Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Red Hat Enterprise Linux Number Of NVD 1680 CRITICAL 135 HIGH 590 MEDIUM 803 LOW 151
URL https://www.redhat.com/technologies/linux-platforms/enterprise-linux
Explanation Full support is 5.5 years from release.
Maintenance support (security updates only) is for 3.5 years.
After that, extended support is available for a fee.
Tag
  • Linux
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://access.redhat.com/ja/articles/16476
2 https://access.redhat.com/support/policy/updates/errata
3 https://access.redhat.com/articles/3078
4 https://access.redhat.com/security
5 https://access.redhat.com/errata/#/?q=&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
771 Red Hat Enterprise Linux 9 9.7 Nov. 11, 2025 May 17, 2022 4 127 172 17
772 Red Hat Enterprise Linux 8 8.10 May 22, 2024 May 7, 2019 May 30, 2029 43 314 444 50
773 Red Hat Enterprise Linux 7 7.9 Sept. 29, 2020 Dec. 11, 2013 Aug. 6, 2020 June 30, 2024 91 270 270 46
774 Red Hat Enterprise Linux 6 6.10 June 19, 2018 Nov. 9, 2010 May 10, 2022 Nov. 30, 2020 June 30, 2024 72 169 210 55
775 Red Hat Enterprise Linux 5 5.11 Sept. 16, 2014 March 15, 2007 March 31, 2017 Nov. 30, 2020 24 59 89 40
776 Red Hat Enterprise Linux 4 4.5 Feb. 29, 2012 March 31, 2017 5 30 29 16
777 Red Hat Enterprise Linux 3 3.0 0 33 44 17
778 Red Hat Enterprise Linux 2 2.1 Update 7 April 28, 2005 0 32 37 6
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
771 6.5
3.5
MEDIUM
Network
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to vie… CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2019-14824 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 13:27
2019-11-9
Show GitHub Exploit DB Packet Storm
772 5.5
4.9
MEDIUM
Local
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering s… CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2019-18811 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 13:33
2019-11-8
Show GitHub Exploit DB Packet Storm
773 9.8
7.5
CRITICAL
Network
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very l… CWE-190
 Integer Overflow or Wraparound
CVE-2019-18805 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 13:33
2019-11-7
Show GitHub Exploit DB Packet Storm
774 6.1
4.3
MEDIUM
Network
Pagure: XSS possible in file attachment endpoint CWE-79
Cross-site Scripting
CVE-2016-1000037 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 11:42
2019-11-7
Show GitHub Exploit DB Packet Storm
775 5.5
2.1
MEDIUM
Local
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace. CWE-665
 Improper Initialization
CVE-2014-8181 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 11:18
2019-11-7
Show GitHub Exploit DB Packet Storm
776 3.3
2.1
LOW
Local
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files. CWE-732
 Incorrect Permission Assignment for Critical Resource
CVE-2016-4983 cpe:2.3:o:redhat:enterprise_linux:7.0:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*
cpe:2.3:o:redhat:enterprise_linux…
2024-11-21 11:53
2019-11-6
Show GitHub Exploit DB Packet Storm
777 5.9
2.6
MEDIUM
Network
Cache Poisoning issue exists in DNS Response Rate Limiting. CWE-290
 Authentication Bypass by Spoofing
CVE-2013-5661 cpe:2.3:o:redhat:enterprise_linux:7.0:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*
2024-11-21 10:57
2019-11-6
Show GitHub Exploit DB Packet Storm
778 2.4
2.1
LOW
Physics
gdm3 3.14.2 and possibly later has an information leak before screen lock CWE-200
Information Exposure
CVE-2016-1000002 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 11:42
2019-11-5
Show GitHub Exploit DB Packet Storm
779 7.8
6.8
HIGH
Local
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitr… CWE-190
 Integer Overflow or Wraparound
CVE-2017-5333 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 12:27
2019-11-5
Show GitHub Exploit DB Packet Storm
780 7.8
6.8
HIGH
Local
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2017-5332 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 12:27
2019-11-5
Show GitHub Exploit DB Packet Storm