Redhat

Enterprise Linux Workstation

1845 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.07%
  • Veröffentlicht 08.04.2015 18:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.

  • EPSS 15.8%
  • Veröffentlicht 08.04.2015 18:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related to dynamically evalu...

  • EPSS 30.44%
  • Veröffentlicht 01.04.2015 02:00:35
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial ...

Exploit
  • EPSS 28.51%
  • Veröffentlicht 30.03.2015 10:59:15
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execute arbitrary code via a crafted unserialize call th...

Exploit
  • EPSS 7.1%
  • Veröffentlicht 30.03.2015 10:59:14
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attackers to bypass intended extens...

Exploit
  • EPSS 11.21%
  • Veröffentlicht 30.03.2015 10:59:10
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an a...

  • EPSS 0.11%
  • Veröffentlicht 18.03.2015 16:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

automount 5.0.8, when a program map uses certain interpreted languages, uses the calling user's USER and HOME environment variable values instead of the values for the user used to run the mapped program, which allows local users to gain privileges v...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 02.03.2015 11:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering u...

  • EPSS 2.45%
  • Veröffentlicht 02.03.2015 11:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass in...

Exploit
  • EPSS 1.41%
  • Veröffentlicht 08.02.2015 11:59:36
  • Zuletzt bearbeitet 06.05.2026 22:30:45

bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.