<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Red Hat Enterprise Linux (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/rhel.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/rhel-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Red Hat Enterprise Linux (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:51 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2023-53629 – In the Linux kernel, the following vulnerability has been resolved:

fs: dlm: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53629</guid>
    <pubDate>Tue, 07 Oct 2025 16:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-53629</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  fs: dlm: fix use after free in midcomms commit  While working on processing dlm message in softirq context I experienced the following KASAN use-after-free warning:  [  151.760477] ================================================================== [  151.761803] BUG: KASAN: use-after-free in dlm_midcomms_commit_mhandle+0x19d/0x4…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-50401 – In the Linux kernel, the following vulnerability has been resolved:

nfsd: under...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50401</guid>
    <pubDate>Thu, 18 Sep 2025 16:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-50401</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  nfsd: under NFSv4.1, fix double svc_xprt_put on rpc_create failure  On error situation `clp->cl_cb_conn.cb_xprt` should not be given a reference to the xprt otherwise both client cleanup and the error handling path of the caller call to put it. Better to delay handing over the reference to a later branch.  [   72.530665] refcoun…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-53082 – In the Linux kernel, the following vulnerability has been resolved:

vp_vdpa: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53082</guid>
    <pubDate>Fri, 02 May 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-53082</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  vp_vdpa: fix the crash in hot unplug with vp_vdpa  While unplugging the vp_vdpa device, it triggers a kernel panic The root cause is: vdpa_mgmtdev_unregister() will accesses modern devices which will cause a use after free. So need to change the sequence in vp_vdpa_remove  [  195.003359] BUG: unable to handle page fault for addr…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-56658 – In the Linux kernel, the following vulnerability has been resolved:

net: defer ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56658</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56658</guid>
    <pubDate>Fri, 27 Dec 2024 15:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-56658</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: defer final 'struct net' free in netns dismantle  Ilya reported a slab-use-after-free in dst_destroy [1]  Issue is in xfrm6_net_init() and xfrm4_net_init() :  They copy xfrm[46]_dst_ops_template into net->xfrm.xfrm[46]_dst_ops.  But net structure might be freed before all the dst callbacks are called. So when dst_destroy()…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56658">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-6238 – pgAdmin &lt;= 8.8 has an installation Directory permission issue. Because of this i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6238</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6238</guid>
    <pubDate>Tue, 25 Jun 2024 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-6238</strong></p>
  <p>pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation directory on the Debian or RHEL 8 platforms.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6238">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4438 – The etcd package distributed with the Red Hat OpenStack platform has an incomple...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4438</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4438</guid>
    <pubDate>Wed, 08 May 2024 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4438</strong></p>
  <p>The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2023-39325/CVE-2023-44487, known as Rapid Reset. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4438">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4437 – The etcd package distributed with the Red Hat OpenStack platform has an incomple...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4437</guid>
    <pubDate>Wed, 08 May 2024 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4437</strong></p>
  <p>The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2021-44716. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4436 – The etcd package distributed with the Red Hat OpenStack platform has an incomple...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4436</guid>
    <pubDate>Wed, 08 May 2024 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4436</strong></p>
  <p>The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2022-41723. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2680 – This CVE exists because of an incomplete fix for CVE-2021-3750. More specificall...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2680</guid>
    <pubDate>Wed, 13 Sep 2023 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2680</strong></p>
  <p>This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 via RHSA-2022:7967 included a version of qemu-kvm that was actually missing the fix for CVE-2021-3750.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-2319 – It was discovered that an update for PCS package in RHBA-2023:2151 erratum relea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2319</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2319</guid>
    <pubDate>Wed, 17 May 2023 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-2319</strong></p>
  <p>It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591. The CVE-2023-2319 was assigned to that Red Hat specific security regression in Red Hat Enterprise Linu…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2319">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2295 – A vulnerability was found in the libreswan library. This security issue occurs w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2295</guid>
    <pubDate>Wed, 17 May 2023 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2295</strong></p>
  <p>A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote c…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2491 – A flaw was found in the Emacs text editor. Processing a specially crafted org-mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2491</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2491</guid>
    <pubDate>Wed, 17 May 2023 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2491</strong></p>
  <p>A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2491">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2203 – A flaw was found in the WebKitGTK package. An improper input validation issue ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2203</guid>
    <pubDate>Wed, 17 May 2023 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2203</strong></p>
  <p>A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Re…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30549 – Apptainer is an open source container platform for Linux. There is an ext4 use-a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30549</guid>
    <pubDate>Tue, 25 Apr 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30549</strong></p>
  <p>Apptainer is an open source container platform for Linux. There is an ext4 use-after-free flaw that is exploitable through versions of Apptainer < 1.1.0 and installations that include apptainer-suid < 1.1.8 on older operating systems where that CVE has not been patched. That includes Red Hat Enterprise Linux 7, Debian 10 buster (unless the linux-5.10 package is installed), Ubuntu 18.04 bionic and…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-41352 – An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41352</guid>
    <pubDate>Mon, 26 Sep 2022 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-41352</strong></p>
  <p>An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red H…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-2738 – The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2738</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2738</guid>
    <pubDate>Thu, 01 Sep 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-2738</strong></p>
  <p>The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixed via RHSA-2020:2117. This issue could possibly be used to crash or cause potential code execution in Go applications that use the Go GPGME wrapper library, under certain conditions, during GPG signa…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2738">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-28623 – Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28623</guid>
    <pubDate>Fri, 08 Jul 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-28623</strong></p>
  <p>Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL and HPE IceWall SSO version 10.0 certd library Patch 9 for HP-UX.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-1665 – A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Powe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-1665</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-1665</guid>
    <pubDate>Tue, 21 Jun 2022 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-1665</strong></p>
  <p>A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdown patches applied to it and can bypass the secure boot validations, allowing the attacker to load another non-trusted code.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-1291</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1665">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-20325 – Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20325</guid>
    <pubDate>Fri, 18 Feb 2022 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-20325</strong></p>
  <p>Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-20…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43816 – containerd is an open source container runtime. On installations using SELinux, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43816</guid>
    <pubDate>Wed, 05 Jan 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43816</strong></p>
  <p>containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged, regular file on disk for complete read/write access (sans delete). Such is achieved b…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-10772 – An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterpri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10772</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10772</guid>
    <pubDate>Fri, 27 Nov 2020 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-10772</strong></p>
  <p>An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower amplification ratio compared to versions of Unbound that shipped before the mentioned erratum. This issue is about the incomplete fi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-406</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10772">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-4125 – Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4125</guid>
    <pubDate>Mon, 20 Jul 2020 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-4125</strong></p>
  <p>Using HCL Marketing Operations 9.1.2.4, 10.1.x, 11.1.0.x, a malicious attacker could download files from the RHEL environment by doing some modification in the link, giving the attacker access to confidential information.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-494</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14300 – The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14300</guid>
    <pubDate>Mon, 13 Jul 2020 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14300</strong></p>
  <p>The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the fixes regressed in that update was the fix for CVE-2016-9962, that was previously corrected in the docker packages in Re…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-273</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14298 – The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14298</guid>
    <pubDate>Mon, 13 Jul 2020 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14298</strong></p>
  <p>The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malicious or compromised container to compromise the container host and other containers running on the same host. This issue only affects docker version…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-273</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-3278 – frysk packages through 2008-08-05 as shipped in Red Hat Enterprise Linux 5 are b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3278</guid>
    <pubDate>Thu, 07 Nov 2019 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-3278</strong></p>
  <p>frysk packages through 2008-08-05 as shipped in Red Hat Enterprise Linux 5 are built with an insecure RPATH set in the ELF header of multiple binaries in /usr/bin/f* (e.g. fcore, fcatch, fstack, fstep, ...) shipped in the package. A local attacker can exploit this vulnerability by running arbitrary code as another user.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-10171 – It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10171</guid>
    <pubDate>Fri, 02 Aug 2019 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-10171</strong></p>
  <p>It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-16863 – It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16863</guid>
    <pubDate>Mon, 03 Dec 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-16863</strong></p>
  <p>It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat Enterprise Linux 7.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-184</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-8989 – A security vulnerability in HPE IceWall SSO Dfw 10.0 and 11.0 on RHEL, HP-UX, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8989</guid>
    <pubDate>Mon, 06 Aug 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-8989</strong></p>
  <p>A security vulnerability in HPE IceWall SSO Dfw 10.0 and 11.0 on RHEL, HP-UX, and Windows could be exploited remotely to allow URL Redirection.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-8657 – It was discovered that EAP packages in certain versions of Red Hat Enterprise Li...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-8657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-8657</guid>
    <pubDate>Tue, 31 Jul 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-8657</strong></p>
  <p>It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /etc/init.d init scripts (i.e. on Red Hat Enterprise Linux 6 and earlier), the file is sourced by the jboss init script and its content executed with root privil…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-8657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1132 – A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inj...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1132</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1132</guid>
    <pubDate>Wed, 20 Jun 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1132</strong></p>
  <p>A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inject the component's database (SQLite) without authenticating to the controller or SDNInterfaceapp. SDNInterface has been deprecated in OpenDayLight since it was last used in the final Carbon series release. In addition to the component not being included in OpenDayLight in newer releases, the SDNInterface component is…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1132">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1125 – procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1125</guid>
    <pubDate>Wed, 23 May 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1125</strong></p>
  <p>procps-ng before version 3.3.15 is vulnerable to a stack buffer overflow in pgrep. This vulnerability is mitigated by FORTIFY, as it involves strncat() to a stack-allocated string. When pgrep is compiled with FORTIFY (as on Red Hat Enterprise Linux and Fedora), the impact is limited to a crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1111 – DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1111</guid>
    <pubDate>Thu, 17 May 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1111</strong></p>
  <p>DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-2628 – curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-2628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-2628</guid>
    <pubDate>Mon, 12 Mar 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-2628</strong></p>
  <p>curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by USE_HTTP_NEGOTIATE. This issue was introduced in RHEL 6.7 and affects RHEL 6 curl only.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-2628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-15131 – It was found that system umask policy is not being honored when creating XDG use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15131</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15131</guid>
    <pubDate>Tue, 09 Jan 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-15131</strong></p>
  <p>It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15131">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-15087 – It was discovered that the fix for CVE-2017-12163 was not properly shipped in er...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15087</guid>
    <pubDate>Wed, 08 Nov 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-15087</strong></p>
  <p>It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-15086 – It was discovered that the fix for CVE-2017-12151 was not properly shipped in er...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15086</guid>
    <pubDate>Wed, 08 Nov 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-15086</strong></p>
  <p>It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-300</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-7050 – SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7050</guid>
    <pubDate>Thu, 08 Jun 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-7050</strong></p>
  <p>SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5416 – 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat En...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5416</guid>
    <pubDate>Thu, 08 Jun 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5416</strong></p>
  <p>389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to read the default Access Control Instructions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5416">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-5405 – 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat En...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5405</guid>
    <pubDate>Thu, 08 Jun 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-5405</strong></p>
  <p>389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-199</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-4992 – 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat En...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4992</guid>
    <pubDate>Thu, 08 Jun 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-4992</strong></p>
  <p>389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to infer the existence of RDN component objects.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-3099 – mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3099</guid>
    <pubDate>Thu, 08 Jun 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-3099</strong></p>
  <p>mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the use of ciphers that were not intended to be enabled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-6325 – The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6325</guid>
    <pubDate>Thu, 13 Oct 2016 14:59:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-6325</strong></p>
  <p>The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5425 – The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5425</guid>
    <pubDate>Thu, 13 Oct 2016 14:59:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5425</strong></p>
  <p>The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-3699 – The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3699</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3699</guid>
    <pubDate>Fri, 07 Oct 2016 14:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-3699</strong></p>
  <p>The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the initrd.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3699">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-5408 – Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5408</guid>
    <pubDate>Wed, 10 Aug 2016 14:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-5408</strong></p>
  <p>Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linux 6 allows remote attackers to execute arbitrary code via unspecified vectors.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-4051.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-4474 – The image build process for the overcloud images in Red Hat OpenStack Platform 8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-4474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-4474</guid>
    <pubDate>Thu, 30 Jun 2016 16:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-4474</strong></p>
  <p>The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) director (aka overcloud-full) use a default root password of ROOTPW, which allows attackers to gain access via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-4474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-3707 – The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3707</guid>
    <pubDate>Mon, 27 Jun 2016 10:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-3707</strong></p>
  <p>The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before 3.10.0-327.22.1 in Red Hat Enterprise Linux for Real Time 7 and other products, allows remote attackers to execute SysRq commands via crafted ICMP Echo Request packets, as demonstrated by a brute-force attack to discover a cookie, or an attack that o…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5329 – The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterpri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5329</guid>
    <pubDate>Mon, 11 Apr 2016 21:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5329</strong></p>
  <p>The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured RabbitMQ credentials, which makes it easier for remote attackers to obtain access to services in deployed overclouds by leveraging knowledge of the default credentials.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5229 – The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5229</guid>
    <pubDate>Fri, 08 Apr 2016 15:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5229</strong></p>
  <p>The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-17</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-3632 – The default configuration in a sudoers file in the Red Hat openstack-neutron pac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3632</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3632</guid>
    <pubDate>Tue, 07 Oct 2014 14:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-3632</strong></p>
  <p>The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stack Platform 5.0 for Red Hat Enterprise Linux 6, allows remote attackers to gain privileges via a crafted configuration file.  NOTE: this vulnerability exists because of a CVE-2013-6433 regression.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3632">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-7283 – Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7283</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7283</guid>
    <pubDate>Thu, 09 Jan 2014 18:07:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-7283</strong></p>
  <p>Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact and attack vectors, involving the /var/tmp/libreswan-nss-pwd temporary file.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7283">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2231 – Unquoted Windows search path vulnerability in the QEMU Guest Agent service for R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2231</guid>
    <pubDate>Tue, 01 Oct 2013 17:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2231</strong></p>
  <p>Unquoted Windows search path vulnerability in the QEMU Guest Agent service for Red Hat Enterprise Linux Desktop 6, HPC Node 6, Server 6, Workstation 6, Desktop Supplementary 6, Server Supplementary 6, Supplementary AUS 6.4, Supplementary EUS 6.4.z, and Workstation Supplementary 6, when installing on Windows, allows local users to gain privileges via a crafted program in an unspecified folder.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-2482 – A certain Red Hat patch to the sctp_sock_migrate function in net/sctp/socket.c i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2482</guid>
    <pubDate>Sat, 08 Jun 2013 13:05:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-2482</strong></p>
  <p>A certain Red Hat patch to the sctp_sock_migrate function in net/sctp/socket.c in the Linux kernel before 2.6.21, as used in Red Hat Enterprise Linux (RHEL) 5, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) via a crafted SCTP packet.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-4272 – A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red H...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-4272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-4272</guid>
    <pubDate>Wed, 27 Jan 2010 17:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-4272</strong></p>
  <p>A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (deadlock) via crafted packets that force collisions in the IPv4 routing hash table, and trigger a routing "emergency" in which a hash chain is too long.  NOTE: this is related to an issue in the Linux kernel before 2.6.31, when the kern…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-4272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-2695 – The Linux kernel before 2.6.31-rc7 does not properly prevent mmap operations tha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2695</guid>
    <pubDate>Fri, 28 Aug 2009 15:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-2695</strong></p>
  <p>The Linux kernel before 2.6.31-rc7 does not properly prevent mmap operations that target page zero and other low memory addresses, which allows local users to gain privileges by exploiting NULL pointer dereference vulnerabilities, related to (1) the default configuration of the allow_unconfined_mmap_low boolean in SELinux on Red Hat Enterprise Linux (RHEL) 5, (2) an error that causes allow_unconf…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-6560 – Buffer overflow in CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9 and R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-6560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-6560</guid>
    <pubDate>Tue, 31 Mar 2009 14:09:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-6560</strong></p>
  <p>Buffer overflow in CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9 and Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (CPU consumption and memory corruption) via a cluster.conf file with many lines.  NOTE: it is not clear whether this issue crosses privilege boundaries in realistic uses of the product.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-6560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-4310 – httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise L...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4310</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4310</guid>
    <pubDate>Tue, 09 Dec 2008 00:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-4310</strong></p>
  <p>httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CPU consumption) via a crafted HTTP request.  NOTE: this issue exists because of an incomplete fix for CVE-2008-3656.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4310">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-3844 – Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3844</guid>
    <pubDate>Wed, 27 Aug 2008 20:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-3844</strong></p>
  <p>Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externally introduced modification (Trojan Horse) that allows the package authors to have an unknown impact.  NOTE: since the malicious packages were not distributed from any official Red Hat sources, the scope of this issue is restricted to users who may h…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1376 – A certain Red Hat build script for nfs-utils before 1.0.9-35z.el5_2 on Red Hat E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1376</guid>
    <pubDate>Fri, 01 Aug 2008 14:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1376</strong></p>
  <p>A certain Red Hat build script for nfs-utils before 1.0.9-35z.el5_2 on Red Hat Enterprise Linux (RHEL) 5 omits TCP wrappers support, which might allow remote attackers to bypass intended access restrictions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-2375 – Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat En...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-2375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-2375</guid>
    <pubDate>Wed, 09 Jul 2008 00:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-2375</strong></p>
  <p>Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat Enterprise Linux (RHEL) 3 and 4, when PAM is used, allows remote attackers to cause a denial of service (memory consumption) via a large number of invalid authentication attempts within the same session, a different vulnerability than CVE-2007-5962.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-2375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-5962 – Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5962</guid>
    <pubDate>Thu, 22 May 2008 13:09:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-5962</strong></p>
  <p>Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a large number of CWD commands, as demonstrated by an attack on a daemon with the deny_file configuration option.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-1198 – The default IPSec ifup script in Red Hat Enterprise Linux 3 through 5 configures...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1198</guid>
    <pubDate>Thu, 06 Mar 2008 21:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-1198</strong></p>
  <p>The default IPSec ifup script in Red Hat Enterprise Linux 3 through 5 configures racoon to use aggressive IKE mode instead of main IKE mode, which makes it easier for remote attackers to conduct brute force attacks by sniffing an unencrypted preshared key (PSK) hash.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-4130 – The Linux kernel 2.6.9 before 2.6.9-67 in Red Hat Enterprise Linux (RHEL) 4 on I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-4130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-4130</guid>
    <pubDate>Tue, 05 Feb 2008 00:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-4130</strong></p>
  <p>The Linux kernel 2.6.9 before 2.6.9-67 in Red Hat Enterprise Linux (RHEL) 4 on Itanium (ia64) does not properly handle page faults during NUMA memory access, which allows local users to cause a denial of service (panic) via invalid arguments to set_mempolicy in an MPOL_BIND operation.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-4130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-7175 – The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-7175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-7175</guid>
    <pubDate>Tue, 27 Mar 2007 23:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-7175</strong></p>
  <p>The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-7175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2007-0980 – Unspecified vulnerability in HP Serviceguard for Linux; packaged for SuSE SLES8 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-0980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-0980</guid>
    <pubDate>Fri, 16 Feb 2007 01:28:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2007-0980</strong></p>
  <p>Unspecified vulnerability in HP Serviceguard for Linux; packaged for SuSE SLES8 and United Linux 1.0 before SG A.11.15.07, SuSE SLES9 and SLES10 before SG A.11.16.10, and Red Hat Enterprise Linux (RHEL) before SG A.11.16.10; allows remote attackers to obtain unauthorized access via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-0980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-5170 – pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5170</guid>
    <pubDate>Tue, 10 Oct 2006 04:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-5170</strong></p>
  <p>pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-3629 – initscripts in Red Hat Enterprise Linux 4 does not properly handle certain envir...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-3629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-3629</guid>
    <pubDate>Sat, 31 Dec 2005 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-3629</strong></p>
  <p>initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with sudo permissions for /sbin/service to gain root privileges via unknown vectors.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-3629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-0403 – init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-0403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-0403</guid>
    <pubDate>Thu, 01 Sep 2005 22:03:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-0403</strong></p>
  <p>init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 does not properly clear controlling tty's in multi-threaded applications, which allows local users to cause a denial of service (crash) and possibly gain tty access via unknown attack vectors that trigger an access of a pointer to a freed structure.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-0403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-0086 – Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-0086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-0086</guid>
    <pubDate>Mon, 02 May 2005 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-0086</strong></p>
  <p>Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file, as demonstrated using the UTF-8 locale.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-0086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-0091 – Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split pat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-0091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-0091</guid>
    <pubDate>Mon, 02 May 2005 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-0091</strong></p>
  <p>Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when using the hugemem kernel, allows local users to read and write to arbitrary kernel memory and gain privileges via certain syscalls.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-0091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2003-0084 – mod_auth_any package in Red Hat Enterprise Linux 2.1 and other operating systems...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2003-0084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2003-0084</guid>
    <pubDate>Mon, 12 May 2003 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2003-0084</strong></p>
  <p>mod_auth_any package in Red Hat Enterprise Linux 2.1 and other operating systems does not properly escape arguments when calling other programs, which allows attackers to execute arbitrary commands via shell metacharacters.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2003-0084">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
