Redhat Enterprise Linux Desktop vulnerabilities

1,928 known vulnerabilities affecting redhat/enterprise_linux_desktop.

Total CVEs
1,928
CISA KEV
56
actively exploited
Public exploits
141
Exploited in wild
61
Severity breakdown
CRITICAL345HIGH708MEDIUM756LOW119

Vulnerabilities

Page 48 of 97
CVE-2017-3157MEDIUMCVSS 5.5v6.0v7.02017-11-20
CVE-2017-3157 [MEDIUM] CWE-200 CVE-2017-3157: By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could cra By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send t
nvd
CVE-2016-8610HIGHCVSS 7.5v6.0v7.02017-11-13
CVE-2016-8610 [HIGH] CWE-400 CVE-2016-8610: A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the w A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
nvd
CVE-2015-7529HIGHCVSS 7.8v6.0v7.02017-11-06
CVE-2015-7529 [HIGH] CWE-59 CVE-2015-7529: sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.
nvd
CVE-2017-16541MEDIUMCVSS 6.5v6.0v7.02017-11-04
CVE-2017-16541 [MEDIUM] CWE-200 CVE-2017-16541: Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected.
nvd
CVE-2017-5053CRITICALCVSS 9.6v6.02017-10-27
CVE-2017-5053 [CRITICAL] CWE-125 CVE-2017-5053: An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to Array.prototype.indexOf.
nvd
CVE-2017-5121HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5121 [HIGH] CWE-20 CVE-2017-5121: Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windo Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windows, and Mac allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to the escape analysis phase.
nvd
CVE-2017-5091HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5091 [HIGH] CWE-416 CVE-2017-5091: A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, an A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, and Mac allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2017-5057HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5057 [HIGH] CWE-843 CVE-2017-5057: Type confusion in PDFium in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58. Type confusion in PDFium in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
nvd
CVE-2017-5098HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5098 [HIGH] CWE-416 CVE-2017-5098: A use after free in V8 in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android a A use after free in V8 in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2017-5095HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5095 [HIGH] CWE-787 CVE-2017-5095: Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit stack corruption via a crafted PDF file.
nvd
CVE-2017-5087HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5087 [HIGH] CWE-416 CVE-2017-5087: A use after free in Blink in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 5 A use after free in Blink in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page, aka an IndexedDB sandbox escape.
nvd
CVE-2017-5100HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5100 [HIGH] CWE-416 CVE-2017-5100: A use after free in Apps in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacke A use after free in Apps in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2017-5114HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5114 [HIGH] CWE-119 CVE-2017-5114: Inappropriate use of partition alloc in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Win Inappropriate use of partition alloc in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac, and 61.0.3163.81 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.
nvd
CVE-2017-5078HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5078 [HIGH] CVE-2017-5078: Insufficient validation of untrusted input in Blink's mailto: handling in Google Chrome prior to 59. Insufficient validation of untrusted input in Blink's mailto: handling in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac allowed a remote attacker to perform command injection via a crafted HTML page, a similar issue to CVE-2004-0121. For example, characters such as * have an incorrect interaction with xdg-email in xdg-utils, and a space charac
nvd
CVE-2017-5068HIGHCVSS 7.5v6.02017-10-27
CVE-2017-5068 [HIGH] CWE-362 CVE-2017-5068: Incorrect handling of picture ID in WebRTC in Google Chrome prior to 58.0.3029.96 for Mac, Windows, Incorrect handling of picture ID in WebRTC in Google Chrome prior to 58.0.3029.96 for Mac, Windows, and Linux allowed a remote attacker to trigger a race condition via a crafted HTML page.
nvd
CVE-2017-5062HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5062 [HIGH] CWE-416 CVE-2017-5062: A use after free in Chrome Apps in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, A use after free in Chrome Apps in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to potentially perform out of bounds memory access via a crafted Chrome extension.
nvd
CVE-2017-5070HIGHCVSS 8.8KEVv6.02017-10-27
CVE-2017-5070 [HIGH] CWE-843 CVE-2017-5070: Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.30 Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2017-5116HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5116 [HIGH] CWE-843 CVE-2017-5116: Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.31 Type confusion in V8 in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2017-5054HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5054 [HIGH] CWE-125 CVE-2017-5054: An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to obtain heap memory contents via a crafted HTML page.
nvd
CVE-2017-5111HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5111 [HIGH] CWE-416 CVE-2017-5111: A use after free in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac allowe A use after free in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.
nvd