← Back

Enterprise Linux

enterprise_linux

Vendor: Redhat • 1,858 CVEs

CVEs (1,858)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectRedhat
4Debian Linux
Enterprise LinuxFedora+1 more
Nov 21, 2024
Dec 3, 2019
N/A· v4
4.7 MEDIUM· v3
3.3 LOW· v2
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
3Linux
OpensuseRedhat
3Enterprise Linux
LeapLinux Kernel
Jun 17, 2026
Nov 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.4 MEDIUM· v2
In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large o...Show more
In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large old_size value is used in a memset call, aka CID-345c0dbf3a30.Show less
5Canonical
FedoraprojectLinux+2 more
5Enterprise Linux
FedoraLeap+2 more
Jun 17, 2026
Nov 27, 2019
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and...Show more
The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.Show less
2Linux
Redhat
2Dhcp6c
Enterprise Linux
Nov 21, 2024
Nov 27, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.
3Debian
GnupgRedhat
3Debian Linux
Enterprise LinuxGnupg
Nov 21, 2024
Nov 27, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate.
4Accountsservice Project
DebianOpensuse+1 more
4Accountsservice
Debian LinuxEnterprise Linux+1 more
Nov 21, 2024
Nov 27, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.
5Canonical
OracleRedhat+2 more
5Enterprise Linux
Mysql WorkbenchSinec Infrastructure Network Services+2 more
Jun 17, 2026
Nov 27, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarget in expr.c.
3Ethz
FedoraprojectRedhat
3Enterprise Linux
FedoraXquest
Nov 21, 2024
Nov 27, 2019
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
A password generation weakness exists in xquest through 2016-06-13.
2Artifex
Redhat
93scale Api Management
Enterprise LinuxEnterprise Linux Desktop+6 more
Jun 17, 2026
Nov 27, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially cra...Show more
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.Show less
5Canonical
DebianFedoraproject+2 more
5Debian Linux
Enterprise LinuxFedora+2 more
Jun 17, 2026
Nov 27, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrar...Show more
A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join_existing function is called after a STA connects to an AP.Show less
3Debian
Hardlink ProjectRedhat
3Debian Linux
Enterprise LinuxHardlink
Nov 21, 2024
Nov 26, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.
3Debian
Hardlink ProjectRedhat
3Debian Linux
Enterprise LinuxHardlink
Nov 21, 2024
Nov 26, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote att...Show more
Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote attacker could provide a specially-crafted directory tree and trick the local user into consolidating it, leading to hardlink executable crash or potentially arbitrary code execution with user privileges.Show less
3Debian
Hardlink ProjectRedhat
3Debian Linux
Enterprise LinuxHardlink
Nov 21, 2024
Nov 26, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory...Show more
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution with the privileges of the user running the hardlink executable.Show less
4Debian
FedoraprojectLibuser Project+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Jan 23, 2026
Nov 25, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
libuser has information disclosure when moving user's home directory
3Fedoraproject
Libuser ProjectRedhat
3Enterprise Linux
FedoraLibuser
Nov 21, 2024
Nov 25, 2019
N/A· v4
6.3 MEDIUM· v3
3.3 LOW· v2
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
3Debian
QuaggaRedhat
3Debian Linux
Enterprise LinuxQuagga
Nov 21, 2024
Nov 25, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
4Canonical
Ibus ProjectOracle+1 more
4Enterprise Linux
IbusUbuntu Linux+1 more
Jun 17, 2026
Nov 25, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attac...Show more
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.Show less
3Linux
NetappRedhat
18Altavault
Baseboard Management ControllerCodeready Linux Builder Eus+15 more
Jun 17, 2026
Nov 25, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
5Buildah Project
Libpod ProjectOpensuse+2 more
6Buildah
Enterprise LinuxLeap+3 more
Jun 17, 2026
Nov 25, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container regi...Show more
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.Show less
2Python
Redhat
3Enterprise Linux
Enterprise Virtualization HypervisorPyxml
Nov 21, 2024
Nov 22, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
PyXML: Hash table collisions CPU usage Denial of Service