Redhat

Enterprise Linux

1709 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.42%
  • Veröffentlicht 25.03.2021 19:15:15
  • Zuletzt bearbeitet 21.11.2024 06:21:36

A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this v...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 25.03.2021 19:15:14
  • Zuletzt bearbeitet 21.11.2024 06:21:32

A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when open...

  • EPSS 0.04%
  • Veröffentlicht 25.03.2021 19:15:14
  • Zuletzt bearbeitet 21.11.2024 06:21:32

A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were used. Instead of returning th...

  • EPSS 0.04%
  • Veröffentlicht 23.03.2021 21:15:14
  • Zuletzt bearbeitet 21.11.2024 06:21:26

The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest ...

  • EPSS 0.12%
  • Veröffentlicht 23.03.2021 17:15:13
  • Zuletzt bearbeitet 21.11.2024 05:46:15

An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.

  • EPSS 0.36%
  • Veröffentlicht 19.03.2021 20:15:13
  • Zuletzt bearbeitet 21.11.2024 04:18:37

A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available ...

  • EPSS 0%
  • Veröffentlicht 18.03.2021 20:15:13
  • Zuletzt bearbeitet 21.11.2024 06:21:27

A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use th...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 18.03.2021 19:15:12
  • Zuletzt bearbeitet 21.11.2024 04:27:29

A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to th...

  • EPSS 0.42%
  • Veröffentlicht 18.03.2021 17:15:13
  • Zuletzt bearbeitet 21.11.2024 05:21:53

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerabilit...

  • EPSS 0.39%
  • Veröffentlicht 15.03.2021 18:15:17
  • Zuletzt bearbeitet 21.11.2024 05:46:17

A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service.