Redhat

Enterprise Linux Desktop

1928 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 7.58%
  • Published 25.01.2008 01:00:00
  • Last modified 09.04.2025 00:30:58

CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject...

  • EPSS 0.14%
  • Published 18.12.2007 01:46:00
  • Last modified 09.04.2025 00:30:58

Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.

  • EPSS 0.08%
  • Published 04.12.2007 00:46:00
  • Last modified 09.04.2025 00:30:58

The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might ...

  • EPSS 1.53%
  • Published 03.12.2007 20:46:00
  • Last modified 09.04.2025 00:30:58

Perl-Compatible Regular Expression (PCRE) library before 6.7 does not properly calculate the compiled memory allocation for regular expressions that involve a quantified "subpattern containing a named recursion or subroutine reference," which allows ...

  • EPSS 0.08%
  • Published 15.07.2007 22:30:00
  • Last modified 09.04.2025 00:30:58

The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file.

  • EPSS 11.55%
  • Published 27.06.2007 17:30:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML vi...

  • EPSS 0.04%
  • Published 26.06.2007 18:30:00
  • Last modified 09.04.2025 00:30:58

The Linux kernel before 2.6.9-42.0.8 in Red Hat 4.4 allows local users to cause a denial of service (kernel OOPS from null dereference) via fput in a 32-bit ioctl on 64-bit x86 systems, an incomplete fix of CVE-2005-3044.1.

Exploit
  • EPSS 0.21%
  • Published 20.06.2007 22:30:00
  • Last modified 09.04.2025 00:30:58

Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the m...

  • EPSS 7.49%
  • Published 06.04.2007 01:19:00
  • Last modified 09.04.2025 00:30:58

Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflo...

  • EPSS 1.32%
  • Published 06.04.2007 01:19:00
  • Last modified 09.04.2025 00:30:58

Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.