Redhat

Enterprise Linux

1952 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.36%
  • Veröffentlicht 06.11.2019 15:15:10
  • Zuletzt bearbeitet 21.11.2024 02:18:43

The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.

Exploit
  • EPSS 0.4%
  • Veröffentlicht 05.11.2019 22:15:10
  • Zuletzt bearbeitet 21.11.2024 02:53:21

A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.

  • EPSS 3.45%
  • Veröffentlicht 05.11.2019 19:15:10
  • Zuletzt bearbeitet 21.11.2024 01:57:54

Cache Poisoning issue exists in DNS Response Rate Limiting.

Exploit
  • EPSS 0.53%
  • Veröffentlicht 05.11.2019 14:15:13
  • Zuletzt bearbeitet 21.11.2024 02:42:49

gdm3 3.14.2 and possibly later has an information leak before screen lock

  • EPSS 3.62%
  • Veröffentlicht 04.11.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 01:55:30

An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.

Exploit
  • EPSS 6.71%
  • Veröffentlicht 04.11.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 02:39:35

The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.

  • EPSS 2.11%
  • Veröffentlicht 04.11.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 03:27:24

The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.

  • EPSS 2.22%
  • Veröffentlicht 04.11.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 03:27:24

Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.

  • EPSS 0.43%
  • Veröffentlicht 04.11.2019 20:15:09
  • Zuletzt bearbeitet 21.11.2024 01:55:13

The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.

Exploit
  • EPSS 0.63%
  • Veröffentlicht 04.11.2019 19:15:10
  • Zuletzt bearbeitet 21.11.2024 00:05:25

There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by...