Redhat

Enterprise Linux

1730 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 30.11.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference).

  • EPSS 0.11%
  • Veröffentlicht 15.11.2017 21:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occur...

  • EPSS 0.06%
  • Veröffentlicht 05.10.2017 01:29:04
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_...

Warnung
  • EPSS 54.19%
  • Veröffentlicht 05.10.2017 01:29:04
  • Zuletzt bearbeitet 22.10.2025 00:16:00

Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4f...

  • EPSS 0.07%
  • Veröffentlicht 19.09.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secur...

  • EPSS 0.04%
  • Veröffentlicht 14.09.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2, when the nfnetlink_log module is loaded, allows local users to cause a denial of service (panic) by creating netlink sockets.

  • EPSS 30%
  • Veröffentlicht 19.08.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel q...

Exploit
  • EPSS 0.82%
  • Veröffentlicht 11.08.2017 19:29:02
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.

Exploit
  • EPSS 53.25%
  • Veröffentlicht 11.08.2017 19:29:02
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution.

  • EPSS 0.11%
  • Veröffentlicht 10.08.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of service (crash) via a crafted catalog size in (1) the parallels_open function in block/parallels.c or (2) bochs_open function in bo...