VendorsRed Hatlinuxall versions
Vulnerabilities

Red Hat Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

252CVEs
CVE-1999-1330
The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.
Published 2002-03-09 · Modified
4.6EPSS 0.004
CVE-2001-0496
kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.
Published 2001-05-24 · Modified
4.6EPSS 0.004
CVE-2000-0701
The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.
Published 2000-09-21 · Modified
4.6EPSS 0.004
CVE-2003-0464
The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd.
Published 2003-07-25 · Modified
4.6EPSS 0.004
CVE-2001-0635
Red Hat Linux 7.1 sets insecure permissions on swap files created during installation, which can allow a local attacker to gain additional privileges by reading sensitive information from the swap file, such as passwords.
Published 2002-03-09 · Modified
4.6EPSS 0.004
CVE-2000-0365
Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices.
Published 2000-05-24 · Modified
4.6EPSS 0.004
CVE-2000-0364
screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to other ttys.
Published 2000-05-24 · Modified
4.6EPSS 0.004
CVE-2003-0194
tcpdump does not properly drop privileges to the pcap user when starting up.
Published 2003-05-17 · Modified
4.6EPSS 0.004
CVE-2021-20567
IBM Resilient SOAR V38.0 could allow a local privileged attacker to obtain sensitive information due to improper or nonexisting encryption.IBM X-Force ID: 199239.
Published 2021-06-16 · Modified
4.4EPSS 0.001
CVE-2003-0442
Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.
Published 2003-06-20 · Modified
4.31 PoCEPSS 0.070
CVE-2019-4533
IBM Resilient SOAR V38.0 users may experience a denial of service of the SOAR Platform due to a insufficient input validation. IBM X-Force ID: 165589.
Published 2020-08-28 · Modified
4.3EPSS 0.010
CVE-2007-1462
The luci server component in conga preserves the password between page loads for the Add System/Cluster task flow by storing the password in the Value attribute of a password entry field, which allows attackers to steal the password by performing a "view source" or other operation to obtain the web page. NOTE: there are limited circumstances under which such an attack is feasible.
Published 2007-03-15 · Modified
4.3EPSS 0.009
CVE-2019-4579
IBM Resilient SOAR 38 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 167236.
Published 2020-08-28 · Modified
4.3EPSS 0.007
CVE-2007-1352
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.
Published 2007-04-06 · Modified
3.8EPSS 0.015
CVE-2001-0946
apmscript in Apmd in Red Hat 7.2 "Enigma" allows local users to create or change the modification dates of arbitrary files via a symlink attack on the LOW_POWER temporary file, which could be used to cause a denial of service, e.g. by creating /etc/nologin and disabling logins.
Published 2002-06-25 · Modified
3.6EPSS 0.004
CVE-2002-1509
A patch for shadow-utils 20000902 causes the useradd command to create a mail spool files with read/write privileges of the new user's group (mode 660), which allows other users in the same group to read or modify the new user's incoming email.
Published 2004-09-01 · Modified
3.6EPSS 0.004
CVE-2002-0044
GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.
Published 2002-06-25 · Modified
3.6EPSS 0.004
CVE-2002-0069
Memory leak in SNMP in Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service.
Published 2003-04-02 · Modified
2.6EPSS 0.028
CVE-2004-1335
Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function.
Published 2005-01-06 · Modified
2.11 PoCEPSS 0.010
CVE-2000-0263
The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.
Published 2000-10-13 · Modified
2.11 PoCEPSS 0.010
CVE-2000-0829
The tmpwatch utility in Red Hat Linux forks a new process for each directory level, which allows local users to cause a denial of service by creating deeply nested directories in /tmp or /var/tmp/.
Published 2001-05-07 · Modified
2.11 PoCEPSS 0.010
CVE-2004-1333
Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow.
Published 2005-01-06 · Modified
2.11 PoCEPSS 0.010
CVE-2000-0531
Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets.
Published 2000-07-12 · Modified
2.11 PoCEPSS 0.009
CVE-2000-0336
Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.
Published 2000-07-12 · Modified
2.11 PoCEPSS 0.009
CVE-2000-0816
Linux tmpwatch --fuser option allows local users to execute arbitrary commands by creating files whose names contain shell metacharacters.
Published 2001-05-07 · Modified
2.11 PoCEPSS 0.009
CVE-2001-0169
When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
Published 2001-05-07 · Modified
2.11 PoCEPSS 0.009
CVE-2001-0170
glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.
Published 2001-05-07 · Modified
2.12 PoCEPSS 0.008
CVE-2001-0736
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.
Published 2001-10-12 · Modified
2.11 PoCEPSS 0.008
CVE-2000-0286
X fontserver xfs allows local users to cause a denial of service via malformed input to the server.
Published 2000-04-26 · Modified
2.11 PoCEPSS 0.007
CVE-2004-1334
Integer overflow in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (kernel crash) via a cmsg_len that contains a -1, which leads to a buffer overflow.
Published 2005-01-06 · Modified
2.1EPSS 0.005
CVE-2002-0080
rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.
Published 2002-06-25 · Modified
2.1EPSS 0.005
CVE-1999-1496
Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.
Published 2001-09-12 · Modified
2.1EPSS 0.005
CVE-2003-0461
/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.
Published 2003-07-25 · Modified
2.1EPSS 0.004
CVE-1999-1332
gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.
Published 2002-03-09 · Modified
2.1EPSS 0.004
CVE-2000-0633
Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.
Published 2000-10-13 · Modified
2.1EPSS 0.004
CVE-1999-1407
ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.
Published 2002-03-09 · Modified
2.1EPSS 0.004
CVE-2000-0184
Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords.
Published 2000-04-25 · Modified
2.1EPSS 0.004
CVE-1999-1406
dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.
Published 2001-09-12 · Modified
2.1EPSS 0.004
CVE-2007-3379
Unspecified vulnerability in the kernel in Red Hat Enterprise Linux (RHEL) 4 on the x86_64 platform allows local users to cause a denial of service (OOPS) via unspecified vectors related to the get_gate_vma function and the fuser command.
Published 2007-09-17 · Modified
2.1EPSS 0.003
CVE-1999-1348
Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service.
Published 2001-09-12 · Modified
2.1EPSS 0.003
← Prev6 / 7Next →