Redhat

Enterprise Linux Server Aus

1054 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.25%
  • Veröffentlicht 22.06.2017 21:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.

  • EPSS 9.44%
  • Veröffentlicht 20.06.2017 01:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.

  • EPSS 65.46%
  • Veröffentlicht 20.06.2017 01:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacke...

  • EPSS 7.81%
  • Veröffentlicht 19.06.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made t...

Exploit
  • EPSS 4.03%
  • Veröffentlicht 06.06.2017 21:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.

  • EPSS 48.7%
  • Veröffentlicht 06.06.2017 21:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.

Exploit
  • EPSS 38.97%
  • Veröffentlicht 29.05.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.

Warnung Exploit
  • EPSS 92.68%
  • Veröffentlicht 27.04.2017 01:59:02
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in ...

  • EPSS 0.89%
  • Veröffentlicht 24.04.2017 19:59:06
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Difficult to exploit vulnerability allows high privi...

  • EPSS 0.73%
  • Veröffentlicht 24.04.2017 19:59:04
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121. Difficult to exploit vulnerability allows unauthen...