Redhat

Enterprise Linux

1730 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.02%
  • Veröffentlicht 09.05.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Graphics class. Successful exploitation could lead to arbitrary code execution.

  • EPSS 0.28%
  • Veröffentlicht 21.04.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.

  • EPSS 0.45%
  • Veröffentlicht 21.04.2017 15:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Session fixation vulnerability in pcsd in pcs before 0.9.157.

  • EPSS 94.01%
  • Veröffentlicht 17.04.2017 21:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

  • EPSS 1.54%
  • Veröffentlicht 12.04.2017 20:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.

  • EPSS 0.11%
  • Veröffentlicht 03.03.2017 11:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection...

  • EPSS 0.13%
  • Veröffentlicht 13.02.2017 18:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

  • EPSS 1.4%
  • Veröffentlicht 13.02.2017 18:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.

  • EPSS 0.07%
  • Veröffentlicht 22.12.2016 21:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted ...

  • EPSS 0.8%
  • Veröffentlicht 22.12.2016 21:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or potentially execute arbitrary code.