Vulnerabilities > Redhat > Enterprise Linux > High

DATE CVE VULNERABILITY TITLE RISK
2024-10-29 CVE-2024-50074 Out-of-bounds Read vulnerability in multiple products
In the Linux kernel, the following vulnerability has been resolved: parport: Proper fix for array out-of-bounds access The recent fix for array out-of-bounds accesses replaced sprintf() calls blindly with snprintf().
local
low complexity
linux redhat CWE-125
7.8
2024-08-19 CVE-2024-44070 An issue was discovered in FRRouting (FRR) through 10.1.
network
low complexity
frrouting redhat
7.5
2024-08-12 CVE-2024-7006 NULL Pointer Dereference vulnerability in multiple products
A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`.
network
low complexity
libtiff redhat CWE-476
7.5
2024-08-02 CVE-2024-3056 Resource Exhaustion vulnerability in multiple products
A flaw was found in Podman.
network
high complexity
podman-project redhat fedoraproject CWE-400
7.7
2024-07-01 CVE-2024-6387 Race Condition vulnerability in multiple products
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd).
8.1
2024-06-21 CVE-2024-6239 A flaw was found in the Poppler's Pdfinfo utility.
network
low complexity
freedesktop redhat
7.5
2024-06-12 CVE-2024-3183 Use of Password Hash With Insufficient Computational Effort vulnerability in Redhat products
A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key.
network
low complexity
redhat CWE-916
8.1
2024-02-14 CVE-2023-50387 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue.
7.5
2024-02-09 CVE-2024-0229 Out-of-bounds Write vulnerability in multiple products
An out-of-bounds memory access flaw was found in the X.Org server.
local
low complexity
x-org fedoraproject redhat CWE-787
7.8
2024-02-07 CVE-2023-6356 NULL Pointer Dereference vulnerability in multiple products
A flaw was found in the Linux kernel's NVMe driver.
network
low complexity
redhat linux debian CWE-476
7.5