CVE-2008-0884
- EPSS 0.04%
- Veröffentlicht 04.04.2008 00:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Replace function in the capp-lspp-config script in the (1) lspp-eal4-config-ibm and (2) capp-lspp-eal4-config-hp packages before 0.65-2 in Red Hat Enterprise Linux (RHEL) 5 uses lstat instead of stat to determine the /etc/pam.d/system-auth file p...
CVE-2008-1198
- EPSS 0.43%
- Veröffentlicht 06.03.2008 21:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The default IPSec ifup script in Red Hat Enterprise Linux 3 through 5 configures racoon to use aggressive IKE mode instead of main IKE mode, which makes it easier for remote attackers to conduct brute force attacks by sniffing an unencrypted preshare...
CVE-2008-0595
- EPSS 0.05%
- Veröffentlicht 29.02.2008 19:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a m...
CVE-2007-4130
- EPSS 0.05%
- Veröffentlicht 05.02.2008 00:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Linux kernel 2.6.9 before 2.6.9-67 in Red Hat Enterprise Linux (RHEL) 4 on Itanium (ia64) does not properly handle page faults during NUMA memory access, which allows local users to cause a denial of service (panic) via invalid arguments to set_m...
CVE-2007-6285
- EPSS 0.14%
- Veröffentlicht 20.12.2007 22:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 4 and 5, does not specify the nodev mount option for the -hosts map, which allows local users to access "important devices" by opera...
CVE-2007-6283
- EPSS 0.14%
- Veröffentlicht 18.12.2007 01:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.
CVE-2007-5964
- EPSS 0.13%
- Veröffentlicht 13.12.2007 18:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/net filesystem) map, which allows local users to gain privileges via a setuid program on a remote NF...
CVE-2006-7226
- EPSS 1.53%
- Veröffentlicht 03.12.2007 20:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Perl-Compatible Regular Expression (PCRE) library before 6.7 does not properly calculate the compiled memory allocation for regular expressions that involve a quantified "subpattern containing a named recursion or subroutine reference," which allows ...
CVE-2007-5494
- EPSS 0.04%
- Veröffentlicht 30.11.2007 02:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Memory leak in the Red Hat Content Accelerator kernel patch in Red Hat Enterprise Linux (RHEL) 4 and 5 allows local users to cause a denial of service (memory consumption) via a large number of open requests involving O_ATOMICLOOKUP.
CVE-2007-5116
- EPSS 11.41%
- Veröffentlicht 07.11.2007 23:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicode (UTF) characters in a regular expression.