← Back

Enterprise Linux

enterprise_linux

Vendor: Redhat • 1,858 CVEs

CVEs (1,858)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Clusterlabs
FedoraprojectRedhat
3Enterprise Linux
FedoraPcs
May 13, 2026
Apr 21, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
4Apache
NetappOracle+1 more
79Api Gateway
Application Testing SuiteAutovue Vuelink Integration+76 more
May 13, 2026
Apr 17, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, c...Show more
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.Show less
1Redhat
2Enterprise Linux
Mod Cluster
May 13, 2026
Apr 12, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.
2Linux
Redhat
2Enterprise Linux
Linux Kernel
May 13, 2026
Mar 3, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances vi...Show more
Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) attack. NOTE: the vendor states "Basically if you care about this attack vector, disable deduplication." Share-until-written approaches for memory conservation among mutually untrusting tenants are inherently detectable for information disclosure, and can be classified as potentially misunderstood behaviors rather than vulnerabilitiesShow less
4Canonical
DebianLibjpeg Turbo+1 more
4Debian Linux
Enterprise LinuxLibjpeg Turbo+1 more
May 13, 2026
Feb 13, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
2Freedesktop
Redhat
2Enterprise Linux
Polkit
May 13, 2026
Feb 13, 2017
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
2Redhat
Uclouvain
5Enterprise Linux
Enterprise Linux For Ibm Z SystemsEnterprise Linux For Power Big Endian+2 more
May 6, 2026
Dec 22, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or potentially execute arbitrary code.
1Redhat
5Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+2 more
May 6, 2026
Dec 22, 2016
N/A· v4
4.4 MEDIUM· v3
4.9 MEDIUM· v2
sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user wit...Show more
sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could use this flaw to read content from specially formatted files with elevated privileges provided by sudo.Show less
7Canonical
DebianFedoraproject+4 more
18Cloud Backup
Debian LinuxEnterprise Linux+15 more
Apr 21, 2026
Nov 10, 2016
N/A· v4
7.0 HIGH· v3
7.2 HIGH· v2
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping,...Show more
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."Show less
2Gnome
Redhat
2Enterprise Linux
Shotwell
May 6, 2026
Oct 25, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.
5Debian
MariadbOracle+2 more
12Debian Linux
Enterprise LinuxEnterprise Linux Desktop+9 more
May 6, 2026
Sep 20, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5...Show more
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.Show less
6Cisco
NodejsOpenssl+3 more
9Content Security Management Appliance
DatabaseEnterprise Linux+6 more
May 29, 2026
Sep 1, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obt...Show more
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.Show less
5Debian
FedoraprojectFreebsd+2 more
6Debian Linux
Enterprise LinuxFedora+3 more
May 6, 2026
Aug 7, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a...Show more
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimensions in an image.Show less
4Ibm
MariadbOracle+1 more
11Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Server+8 more
May 6, 2026
Jul 21, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confi...Show more
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to Server: Connection.Show less
3Mariadb
OracleRedhat
3Enterprise Linux
MariadbMysql
May 6, 2026
Jul 21, 2016
N/A· v4
7.5 HIGH· v3
6.2 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.5.45 and earlier and 5.6.26 and earlier allows local users to affect confidentiality, integrity, and availability via vectors related to Server: Option.
4Ibm
MariadbOracle+1 more
5Enterprise Linux
LinuxMariadb+2 more
May 6, 2026
Jul 21, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confi...Show more
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to Server: Security: Encryption.Show less
2Isc
Redhat
2Bind
Enterprise Linux
May 6, 2026
Jul 6, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary DNS server crash) via a large AXFR response, and possibly allows IXFR se...Show more
ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary DNS server crash) via a large AXFR response, and possibly allows IXFR servers to cause a denial of service (IXFR client crash) via a large IXFR response and allows remote authenticated users to cause a denial of service (primary DNS server crash) via a large UPDATE message.Show less
4Fedoraproject
LinuxRedhat+1 more
11Enterprise Linux
FedoraLinux Enterprise Debuginfo+8 more
May 6, 2026
Jun 27, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by...Show more
The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by reading an RDS message.Show less
4Linux
NovellOracle+1 more
14Enterprise Linux
Enterprise Linux DesktopEnterprise Linux For Real Time+11 more
May 6, 2026
Jun 27, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash)...Show more
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.Show less
4Debian
OpensuseRedhat+1 more
11Debian Linux
Enterprise LinuxEnterprise Linux Desktop+8 more
May 6, 2026
Jun 9, 2016
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.