← Back

Linux

linux

Vendor: Redhat • 229 CVEs

CVEs (229)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Linux
Redhat
3Fedora Core
LinuxLinux Kernel
Apr 16, 2026
Dec 15, 2004
N/A· v4
N/A· v3
2.1 LOW· v2
Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function.
2Linux
Redhat
3Fedora Core
LinuxLinux Kernel
Apr 16, 2026
Dec 15, 2004
N/A· v4
N/A· v3
2.1 LOW· v2
Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow.
1Redhat
3Fedora Core
KernelLinux
Apr 16, 2026
Dec 6, 2004
N/A· v4
N/A· v3
7.2 HIGH· v2
Integer overflow in the ubsec_keysetup function for Linux Broadcom 5820 cryptonet driver allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a negative add_dsa_buf_bytes variab...Show more
Integer overflow in the ubsec_keysetup function for Linux Broadcom 5820 cryptonet driver allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a negative add_dsa_buf_bytes variable, which leads to a buffer overflow.Show less
244d
AppleAvaya+21 more
65Aaa Server
Access RegistrarApache Based Web Server+62 more
Apr 16, 2026
Nov 23, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a de...Show more
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.Show less
234d
AppleAvaya+20 more
66Aaa Server
Access RegistrarApache Based Web Server+63 more
Apr 16, 2026
Nov 23, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
234d
AppleAvaya+20 more
66Aaa Server
Access RegistrarApache Based Web Server+63 more
Apr 16, 2026
Nov 23, 2004
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
3Mozilla
RedhatSgi
7Enterprise Linux
Enterprise Linux DesktopFedora Core+4 more
Apr 16, 2026
Oct 18, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a nu...Show more
Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.Show less
5Conectiva
MozillaNetscape+2 more
10Enterprise Linux
Enterprise Linux DesktopFedora Core+7 more
Apr 16, 2026
Sep 14, 2004
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and...Show more
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.Show less
1Redhat
2Linux
Tcpdump
Apr 16, 2026
Feb 17, 2004
N/A· v4
N/A· v3
7.5 HIGH· v2
tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.
1Redhat
1Linux
Apr 16, 2026
Aug 27, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose source addresses are the same as the target.
1Redhat
1Linux
Apr 16, 2026
Aug 27, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could allow attackers to cause a denial of service.
1Redhat
1Linux
Apr 16, 2026
Aug 27, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which allows attackers to modify the bridge topology.
1Redhat
1Linux
Apr 16, 2026
Aug 27, 2003
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd.
1Redhat
1Linux
Apr 16, 2026
Aug 27, 2003
N/A· v4
N/A· v3
2.1 LOW· v2
/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.
2Php
Redhat
2Linux
Php
Apr 16, 2026
Jul 24, 2003
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.
4Adobe
MandrakesoftRedhat+1 more
7Acrobat
Enterprise LinuxLinux+4 more
Apr 16, 2026
Jul 24, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
4Apple
KdeRedhat+1 more
6Kde
Konqueror EmbeddedLinux+3 more
Apr 16, 2026
Jun 16, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
1Redhat
1Linux
Apr 16, 2026
Jun 16, 2003
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a denial of service (CPU consumption) via certain packets that cause a large number of hash table collisions.
1Redhat
1Linux
Apr 16, 2026
Jun 16, 2003
N/A· v4
N/A· v3
7.5 HIGH· v2
Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.
1Redhat
1Linux
Apr 16, 2026
Jun 16, 2003
N/A· v4
N/A· v3
10.0 HIGH· v2
The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.