Redhat

Enterprise Linux

1903 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3.82%
  • Veröffentlicht 31.12.2005 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:17:16

Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and ...

Exploit
  • EPSS 3.38%
  • Veröffentlicht 31.12.2005 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:17:17

Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.

  • EPSS 0.39%
  • Veröffentlicht 31.12.2005 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:17:17

initscripts in Red Hat Enterprise Linux 4 does not properly handle certain environment variables when /sbin/service is executed, which allows local users with sudo permissions for /sbin/service to gain root privileges via unknown vectors.

  • EPSS 0.39%
  • Veröffentlicht 22.12.2005 11:03:00
  • Zuletzt bearbeitet 16.06.2026 22:17:18

udev does not properly set permissions on certain files in /dev/input, which allows local users to obtain sensitive data that is entered at the console, such as user passwords.

  • EPSS 0.39%
  • Veröffentlicht 25.10.2005 17:06:00
  • Zuletzt bearbeitet 16.06.2026 22:14:15

The rw_vm function in usercopy.c in the 4GB split patch for the Linux kernel in Red Hat Enterprise Linux 4 does not perform proper bounds checking, which allows local users to cause a denial of service (crash).

  • EPSS 0.45%
  • Veröffentlicht 14.09.2005 19:03:00
  • Zuletzt bearbeitet 16.06.2026 22:15:00

The raw_sendmsg function in the Linux kernel 2.6 before 2.6.13.1 allows local users to cause a denial of service (change hardware state) or read from arbitrary memory via crafted input.

  • EPSS 0.4%
  • Veröffentlicht 01.09.2005 22:03:00
  • Zuletzt bearbeitet 16.06.2026 22:11:02

init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 does not properly clear controlling tty's in multi-threaded applications, which allows local users to cause a denial of service (crash) and possibly gain tty access vi...

  • EPSS 1.97%
  • Veröffentlicht 13.06.2005 04:00:00
  • Zuletzt bearbeitet 16.06.2026 22:13:38

sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges.

  • EPSS 0.38%
  • Veröffentlicht 18.05.2005 04:00:00
  • Zuletzt bearbeitet 16.06.2026 22:11:42

The xattr file system code, as backported in Red Hat Enterprise Linux 3 on 64-bit systems, does not properly handle certain offsets, which allows local users to cause a denial of service (system crash) via certain actions on an ext3 file system with ...

  • EPSS 0.51%
  • Veröffentlicht 04.05.2005 04:00:00
  • Zuletzt bearbeitet 16.06.2026 22:12:37

Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2004-1287.