Redhat

Enterprise Linux

1952 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 14.08%
  • Veröffentlicht 09.06.2015 18:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or p...

Exploit
  • EPSS 38.43%
  • Veröffentlicht 09.06.2015 18:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted length value in a (1) tar, (2) ph...

Exploit
  • EPSS 7.7%
  • Veröffentlicht 09.06.2015 18:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (heap metadata corruption) or possibly have unspecified other impact via a craf...

Exploit
  • EPSS 10.88%
  • Veröffentlicht 09.06.2015 18:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read and application crash) via a crafted length v...

  • EPSS 15.28%
  • Veröffentlicht 13.05.2015 18:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_...

Exploit
  • EPSS 7.91%
  • Veröffentlicht 13.04.2015 14:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.

  • EPSS 4.16%
  • Veröffentlicht 25.02.2015 11:59:11
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a d...

Exploit
  • EPSS 87.64%
  • Veröffentlicht 24.02.2015 01:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execu...

  • EPSS 14.45%
  • Veröffentlicht 26.01.2015 15:59:09
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image.

  • EPSS 16.86%
  • Veröffentlicht 26.01.2015 15:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overf...