Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Red Hat Enterprise Linux Number Of NVD 1680 CRITICAL 135 HIGH 590 MEDIUM 803 LOW 151
URL https://www.redhat.com/technologies/linux-platforms/enterprise-linux
Explanation Full support is 5.5 years from release.
Maintenance support (security updates only) is for 3.5 years.
After that, extended support is available for a fee.
Tag
  • Linux
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://access.redhat.com/ja/articles/16476
2 https://access.redhat.com/support/policy/updates/errata
3 https://access.redhat.com/articles/3078
4 https://access.redhat.com/security
5 https://access.redhat.com/errata/#/?q=&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
841 Red Hat Enterprise Linux 9 9.7 Nov. 11, 2025 May 17, 2022 4 127 172 17
842 Red Hat Enterprise Linux 8 8.10 May 22, 2024 May 7, 2019 May 30, 2029 43 314 444 50
843 Red Hat Enterprise Linux 7 7.9 Sept. 29, 2020 Dec. 11, 2013 Aug. 6, 2020 June 30, 2024 91 270 270 46
844 Red Hat Enterprise Linux 6 6.10 June 19, 2018 Nov. 9, 2010 May 10, 2022 Nov. 30, 2020 June 30, 2024 72 169 210 55
845 Red Hat Enterprise Linux 5 5.11 Sept. 16, 2014 March 15, 2007 March 31, 2017 Nov. 30, 2020 24 59 89 40
846 Red Hat Enterprise Linux 4 4.5 Feb. 29, 2012 March 31, 2017 5 30 29 16
847 Red Hat Enterprise Linux 3 3.0 0 33 44 17
848 Red Hat Enterprise Linux 2 2.1 Update 7 April 28, 2005 0 32 37 6
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
841 9.8
7.5
CRITICAL
Network
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A… CWE-863
 Incorrect Authorization
CVE-2019-14813 cpe:2.3:o:redhat:enterprise_linux:8.0:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*
2024-11-21 13:27
2019-09-6
Show GitHub Exploit DB Packet Storm
842 4.4
3.6
MEDIUM
Local
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access… NVD-CWE-noinfo
CVE-2019-15718 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 13:29
2019-09-4
Show GitHub Exploit DB Packet Storm
843 4.7
4.7
MEDIUM
Local
In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c when SAS expander discovery fails. This will cause a BUG and denial of service. CWE-401
 Missing Release of Memory after Effective Lifetime
CVE-2019-15807 cpe:2.3:o:redhat:enterprise_linux:8.0:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*
2024-11-21 13:29
2019-08-30
Show GitHub Exploit DB Packet Storm
844 5.5
4.9
MEDIUM
Local
A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local access can create a denial of service situation via NULL pointer dereference in o… - CVE-2019-10140 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 13:18
2019-08-16
Show GitHub Exploit DB Packet Storm
845 8.1
4.8
HIGH
Adjacent
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This al… CWE-327
 Use of a Broken or Risky Cryptographic Algorithm
CVE-2019-9506 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 13:51
2019-08-15
Show GitHub Exploit DB Packet Storm
846 7.5
7.8
HIGH
Network
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-s… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2019-9518 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 13:51
2019-08-14
Show GitHub Exploit DB Packet Storm
847 7.5
7.8
HIGH
Network
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without const… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2019-9517 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 13:51
2019-08-14
Show GitHub Exploit DB Packet Storm
848 6.5
6.8
MEDIUM
Network
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, … CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2019-9516 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 13:51
2019-08-14
Show GitHub Exploit DB Packet Storm
849 7.5
7.8
HIGH
Network
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2019-9515 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 13:51
2019-08-14
Show GitHub Exploit DB Packet Storm
850 7.5
7.8
HIGH
Network
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that shou… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2019-9514 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 13:51
2019-08-14
Show GitHub Exploit DB Packet Storm