Redhat

Enterprise Linux Hpc Node

146 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 69.06%
  • Veröffentlicht 19.07.2016 02:00:20
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, wh...

  • EPSS 0.06%
  • Veröffentlicht 27.06.2016 10:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a craft...

  • EPSS 0.2%
  • Veröffentlicht 27.06.2016 10:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.

  • EPSS 0.77%
  • Veröffentlicht 13.06.2016 19:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity d...

  • EPSS 0.05%
  • Veröffentlicht 07.06.2016 14:06:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.

  • EPSS 0.13%
  • Veröffentlicht 07.06.2016 14:06:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter...

Exploit
  • EPSS 9.11%
  • Veröffentlicht 16.05.2016 10:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote attackers to cause a denial of ...

Exploit
  • EPSS 9.11%
  • Veröffentlicht 16.05.2016 10:59:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a den...

Exploit
  • EPSS 8.13%
  • Veröffentlicht 16.05.2016 10:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related to a "type confusion" issue.

Exploit
  • EPSS 12.86%
  • Veröffentlicht 16.05.2016 10:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a...