Redhat

Enterprise Linux Server Eus

622 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.4%
  • Published 05.10.2017 01:29:04
  • Last modified 20.04.2025 01:37:25

Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.

Exploit
  • EPSS 4.19%
  • Published 12.09.2017 17:29:00
  • Last modified 20.04.2025 01:37:25

The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remot...

Exploit
  • EPSS 79.83%
  • Published 05.09.2017 06:29:00
  • Last modified 20.04.2025 01:37:25

backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option su...

Exploit
  • EPSS 9.67%
  • Published 31.08.2017 20:29:00
  • Last modified 20.04.2025 01:37:25

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.

Exploit
  • EPSS 12.22%
  • Published 31.08.2017 20:29:00
  • Last modified 20.04.2025 01:37:25

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.

Exploit
  • EPSS 18.56%
  • Published 31.08.2017 20:29:00
  • Last modified 20.04.2025 01:37:25

RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.

Exploit
  • EPSS 4.54%
  • Published 31.08.2017 20:29:00
  • Last modified 20.04.2025 01:37:25

RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.

Exploit
  • EPSS 1.99%
  • Published 31.08.2017 17:29:00
  • Last modified 20.04.2025 01:37:25

Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/generator.c, which will stop after encountering a '\0' byte, returning...

  • EPSS 1.65%
  • Published 22.08.2017 18:29:00
  • Last modified 20.04.2025 01:37:25

Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of executi...

  • EPSS 27.64%
  • Published 19.08.2017 18:29:00
  • Last modified 20.04.2025 01:37:25

Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel q...