Redhat

Enterprise Mrg

72 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.54%
  • Veröffentlicht 09.10.2013 14:54:26
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cumin, as used in Red Hat Enterprise MRG 2.4, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted Ajax update request.

Exploit
  • EPSS 52.33%
  • Veröffentlicht 01.10.2013 20:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arb...

  • EPSS 0.59%
  • Veröffentlicht 23.08.2013 16:55:07
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL serve...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 04.07.2013 21:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux kernel through 3.10 allows local users to obtain sensitive information from kernel memory via a read operation on a malfunctioning CD-ROM drive.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 29.04.2013 14:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write acce...

  • EPSS 0.09%
  • Veröffentlicht 29.04.2013 14:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The ext4_orphan_del function in fs/ext4/namei.c in the Linux kernel before 3.7.3 does not properly handle orphan-list entries for non-journal filesystems, which allows physically proximate attackers to cause a denial of service (system hang) via a cr...

  • EPSS 0.05%
  • Veröffentlicht 15.03.2013 20:55:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect length value during a copy operation, which allows local users to obtain sensitive infor...

  • EPSS 0.07%
  • Veröffentlicht 15.03.2013 20:55:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 does not initialize certain structure members, which allows local users to obtain sensitive information fr...

  • EPSS 0.05%
  • Veröffentlicht 15.03.2013 20:55:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect C library function for copying strings, which allows local users to obtain sensitive information from kernel stack memory by leveraging the CAP_NE...

  • EPSS 0.69%
  • Veröffentlicht 14.03.2013 03:10:23
  • Zuletzt bearbeitet 11.04.2025 00:51:21

aviary/jobcontrol.py in Condor, as used in Red Hat Enterprise MRG 2.3, when removing a job, allows remote attackers to cause a denial of service (condor_schedd restart) via square brackets in the cproc option.