Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Red Hat Enterprise Linux Number Of NVD 1680 CRITICAL 135 HIGH 590 MEDIUM 803 LOW 151
URL https://www.redhat.com/technologies/linux-platforms/enterprise-linux
Explanation Full support is 5.5 years from release.
Maintenance support (security updates only) is for 3.5 years.
After that, extended support is available for a fee.
Tag
  • Linux
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://access.redhat.com/ja/articles/16476
2 https://access.redhat.com/support/policy/updates/errata
3 https://access.redhat.com/articles/3078
4 https://access.redhat.com/security
5 https://access.redhat.com/errata/#/?q=&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
1211 Red Hat Enterprise Linux 9 9.7 Nov. 11, 2025 May 17, 2022 4 127 172 17
1212 Red Hat Enterprise Linux 8 8.10 May 22, 2024 May 7, 2019 May 30, 2029 43 314 444 50
1213 Red Hat Enterprise Linux 7 7.9 Sept. 29, 2020 Dec. 11, 2013 Aug. 6, 2020 June 30, 2024 91 270 270 46
1214 Red Hat Enterprise Linux 6 6.10 June 19, 2018 Nov. 9, 2010 May 10, 2022 Nov. 30, 2020 June 30, 2024 72 169 210 55
1215 Red Hat Enterprise Linux 5 5.11 Sept. 16, 2014 March 15, 2007 March 31, 2017 Nov. 30, 2020 24 59 89 40
1216 Red Hat Enterprise Linux 4 4.5 Feb. 29, 2012 March 31, 2017 5 30 29 16
1217 Red Hat Enterprise Linux 3 3.0 0 33 44 17
1218 Red Hat Enterprise Linux 2 2.1 Update 7 April 28, 2005 0 32 37 6
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
1211 6.5
4.0
MEDIUM
Network
It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security re… CWE-20
 Improper Input Validation 
CVE-2017-12197 cpe:2.3:o:redhat:enterprise_linux:6.0:* 2024-11-21 12:09
2018-01-19
Show GitHub Exploit DB Packet Storm
1212 5.5
4.9
MEDIUM
Local
A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.12. A lack of size check could cause a denial of service (BUG). CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2017-15128 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 12:14
2018-01-14
Show GitHub Exploit DB Packet Storm
1213 5.5
4.9
MEDIUM
Local
A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13. A superfluous implicit page unlock for VM_SHARED hugetlbfs mapping could trigger a local den… - CVE-2017-15127 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 12:14
2018-01-14
Show GitHub Exploit DB Packet Storm
1214 7.8
4.6
HIGH
Local
It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This is… NVD-CWE-noinfo
CVE-2017-12189 cpe:2.3:o:redhat:enterprise_linux:7.0:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*
2024-11-21 12:09
2018-01-11
Show GitHub Exploit DB Packet Storm
1215 7.8
4.6
HIGH
Local
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs bef… - CVE-2017-15131 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 12:14
2018-01-10
Show GitHub Exploit DB Packet Storm
1216 4.7
4.9
MEDIUM
Local
A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::… CWE-362
Race Condition
CVE-2017-15129 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 12:14
2018-01-10
Show GitHub Exploit DB Packet Storm
1217 5.5
2.1
MEDIUM
Local
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink at… CWE-59
Link Following
CVE-2014-1859 cpe:2.3:o:redhat:enterprise_linux:7.0:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*
2024-11-21 11:05
2018-01-9
Show GitHub Exploit DB Packet Storm
1218 7.5
5.0
HIGH
Network
The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions. CWE-20
 Improper Input Validation 
CVE-2014-8119 cpe:2.3:o:redhat:enterprise_linux:7.0:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*
2024-11-21 11:18
2017-12-30
Show GitHub Exploit DB Packet Storm
1219 5.5
2.1
MEDIUM
Local
The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leveraging failure to disab… CWE-74
Injection
CVE-2016-3695 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 11:50
2017-12-30
Show GitHub Exploit DB Packet Storm
1220 7.8
2.1
HIGH
Local
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi… - CVE-2017-15104 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 12:14
2017-12-19
Show GitHub Exploit DB Packet Storm