Redhat

Enterprise Linux

1709 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.43%
  • Veröffentlicht 21.04.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.

  • EPSS 0.45%
  • Veröffentlicht 21.04.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Session fixation vulnerability in pcsd in pcs before 0.9.157.

  • EPSS 94.01%
  • Veröffentlicht 17.04.2017 21:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

  • EPSS 1.54%
  • Veröffentlicht 12.04.2017 20:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.

  • EPSS 0.11%
  • Veröffentlicht 03.03.2017 11:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection...

  • EPSS 0.13%
  • Veröffentlicht 13.02.2017 18:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

  • EPSS 1.11%
  • Veröffentlicht 13.02.2017 18:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.

  • EPSS 0.07%
  • Veröffentlicht 22.12.2016 21:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted ...

  • EPSS 0.8%
  • Veröffentlicht 22.12.2016 21:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or potentially execute arbitrary code.

Warnung Exploit
  • EPSS 94.25%
  • Veröffentlicht 10.11.2016 21:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in Oc...