Redhat

Enterprise Linux Eus

778 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.8%
  • Published 27.08.2008 20:41:00
  • Last modified 09.04.2025 00:30:58

libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.

  • EPSS 0.09%
  • Published 08.08.2008 19:41:00
  • Last modified 09.04.2025 00:30:58

QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different for...

  • EPSS 0.06%
  • Published 08.08.2008 18:41:00
  • Last modified 09.04.2025 00:30:58

The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain da...

  • EPSS 9.7%
  • Published 13.06.2008 18:41:00
  • Last modified 09.04.2025 00:30:58

The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service...

  • EPSS 0.08%
  • Published 04.12.2007 00:46:00
  • Last modified 09.04.2025 00:30:58

The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might ...

  • EPSS 11.55%
  • Published 27.06.2007 17:30:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML vi...

  • EPSS 17.13%
  • Published 30.03.2007 00:19:00
  • Last modified 09.04.2025 00:30:58

PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted U...

  • EPSS 3.26%
  • Published 05.10.2006 04:04:00
  • Last modified 09.04.2025 00:30:58

The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (process crash) and deny access to NFS exports via unspecified vectors that trigger a kernel oops (null dereference...