Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Red Hat Enterprise Linux Number Of NVD 1680 CRITICAL 135 HIGH 590 MEDIUM 803 LOW 151
URL https://www.redhat.com/technologies/linux-platforms/enterprise-linux
Explanation Full support is 5.5 years from release.
Maintenance support (security updates only) is for 3.5 years.
After that, extended support is available for a fee.
Tag
  • Linux
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://access.redhat.com/ja/articles/16476
2 https://access.redhat.com/support/policy/updates/errata
3 https://access.redhat.com/articles/3078
4 https://access.redhat.com/security
5 https://access.redhat.com/errata/#/?q=&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
1511 Red Hat Enterprise Linux 9 9.7 Nov. 11, 2025 May 17, 2022 4 127 172 17
1512 Red Hat Enterprise Linux 8 8.10 May 22, 2024 May 7, 2019 May 30, 2029 43 314 444 50
1513 Red Hat Enterprise Linux 7 7.9 Sept. 29, 2020 Dec. 11, 2013 Aug. 6, 2020 June 30, 2024 91 270 270 46
1514 Red Hat Enterprise Linux 6 6.10 June 19, 2018 Nov. 9, 2010 May 10, 2022 Nov. 30, 2020 June 30, 2024 72 169 210 55
1515 Red Hat Enterprise Linux 5 5.11 Sept. 16, 2014 March 15, 2007 March 31, 2017 Nov. 30, 2020 24 59 89 40
1516 Red Hat Enterprise Linux 4 4.5 Feb. 29, 2012 March 31, 2017 5 30 29 16
1517 Red Hat Enterprise Linux 3 3.0 0 33 44 17
1518 Red Hat Enterprise Linux 2 2.1 Update 7 April 28, 2005 0 32 37 6
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
1511 7.5
5.0
HIGH
Network
Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application… CWE-22
Path Traversal
CVE-2010-0013 cpe:2.3:o:redhat:enterprise_linux:5.0:*
cpe:2.3:o:redhat:enterprise_linux:4.0:*
2026-04-23 09:35
2010-01-10
Show GitHub Exploit DB Packet Storm
1512 7.5
5.0
HIGH
Network
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote at… CWE-416
 Use After Free
CVE-2009-3553 cpe:2.3:o:redhat:enterprise_linux:5.0:* 2026-04-23 09:35
2009-11-20
Show GitHub Exploit DB Packet Storm
1513 6.5
4.3
MEDIUM
Network
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) vi… CWE-416
 Use After Free
CVE-2009-2416 cpe:2.3:o:redhat:enterprise_linux:5.0:*
cpe:2.3:o:redhat:enterprise_linux:4.0:*
cpe:2.3:o:redhat:enterprise_linux…
2026-04-23 09:35
2009-08-12
Show GitHub Exploit DB Packet Storm
1514 -
6.9
MEDIUM The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrary files via a symlink attack on an unspecified tem… CWE-59
Link Following
CVE-2009-1893 cpe:2.3:o:redhat:enterprise_linux:3.0:*
cpe:2.3:o:redhat:enterprise_linux:3.0:*
cpe:2.3:o:redhat:enterprise_linux…
2026-04-23 09:35
2009-07-18
Show GitHub Exploit DB Packet Storm
1515 7.5
9.3
HIGH
Network
Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary cod… CWE-362
CWE-416
Race Condition
 Use After Free
CVE-2009-1837 cpe:2.3:o:redhat:enterprise_linux:5.0:*
cpe:2.3:o:redhat:enterprise_linux:4.0:*
2026-04-23 09:35
2009-06-13
Show GitHub Exploit DB Packet Storm
1516 -
10.0
HIGH The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of servic… CWE-824
 Access of Uninitialized Pointer
CVE-2009-0846 cpe:2.3:o:redhat:enterprise_linux:4.0:* 2026-04-23 09:35
2009-04-9
Show GitHub Exploit DB Packet Storm
1517 -
5.0
MEDIUM The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows… CWE-863
 Incorrect Authorization
CVE-2008-6123 cpe:2.3:o:redhat:enterprise_linux:3.0:* 2026-04-23 09:35
2009-02-13
Show GitHub Exploit DB Packet Storm
1518 -
6.8
MEDIUM tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed authentication attempts to the OpenPegasus CIM server, which makes it easier f… NVD-CWE-Other
CVE-2008-4315 cpe:2.3:o:redhat:enterprise_linux:5.0:* 2026-04-23 09:35
2008-11-27
Show GitHub Exploit DB Packet Storm
1519 -
6.0
MEDIUM A certain Red Hat patch for tog-pegasus in OpenGroup Pegasus 2.7.0 does not properly configure the PAM tty name, which allows remote authenticated users to bypass intended access restrictions and sen… CWE-264
Permissions, Privileges, and Access Controls
CVE-2008-4313 cpe:2.3:o:redhat:enterprise_linux:5.0:* 2026-04-23 09:35
2008-11-27
Show GitHub Exploit DB Packet Storm
1520 -
4.4
MEDIUM pam_krb5 2.2.14 in Red Hat Enterprise Linux (RHEL) 5 and earlier, when the existing_ticket option is enabled, uses incorrect privileges when reading a Kerberos credential cache, which allows local us… CWE-264
Permissions, Privileges, and Access Controls
CVE-2008-3825 cpe:2.3:o:redhat:enterprise_linux:5:unknown 2026-04-23 09:35
2008-10-4
Show GitHub Exploit DB Packet Storm