Redhat

Enterprise Linux Workstation

1845 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Published 18.02.2011 20:00:09
  • Last modified 11.04.2025 00:51:21

The ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 does not initialize a certain response buffer, which allows local users to obtain potentially sensitive information from kernel memory via vector...

  • EPSS 0.07%
  • Published 23.12.2010 18:00:02
  • Last modified 11.04.2025 00:51:21

arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.

Exploit
  • EPSS 1.62%
  • Published 07.12.2010 21:00:09
  • Last modified 11.04.2025 00:51:21

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath...

Exploit
  • EPSS 0.57%
  • Published 17.11.2010 01:00:02
  • Last modified 11.04.2025 00:51:21

libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to ca...

Exploit
  • EPSS 8.12%
  • Published 06.11.2010 00:00:03
  • Last modified 11.04.2025 00:51:21

WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames.

  • EPSS 3.86%
  • Published 05.11.2010 18:00:05
  • Last modified 11.04.2025 00:51:21

The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unkn...

  • EPSS 27.69%
  • Published 05.11.2010 17:00:01
  • Last modified 11.04.2025 00:51:21

ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbi...

  • EPSS 0.13%
  • Published 22.06.2010 17:30:01
  • Last modified 11.04.2025 00:51:21

The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number.

  • EPSS 5.29%
  • Published 05.03.2010 19:30:00
  • Last modified 11.04.2025 00:51:21

Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denia...

Exploit
  • EPSS 1.81%
  • Published 27.01.2010 17:30:00
  • Last modified 11.04.2025 00:51:21

A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (deadlock) via crafted packets that force collisions in the IPv4 routing hash table, and...