XSS-Attack upon succesfully login.
Published 2018-11-13 · Modified
5.4EPSS 0.012
CVE-2001-1013
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.
Published 2002-02-02 · Modified
5.01 PoCEPSS 0.656
← Prev4 / 7Next →