Redhat

Enterprise Linux Server

1890 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.5%
  • Veröffentlicht 21.11.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fix...

  • EPSS 1.06%
  • Veröffentlicht 20.11.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections...

  • EPSS 69.1%
  • Veröffentlicht 13.11.2017 22:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL ser...

  • EPSS 0.06%
  • Veröffentlicht 06.11.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$host...

Exploit
  • EPSS 4.97%
  • Veröffentlicht 04.11.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: T...

  • EPSS 1.16%
  • Veröffentlicht 27.10.2017 05:29:02
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • EPSS 1.16%
  • Veröffentlicht 27.10.2017 05:29:02
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Inappropriate implementation in interstitials in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to spoof the contents of the omnibox via a crafted HTML page.

  • EPSS 1.16%
  • Veröffentlicht 27.10.2017 05:29:02
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

  • EPSS 1.16%
  • Veröffentlicht 27.10.2017 05:29:02
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

  • EPSS 0.59%
  • Veröffentlicht 27.10.2017 05:29:02
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A timing attack in SVG rendering in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to extract pixel values from a cross-origin page being iframe'd via a crafted HTML page.