Redhat

Enterprise Linux

1731 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 23.12.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:33:11

A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service, or QEMU guest-to-host escape and code execution, via VIRGL_CCMD_RESO...

  • EPSS 0.11%
  • Veröffentlicht 23.12.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:33:11

An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_BLIT commands.

  • EPSS 0.11%
  • Veröffentlicht 23.12.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:33:11

A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via VIRGL_CCMD_RESOURCE_INLINE_WRITE commands.

  • EPSS 0.41%
  • Veröffentlicht 19.12.2019 21:15:13
  • Zuletzt bearbeitet 21.11.2024 04:34:36

A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the defaul...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 19.12.2019 18:15:12
  • Zuletzt bearbeitet 21.11.2024 04:35:37

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c ...

  • EPSS 0.33%
  • Veröffentlicht 13.12.2019 01:15:11
  • Zuletzt bearbeitet 21.11.2024 04:31:10

Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and cre...

  • EPSS 0.68%
  • Veröffentlicht 13.12.2019 01:15:10
  • Zuletzt bearbeitet 21.11.2024 04:31:09

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the ...

  • EPSS 0.78%
  • Veröffentlicht 13.12.2019 01:15:10
  • Zuletzt bearbeitet 21.11.2024 04:31:10

Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field wou...

  • EPSS 5.9%
  • Veröffentlicht 10.12.2019 22:15:13
  • Zuletzt bearbeitet 21.11.2024 04:25:36

Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • EPSS 0.74%
  • Veröffentlicht 06.12.2019 16:15:10
  • Zuletzt bearbeitet 21.11.2024 04:34:35

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, whi...