Redhat

Enterprise Linux

1709 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 35.02%
  • Published 10.10.2006 04:06:00
  • Last modified 09.04.2025 00:30:58

The clip_mkip function in net/atm/clip.c of the ATM subsystem in Linux kernel allows remote attackers to cause a denial of service (panic) via unknown vectors that cause the ATM subsystem to access the memory of socket buffers after they are freed (f...

  • EPSS 3.51%
  • Published 10.10.2006 04:06:00
  • Last modified 09.04.2025 00:30:58

pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the...

  • EPSS 0.1%
  • Published 11.08.2006 21:04:00
  • Last modified 03.04.2025 01:03:51

A regression error in the Perl package for Red Hat Enterprise Linux 4 omits the patch for CVE-2005-0155, which allows local users to overwrite arbitrary files with debugging information.

  • EPSS 0.08%
  • Published 27.07.2006 22:04:00
  • Last modified 03.04.2025 01:03:51

kdesktop_lock in kdebase before 3.1.3-5.11 for KDE in Red Hat Enterprise Linux (RHEL) 3 does not properly terminate, which can prevent the screensaver from activating or prevent users from manually locking the desktop.

  • EPSS 2.06%
  • Published 31.12.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probabl...

Exploit
  • EPSS 7.36%
  • Published 31.12.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to int...

Exploit
  • EPSS 11.29%
  • Published 31.12.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and ...

Exploit
  • EPSS 9.33%
  • Published 31.12.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.

  • EPSS 0.03%
  • Published 31.12.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with sudo permissions for /sbin/service to gain root privileges via unknown vectors.

  • EPSS 0.05%
  • Published 22.12.2005 11:03:00
  • Last modified 03.04.2025 01:03:51

udev does not properly set permissions on certain files in /dev/input, which allows local users to obtain sensitive data that is entered at the console, such as user passwords.