Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Red Hat Enterprise Linux Number Of NVD 1681 CRITICAL 136 HIGH 590 MEDIUM 803 LOW 151
URL https://www.redhat.com/technologies/linux-platforms/enterprise-linux
Explanation Full support is 5.5 years from release.
Maintenance support (security updates only) is for 3.5 years.
After that, extended support is available for a fee.
Tag
  • 商用ライセンス有り
  • Linux

Add Information URL
No Type Name URL
1 https://access.redhat.com/ja/articles/16476
2 https://access.redhat.com/support/policy/updates/errata
3 https://access.redhat.com/articles/3078
4 https://access.redhat.com/security
5 https://access.redhat.com/errata/#/?q=&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
971 Red Hat Enterprise Linux 9 9.7 Nov. 11, 2025 May 17, 2022 5 127 172 17
972 Red Hat Enterprise Linux 8 8.10 May 22, 2024 May 7, 2019 May 30, 2029 44 314 444 50
973 Red Hat Enterprise Linux 7 7.9 Sept. 29, 2020 Dec. 11, 2013 Aug. 6, 2020 June 30, 2024 92 270 270 46
974 Red Hat Enterprise Linux 6 6.10 June 19, 2018 Nov. 9, 2010 May 10, 2022 Nov. 30, 2020 June 30, 2024 73 169 210 55
975 Red Hat Enterprise Linux 5 5.11 Sept. 16, 2014 March 15, 2007 March 31, 2017 Nov. 30, 2020 24 59 89 40
976 Red Hat Enterprise Linux 4 4.5 Feb. 29, 2012 March 31, 2017 5 30 29 16
977 Red Hat Enterprise Linux 3 3.0 0 33 44 17
978 Red Hat Enterprise Linux 2 2.1 Update 7 April 28, 2005 0 32 37 6
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
971 4.9
4.0
MEDIUM
Network
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged … NVD-CWE-noinfo
CVE-2019-2580 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 13:41
2019-04-24
Show GitHub Exploit DB Packet Storm
972 5.5
4.3
MEDIUM
Local
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to u… CWE-754
CWE-908
 Improper Check for Unusual or Exceptional Conditions
 Use of Uninitialized Resource
CVE-2019-11459 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 13:21
2019-04-23
Show GitHub Exploit DB Packet Storm
973 5.9
5.8
MEDIUM
Network
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository. CWE-59
Link Following
CVE-2019-3902 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 13:42
2019-04-23
Show GitHub Exploit DB Packet Storm
974 9.8
7.5
CRITICAL
Network
FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497. CWE-287
Improper Authentication
CVE-2019-11234 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 13:20
2019-04-22
Show GitHub Exploit DB Packet Storm
975 9.8
7.5
CRITICAL
Network
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection… CWE-345
 Insufficient Verification of Data Authenticity
CVE-2019-11235 cpe:2.3:o:redhat:enterprise_linux:7.0:* 2024-11-21 13:20
2019-04-22
Show GitHub Exploit DB Packet Storm
976 7.5
5.0
HIGH
Network
In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detec… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2019-10245 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 13:18
2019-04-19
Show GitHub Exploit DB Packet Storm
977 5.5
2.1
MEDIUM
Local
A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS CWE-400
 Uncontrolled Resource Consumption
CVE-2018-16878 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 12:53
2019-04-19
Show GitHub Exploit DB Packet Storm
978 7.8
4.6
HIGH
Local
A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknes… NVD-CWE-noinfo
CVE-2018-16877 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 12:53
2019-04-19
Show GitHub Exploit DB Packet Storm
979 7.5
5.0
HIGH
Network
In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un… CWE-772
 Missing Release of Resource after Effective Lifetime
CVE-2019-3883 cpe:2.3:o:redhat:enterprise_linux:6.0:* 2024-11-21 13:42
2019-04-17
Show GitHub Exploit DB Packet Storm
980 6.5
3.3
MEDIUM
Adjacent
A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1. CWE-20
 Improper Input Validation 
CVE-2019-3460 cpe:2.3:o:redhat:enterprise_linux:8.0:* 2024-11-21 13:42
2019-04-12
Show GitHub Exploit DB Packet Storm