Redhat Enterprise Linux Hpc Node vulnerabilities
146 known vulnerabilities affecting redhat/enterprise_linux_hpc_node.
Total CVEs
146
CISA KEV
2
actively exploited
Public exploits
9
Exploited in wild
2
Severity breakdown
CRITICAL13HIGH60MEDIUM62LOW11
Vulnerabilities
Page 2 of 8
CVE-2016-7545HIGHCVSS 8.8v6.0v7.02017-01-19
CVE-2016-7545 [HIGH] CWE-284 CVE-2016-7545: SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via
SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
nvd
CVE-2016-7091MEDIUMCVSS 4.4v7.02016-12-22
CVE-2016-7091 [MEDIUM] CWE-200 CVE-2016-7091: sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly
sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could use this flaw to read content from specially formatted files with elev
nvd
CVE-2014-8241CRITICALCVSS 9.8v7.02016-12-14
CVE-2014-8241 [CRITICAL] CVE-2014-8241: XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
nvd
CVE-2016-7796MEDIUMCVSS 5.5v7.02016-10-13
CVE-2016-7796 [MEDIUM] CWE-20 CVE-2016-7796: The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (
The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled.
nvd
CVE-2016-4302HIGHCVSS 7.8v7.02016-09-21
CVE-2016-4302 [HIGH] CWE-119 CVE-2016-4302: Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libar
Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary.
nvd
CVE-2016-5418HIGHCVSS 7.5v6.0v7.02016-09-21
CVE-2016-5418 [HIGH] CWE-19 CVE-2016-5418: The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero
The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.
nvd
CVE-2016-4300HIGHCVSS 7.8v7.02016-09-21
CVE-2016-4300 [HIGH] CWE-190 CVE-2016-4300: Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarc
Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, which triggers a heap-based buffer overflow.
nvd
CVE-2016-4809HIGHCVSS 7.5v6.0v7.02016-09-21
CVE-2016-4809 [HIGH] CWE-20 CVE-2016-4809: The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchiv
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large symlink.
nvd
CVE-2016-7166MEDIUMCVSS 5.5v7.0v6.02016-09-21
CVE-2016-7166 [MEDIUM] CWE-399 CVE-2016-7166: libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote a
libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
nvd
CVE-2016-5844MEDIUMCVSS 6.5v6.0v7.02016-09-21
CVE-2016-5844 [MEDIUM] CWE-190 CVE-2016-5844: Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a den
Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file.
nvd
CVE-2016-5388HIGHCVSS 8.1v7.0v6.02016-07-19
CVE-2016-5388 [HIGH] CWE-284 CVE-2016-5388: Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy
nvd
CVE-2016-0758HIGHCVSS 7.8v7.02016-06-27
CVE-2016-0758 [HIGH] CVE-2016-0758: Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain pri
Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.
nvd
CVE-2016-4470MEDIUMCVSS 5.5v7.02016-06-27
CVE-2016-4470 [MEDIUM] CVE-2016-4470: The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not e
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.
nvd
CVE-2016-3698HIGHCVSS 8.1v7.02016-06-13
CVE-2016-3698 [HIGH] CWE-284 CVE-2016-3698: libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Disc
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.
nvd
CVE-2015-5260HIGHCVSS 7.8v6.0v7.02016-06-07
CVE-2015-5260 [HIGH] CWE-119 CVE-2015-5260: Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.
nvd
CVE-2015-5261HIGHCVSS 7.1v6.0v7.02016-06-07
CVE-2015-5261 [HIGH] CWE-119 CVE-2015-5261: Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitra
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
nvd
CVE-2015-4600CRITICALCVSS 9.8v7.02016-05-16
CVE-2015-4600 [CRITICAL] CVE-2015-4600: The SoapClient implementation in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allo
The SoapClient implementation in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confusion" issues in the (1) SoapClient::__getLastRequest, (2) SoapClient::__getLastResponse, (3) SoapClient:
nvd
CVE-2015-4602CRITICALCVSS 9.8v7.02016-05-16
CVE-2015-4602 [CRITICAL] CVE-2015-4602: The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x b
The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to a "type confusion" issue.
nvd
CVE-2015-4601CRITICALCVSS 9.8v7.02016-05-16
CVE-2015-4601 [CRITICAL] CVE-2015-4601: PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or po
PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confusion" issues in (1) ext/soap/php_encoding.c, (2) ext/soap/php_http.c, and (3) ext/soap/soap.c, a different issue than CVE-2015-4600.
nvd
CVE-2015-4599CRITICALCVSS 9.8v7.02016-05-16
CVE-2015-4599 [CRITICAL] CVE-2015-4599: The SoapFault::__toString method in ext/soap/soap.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5
The SoapFault::__toString method in ext/soap/soap.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information, cause a denial of service (application crash), or possibly execute arbitrary code via an unexpected data type, related to a "type confusion" issue.
nvd