Redhat

Enterprise Linux Server Aus

1059 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.41%
  • Veröffentlicht 05.06.2012 22:55:10
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted EXIF IFD in a TIFF image.

  • EPSS 0.29%
  • Veröffentlicht 05.06.2012 22:55:07
  • Zuletzt bearbeitet 29.04.2026 01:13:23

ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.

  • EPSS 4.21%
  • Veröffentlicht 05.06.2012 22:55:06
  • Zuletzt bearbeitet 29.04.2026 01:13:23

ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.

Warnung Exploit
  • EPSS 94.36%
  • Veröffentlicht 11.05.2012 10:15:48
  • Zuletzt bearbeitet 21.04.2026 20:28:53

sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by ...

  • EPSS 4.46%
  • Veröffentlicht 22.03.2012 16:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly exe...

Exploit
  • EPSS 1.04%
  • Veröffentlicht 18.01.2012 20:55:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memor...

  • EPSS 3.83%
  • Veröffentlicht 06.09.2011 19:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man...

  • EPSS 0.06%
  • Veröffentlicht 06.09.2011 16:55:07
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The is_gpt_valid function in fs/partitions/efi.c in the Linux kernel before 2.6.39 does not check the size of an Extensible Firmware Interface (EFI) GUID Partition Table (GPT) entry, which allows physically proximate attackers to cause a denial of se...

  • EPSS 0.11%
  • Veröffentlicht 10.04.2011 02:51:19
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vector...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 15.03.2011 17:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Race condition in the cm_work_handler function in the InfiniBand driver (drivers/infiniband/core/cma.c) in Linux kernel 2.6.x allows remote attackers to cause a denial of service (panic) by sending an InfiniBand request while other request handlers a...