Skip to main content

Vendor/product archive

redhat / enterprise_linux CVEs

Beta · best-effort

2,185 CVEs tagged to redhat / enterprise_linux201 Critical, 705 High, 1,086 Medium, 193 Low, 0 Unrated.

CVE-2024-0564

Published Jan 30, 2024

A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can creat…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0841

Published Jan 28, 2024

A null pointer dereference flaw was found in the hugetlbfs_fill_super function in the Linux kernel hugetlbfs (HugeTLB pages) functionality. This issue may allow a local user to cr…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6291

Published Jan 26, 2024

A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access t…

CVSS 7.1 · High

CVE-2023-52355

Published Jan 25, 2024

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to caus…

CVSS 7.5 · High
evidence mentions
12
Buzz score
41.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2023-40547

Published Jan 25, 2024

A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to cra…

CVSS 8.3 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2024-0775

Published Jan 22, 2024

A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an information leak problem while free…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0646

Published Jan 17, 2024

An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destinati…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0639

Published Jan 17, 2024

A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux kernel’s SCTP subsystem. This flaw allows guests with loca…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2023-6915

Published Jan 15, 2024

A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attacker using this library to cause a denial of service problem…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6683

Published Jan 12, 2024

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() wa…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 2,185 CVEsPage 12 of 88