Redhat

Enterprise Linux

1709 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Published 07.02.2024 21:15:08
  • Last modified 21.11.2024 08:44:03

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages when using NVMe over TCP, leading the NVMe driver to a NULL pointer dereference in the NVMe driver, caus...

  • EPSS 0.01%
  • Published 06.02.2024 18:15:59
  • Last modified 21.11.2024 08:49:40

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the...

  • EPSS 0.06%
  • Published 06.02.2024 12:15:55
  • Last modified 17.01.2025 20:15:27

An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this iss...

  • EPSS 0.71%
  • Published 05.02.2024 21:15:11
  • Last modified 21.11.2024 08:37:18

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

  • EPSS 0.31%
  • Published 05.02.2024 21:15:10
  • Last modified 21.11.2024 08:37:18

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

Exploit
  • EPSS 0.18%
  • Published 05.02.2024 15:15:08
  • Last modified 21.11.2024 08:45:32

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside...

  • EPSS 0.07%
  • Published 04.02.2024 14:15:47
  • Last modified 21.11.2024 08:43:26

A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.

Exploit
  • EPSS 0.21%
  • Published 31.01.2024 14:15:48
  • Last modified 21.11.2024 08:42:56

A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.

  • EPSS 0.23%
  • Published 31.01.2024 05:15:08
  • Last modified 21.11.2024 08:47:42

A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signing, even without access to the ...

Exploit
  • EPSS 0.02%
  • Published 30.01.2024 15:15:08
  • Last modified 25.11.2024 09:15:05

A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the same host ...