cbcvebase.

Redhat Enterprise Linux Hpc Node vulnerabilities

146 known vulnerabilities affecting redhat/enterprise_linux_hpc_node.

Total CVEs
146
CISA KEV
2
actively exploited
Public exploits
9
Exploited in wild
3
Severity breakdown
CRITICAL13HIGH60MEDIUM62LOW11

Vulnerabilities

Page 3 of 8
CVE-2016-4300P3HIGHCVSS 7.8v7.02016-09-21
CVE-2016-4300 [HIGH] CWE-190 CVE-2016-4300: Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarc Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, which triggers a heap-based buffer overflow.
nvd
CVE-2016-7545P3HIGHCVSS 8.8v6.0v7.02017-01-19
CVE-2016-7545 [HIGH] CWE-284 CVE-2016-7545: SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
nvd
CVE-2016-4992P3HIGHCVSS 7.5v6.0v7.02017-06-08
CVE-2016-4992 [HIGH] CWE-200 CVE-2016-4992: 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC N 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to infer the existence of RDN component objects.
nvd
CVE-2015-4601P3CRITICALCVSS 9.8v7.02016-05-16
CVE-2015-4601 [CRITICAL] CVE-2015-4601: PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or po PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confusion" issues in (1) ext/soap/php_encoding.c, (2) ext/soap/php_http.c, and (3) ext/soap/soap.c, a different issue than CVE-2015-4600.
nvd
CVE-2015-3330P3MEDIUMCVSS 6.8v7.02015-06-09
CVE-2015-3330 [MEDIUM] CWE-20 CVE-2015-3330: The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5. The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via pipelined HTTP requests that result in a "deconfigured interpreter."
nvd
CVE-2015-3276P3HIGHCVSS 7.5v7.02015-12-07
CVE-2015-3276 [HIGH] CVE-2015-3276: The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse Open The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.
nvd
CVE-2016-3099P3HIGHCVSS 7.5v7.02017-06-08
CVE-2016-3099 [HIGH] CWE-327 CVE-2016-3099: mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterpris mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the use of ciphers that were not intended to be enabled.
nvd
CVE-2015-5195P3HIGHCVSS 7.5v6.0v7.02017-07-21
CVE-2015-5195 [HIGH] CWE-20 CVE-2015-5195: ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled during compilation.
nvd
CVE-2015-4604P3HIGHCVSS 7.5v7.02016-05-16
CVE-2015-4604 [HIGH] CWE-20 CVE-2015-4604: The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40 The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishand
nvd
CVE-2015-4605P3HIGHCVSS 7.5v7.02016-05-16
CVE-2015-4605 [HIGH] CWE-20 CVE-2015-4605: The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.4 The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string that is mishandled by
nvd
CVE-2016-6489P3HIGHCVSS 7.5v7.02017-04-14
CVE-2016-6489 [HIGH] CWE-203 CVE-2016-6489: The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.
nvd
CVE-2016-0758P3HIGHCVSS 7.8v7.02016-06-27
CVE-2016-0758 [HIGH] CVE-2016-0758: Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain pri Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.
nvd
CVE-2015-3411P3MEDIUMCVSS 6.5v7.02016-05-16
CVE-2015-3411 [MEDIUM] CWE-20 CVE-2015-3411: PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack % PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file function, or (4) the hash_hmac_file
nvd
CVE-2014-9674P3HIGHCVSS 7.5v6.0v7.02015-02-08
CVE-2014-9674 [HIGH] CVE-2014-9674: The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding t The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.
nvd
CVE-2015-5194P3HIGHCVSS 7.5v6.0v7.02017-07-21
CVE-2015-5194 [HIGH] CWE-20 CVE-2015-5194: The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attacke The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands.
nvd
CVE-2016-3698P3HIGHCVSS 8.1v7.02016-06-13
CVE-2016-3698 [HIGH] CWE-284 CVE-2016-3698: libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Disc libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.
nvd
CVE-2014-8241P3CRITICALCVSS 9.8v7.02016-12-14
CVE-2014-8241 [CRITICAL] CVE-2014-8241: XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
nvd
CVE-2015-4598P3MEDIUMCVSS 6.5v7.02016-05-16
CVE-2015-4598 [MEDIUM] CWE-20 CVE-2015-4598: PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument save method or (2) the GD imagepsloadfont function, as demonstrated by a filename\0.html attack that byp
nvd
CVE-2015-5219P3HIGHCVSS 7.5v6.0v7.02017-07-21
CVE-2015-5219 [HIGH] CWE-704 CVE-2015-5219: The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions fr The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.
nvd
CVE-2016-4302P3HIGHCVSS 7.8v7.02016-09-21
CVE-2016-4302 [HIGH] CWE-119 CVE-2016-4302: Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libar Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary.
nvd
Redhat Enterprise Linux Hpc Node vulnerabilities | cvebase