← Back

Enterprise Linux

enterprise_linux

Vendor: Redhat • 1,858 CVEs

CVEs (1,858)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Apache
NetappRedhat
3Enterprise Linux
Http ServerStorage Automation Store
Nov 21, 2024
Mar 9, 2018
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Validation in the protocol parsing logic in the load balancer resulting in a Segmentation Fault in the serving httpd process.
2Redhat
Selinux Project
2Enterprise Linux
Selinux
Nov 21, 2024
Mar 2, 2018
N/A· v4
4.4 MEDIUM· v3
3.3 LOW· v2
Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity to change the SELinux context of an arbitrary file to a context with few restrictions. This only ha...Show more
Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity to change the SELinux context of an arbitrary file to a context with few restrictions. This only happens when the relabeling process is done, usually when taking SELinux state from disabled to enable (permissive or enforcing). The issue was found in policycoreutils 2.5-11.Show less
2Fedoraproject
Redhat
5389 Directory Server
Enterprise LinuxEnterprise Linux Desktop+2 more
Nov 21, 2024
Mar 1, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated attacker could potentiall...Show more
A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.Show less
4Canonical
DebianRedhat+1 more
11Debian Linux
Enterprise LinuxEnterprise Linux Aus+8 more
Nov 21, 2024
Feb 16, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes tha...Show more
In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted.Show less
4Canonical
DebianLinux+1 more
7Debian Linux
Enterprise LinuxEnterprise Linux Desktop+4 more
Nov 21, 2024
Feb 9, 2018
N/A· v4
7.7 HIGH· v3
6.8 MEDIUM· v2
Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes car...Show more
Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM..Show less
2Linux
Redhat
3Enterprise Linux
Enterprise MrgLinux Kernel
Nov 21, 2024
Feb 9, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.
3Debian
Libpam4j ProjectRedhat
3Debian Linux
Enterprise LinuxLibpam4j
Nov 21, 2024
Jan 18, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possib...Show more
It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive information.Show less
2Linux
Redhat
3Enterprise Linux
Enterprise MrgLinux Kernel
Nov 21, 2024
Jan 14, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.12. A lack of size check could cause a denial of service (BUG).
2Linux
Redhat
3Enterprise Linux
Enterprise MrgLinux Kernel
Nov 21, 2024
Jan 14, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13. A superfluous implicit page unlock for VM_SHARED hugetlbfs mapping could trigger a local denial of service (BUG).
1Redhat
2Enterprise Linux
Jboss Enterprise Application Platform
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This issue is a result of an...Show more
It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This issue is a result of an incomplete fix for CVE-2016-8656.Show less
2Freedesktop
Redhat
2Enterprise Linux
Xdg User Dirs
Nov 21, 2024
Jan 9, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped...Show more
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.Show less
4Canonical
FedoraprojectLinux+1 more
20Enterprise Linux
Enterprise Linux Compute Node EusEnterprise Linux Desktop+17 more
Nov 21, 2024
Jan 9, 2018
N/A· v4
4.7 MEDIUM· v3
4.9 MEDIUM· v2
A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it...Show more
A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption. This vulnerability could allow an unprivileged local user to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is thought to be unlikely.Show less
3Fedoraproject
NumpyRedhat
3Enterprise Linux
FedoraNumpy
Nov 21, 2024
Jan 8, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary f...Show more
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.Show less
3Fedoraproject
Netcf ProjectRedhat
3Enterprise Linux
FedoraNetcf
May 13, 2026
Dec 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.
2Linux
Redhat
2Enterprise Linux
Linux Kernel
May 13, 2026
Dec 29, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leveraging failure to disable APEI error injecti...Show more
The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leveraging failure to disable APEI error injection through EINJ when securelevel is set.Show less
2Heketi Project
Redhat
2Enterprise Linux
Heketi
May 13, 2026
Dec 18, 2017
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
2Heketi Project
Redhat
2Enterprise Linux
Heketi
May 13, 2026
Dec 18, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as...Show more
A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as the user running Heketi server and possibly privilege escalation.Show less
1Redhat
7Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Server+4 more
May 13, 2026
Dec 7, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary.
2Linux
Redhat
2Enterprise Linux
Linux Kernel
May 13, 2026
Nov 30, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference).
3Canonical
LinuxRedhat
3Enterprise Linux
Linux KernelUbuntu Linux
May 13, 2026
Nov 15, 2017
N/A· v4
6.3 MEDIUM· v3
6.9 MEDIUM· v2
The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-w...Show more
The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occurs after a race condition and a NULL pointer dereference.Show less