← Back

Enterprise Linux

enterprise_linux

Vendor: Redhat • 1,858 CVEs

CVEs (1,858)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
OpensuseRedhat+1 more
11Debian Linux
Enterprise LinuxEnterprise Linux Desktop+8 more
May 6, 2026
Jun 9, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-b...Show more
The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow.Show less
5Canonical
LinuxNovell+2 more
12Enterprise Linux
LinuxLinux Kernel+9 more
May 6, 2026
May 23, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecifie...Show more
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and ppp_unregister_channel functions.Show less
2Php
Redhat
2Enterprise Linux
Php
May 6, 2026
May 16, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow...Show more
The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1352.Show less
2Php
Redhat
8Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+5 more
May 6, 2026
May 16, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote a...Show more
The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.Show less
2Php
Redhat
8Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+5 more
May 6, 2026
May 16, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows r...Show more
The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by a "Python script text executable" rule.Show less
2Php
Redhat
8Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+5 more
May 6, 2026
May 16, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related...Show more
The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related to a "type confusion" issue.Show less
2Php
Redhat
8Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+5 more
May 6, 2026
May 16, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibl...Show more
The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to a "type confusion" issue.Show less
2Php
Redhat
8Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+5 more
May 6, 2026
May 16, 2016
N/A· v4
6.5 MEDIUM· v3
7.5 HIGH· v2
PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an applicatio...Show more
PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument save method or (2) the GD imagepsloadfont function, as demonstrated by a filename\0.html attack that bypasses an intended configuration in which client users may write to only .html files.Show less
2Php
Redhat
8Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+5 more
May 6, 2026
May 16, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via crafted input to an application that calls...Show more
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via crafted input to an application that calls the stream_resolve_include_path function in ext/standard/streamsfuncs.c, as demonstrated by a filename\0.extension attack that bypasses an intended configuration in which client users may read files with only one specific extension.Show less
2Php
Redhat
8Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+5 more
May 6, 2026
May 16, 2016
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application...Show more
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file function, as demonstrated by a filename\0.xml attack that bypasses an intended configuration in which client users may read only .xml files.Show less
2Linux
Redhat
3Enterprise Linux
Enterprise MrgLinux Kernel
May 6, 2026
May 2, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of servic...Show more
The VFS subsystem in the Linux kernel 3.x provides an incomplete set of requirements for setattr operations that underspecifies removing extended privilege attributes, which allows local users to cause a denial of service (capability stripping) via a failed invocation of a system call, as demonstrated by using chown to remove a capability from the ping or Wireshark dumpcap program.Show less
4Debian
LinuxOracle+1 more
4Debian Linux
Enterprise LinuxLinux+1 more
May 6, 2026
Apr 27, 2016
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to cause a denial of service (system crash) or possibly have unspecified ot...Show more
The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted application, related to arch/s390/include/asm/mmu_context.h and arch/s390/include/asm/pgalloc.h.Show less
6Debian
IbmMariadb+3 more
7Debian Linux
Enterprise LinuxLeap+4 more
May 6, 2026
Apr 21, 2016
N/A· v4
5.5 MEDIUM· v3
3.5 LOW· v2
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availabili...Show more
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to Security: Privileges.Show less
3Canonical
OracleRedhat
3Enterprise Linux
MysqlUbuntu Linux
May 6, 2026
Apr 21, 2016
N/A· v4
5.5 MEDIUM· v3
3.5 LOW· v2
Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Security: Encryption.
3Canonical
OracleRedhat
3Enterprise Linux
MysqlUbuntu Linux
May 6, 2026
Apr 21, 2016
N/A· v4
4.7 MEDIUM· v3
3.5 LOW· v2
Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Options.
5Debian
MariadbOpensuse+2 more
5Debian Linux
Enterprise LinuxLeap+2 more
May 6, 2026
Apr 21, 2016
N/A· v4
4.7 MEDIUM· v3
3.5 LOW· v2
Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier and MariaDB 10.0.x before 10.0.25 and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to InnoDB.
6Debian
IbmMariadb+3 more
7Debian Linux
Enterprise LinuxLeap+4 more
May 6, 2026
Apr 21, 2016
N/A· v4
5.5 MEDIUM· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availabili...Show more
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to Replication.Show less
6Debian
IbmMariadb+3 more
7Debian Linux
Enterprise LinuxLeap+4 more
May 6, 2026
Apr 21, 2016
N/A· v4
5.5 MEDIUM· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availabili...Show more
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to PS.Show less
6Debian
IbmMariadb+3 more
7Debian Linux
Enterprise LinuxLeap+4 more
May 6, 2026
Apr 21, 2016
N/A· v4
5.5 MEDIUM· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availabili...Show more
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to PS.Show less
6Debian
IbmMariadb+3 more
7Debian Linux
Enterprise LinuxLeap+4 more
May 6, 2026
Apr 21, 2016
N/A· v4
5.5 MEDIUM· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availabili...Show more
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to FTS.Show less