Redhat

Enterprise Linux

1952 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 03.10.2013 21:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new A...

  • EPSS 0.4%
  • Veröffentlicht 03.10.2013 21:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2)...

  • EPSS 0.38%
  • Veröffentlicht 03.10.2013 21:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race co...

  • EPSS 0.37%
  • Veröffentlicht 03.10.2013 21:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

RealtimeKit (aka rtkit) 0.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process...

  • EPSS 0.45%
  • Veröffentlicht 01.10.2013 17:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Unquoted Windows search path vulnerability in the QEMU Guest Agent service for Red Hat Enterprise Linux Desktop 6, HPC Node 6, Server 6, Workstation 6, Desktop Supplementary 6, Server Supplementary 6, Supplementary AUS 6.4, Supplementary EUS 6.4.z, a...

  • EPSS 2.68%
  • Veröffentlicht 30.09.2013 21:55:09
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.2.8, 1.0.x before 1.0.5.6, and 1.1.x before 1.1.2 allows remote authenticated users to cause a denial of service (uninitialized po...

  • EPSS 0.56%
  • Veröffentlicht 23.09.2013 20:55:07
  • Zuletzt bearbeitet 29.04.2026 01:13:23

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

  • EPSS 4.31%
  • Veröffentlicht 16.09.2013 13:02:34
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity...

  • EPSS 2.61%
  • Veröffentlicht 19.08.2013 23:55:08
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly execute arbitrary code via vectors involving 3d graphics that trigger an out-of-bounds array access,...

  • EPSS 3.59%
  • Veröffentlicht 18.08.2013 02:52:23
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-...