Red Hat / Enterprise Linux for IBM Z Systems
113 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-5992 | Opensc: side-channel leaks while stripping encryption pkcs#1 padding | MEDIUM | 5.9 | Jan 31, 2024 |
| CVE-2024-1086 KEV | Use-after-free in Linux kernel's netfilter: nf_tables component | HIGH | 7.8 | Jan 31, 2024 |
| CVE-2024-0409 | Xorg-x11-server: selinux context corruption | HIGH | 7.8 | Jan 18, 2024 |
| CVE-2024-0408 | Xorg-x11-server: selinux unlabeled glx pbuffer | MEDIUM | 5.5 | Jan 18, 2024 |
| CVE-2023-5455 | Ipa: invalid csrf protection | MEDIUM | 6.5 | Jan 10, 2024 |
| CVE-2024-0193 | Kernel: netfilter: use-after-free in nft_trans_gc_catchall_sync leads to privilege escalation | HIGH | 7.8 | Jan 2, 2024 |
| CVE-2023-4641 | Shadow-utils: possible password leak during passwd(1) change | MEDIUM | 5.5 | Dec 27, 2023 |
| CVE-2023-5870 | Postgresql: role pg_signal_backend can signal certain superuser processes. | MEDIUM | 4.4 | Dec 10, 2023 |
| CVE-2023-5868 | Postgresql: memory disclosure in aggregate function calls | MEDIUM | 4.3 | Dec 10, 2023 |
| CVE-2023-5869 | Postgresql: buffer overrun from integer overflow in array modification | HIGH | 8.8 | Dec 10, 2023 |
| CVE-2023-42669 | Samba: "rpcecho" development server allows denial of service via sleep() call on ad dc | MEDIUM | 6.5 | Nov 6, 2023 |
| CVE-2023-46847 | Squid: denial of service in http digest authentication | HIGH | 8.6 | Nov 3, 2023 |
| CVE-2023-46846 | Squid: request/response smuggling in http/1.1 and icap | CRITICAL | 9.3 | Nov 3, 2023 |
| CVE-2023-3972 | Insights-client: unsafe handling of temporary files and directories | HIGH | 7.8 | Nov 1, 2023 |
| CVE-2023-5367 | Xorg-x11-server: out-of-bounds write in xichangedeviceproperty/rrchangeoutputproperty | HIGH | 7.8 | Oct 25, 2023 |
| CVE-2023-5633 | Kernel: vmwgfx: reference count issue leads to use-after-free in surface handling | HIGH | 7.8 | Oct 23, 2023 |
| CVE-2023-4911 KEV | Glibc: buffer overflow in ld.so leading to privilege escalation | HIGH | 7.8 | Oct 3, 2023 |
| CVE-2023-4732 | Kernel: race between task migrating pages and another task calling exit_mmap to release those same pages getting invalid opcode bug in include/linux/swapops.h | MEDIUM | 4.7 | Oct 3, 2023 |
| CVE-2023-5157 | Mariadb: node crashes with transport endpoint is not connected mysqld got signal 6 | HIGH | 7.5 | Sep 26, 2023 |
| CVE-2023-4806 | Glibc: potential use-after-free in getaddrinfo() | MEDIUM | 5.9 | Sep 18, 2023 |
| CVE-2023-4527 | Glibc: stack read overflow in getaddrinfo in no-aaaa mode | MEDIUM | 6.5 | Sep 18, 2023 |
| CVE-2023-38201 | Keylime: challenge-response protocol bypass during agent registration | HIGH | 8.7 | Aug 25, 2023 |
| CVE-2023-4042 | Ghostscript: incomplete fix for cve-2020-16305 | MEDIUM | 5.5 | Aug 23, 2023 |
| CVE-2023-3899 | Subscription-manager: inadequate authorization of com.redhat.rhsm1 d-bus interface allows local users to modify configuration | HIGH | 7.8 | Aug 23, 2023 |
| CVE-2023-38200 | Keylime: registrar is subject to a dos against ssl connections | HIGH | 7.5 | Jul 24, 2023 |
Showing 26 to 50 of 113 CVEs