Redhat

Enterprise Linux Server Aus

1054 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.06%
  • Veröffentlicht 20.11.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections...

  • EPSS 69.1%
  • Veröffentlicht 13.11.2017 22:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL ser...

  • EPSS 0.06%
  • Veröffentlicht 06.11.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$host...

Exploit
  • EPSS 4.97%
  • Veröffentlicht 04.11.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: T...

  • EPSS 2.76%
  • Veröffentlicht 26.10.2017 03:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.

  • EPSS 0.29%
  • Veröffentlicht 24.10.2017 01:29:02
  • Zuletzt bearbeitet 20.04.2025 01:37:25

When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially r...

  • EPSS 0.36%
  • Veröffentlicht 19.10.2017 17:29:05
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.11 and earlier. Easily exploitable vulnerability allows low privile...

  • EPSS 0.25%
  • Veröffentlicht 19.10.2017 17:29:05
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable vulnerability allows low privilege...

  • EPSS 0.47%
  • Veröffentlicht 19.10.2017 17:29:05
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.57 and earlier 5.6.37 and earlier 5.7.19 and earlier. Easily exploitable vulnerability allows low privileged attacke...

  • EPSS 0.54%
  • Veröffentlicht 19.10.2017 17:29:05
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unau...