Redhat Enterprise Linux Server vulnerabilities
1,891 known vulnerabilities affecting redhat/enterprise_linux_server.
Total CVEs
1,891
CISA KEV
58
actively exploited
Public exploits
134
Exploited in wild
63
Severity breakdown
CRITICAL347HIGH710MEDIUM734LOW100
Vulnerabilities
Page 50 of 95
CVE-2017-11215CRITICALCVSS 9.8v6.02017-12-09
CVE-2017-11215 [CRITICAL] CWE-416 CVE-2017-11215: An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information
nvd
CVE-2017-3112CRITICALCVSS 9.8v6.02017-12-09
CVE-2017-3112 [CRITICAL] CWE-125 CVE-2017-3112: An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability oc
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of AdobePSDK metadata. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the
nvd
CVE-2017-11225CRITICALCVSS 9.8v6.02017-12-09
CVE-2017-11225 [CRITICAL] CWE-416 CVE-2017-11225: An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK metadata functionality. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hi
nvd
CVE-2017-11213CRITICALCVSS 9.8v6.02017-12-09
CVE-2017-11213 [CRITICAL] CWE-125 CVE-2017-11213: An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability oc
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer due to an integer overflow; the computation is part of the abstraction that creates an arbitrarily sized transparent or opaque bitmap image. The use of an in
nvd
CVE-2017-3114CRITICALCVSS 9.8v6.02017-12-09
CVE-2017-3114 [CRITICAL] CWE-125 CVE-2017-3114: An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability oc
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer; the computation is part of providing language- and region- or country- specific functionality. The use of an invalid (out-of-range) pointer offset during acce
nvd
CVE-2017-1000410HIGHCVSS 7.5v6.0v7.02017-12-07
CVE-2017-1000410 [HIGH] CVE-2017-1000410: The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of
The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned to an attacker in their uninitialized state. By manipulating the code flows that precede the handling of th
nvd
CVE-2017-15121MEDIUMCVSS 5.5v6.0v7.02017-12-07
CVE-2017-15121 [MEDIUM] CWE-20 CVE-2017-15121: A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an app
A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary.
nvd
CVE-2017-11281CRITICALCVSS 9.8PoCv6.02017-12-01
CVE-2017-11281 [CRITICAL] CWE-119 CVE-2017-11281: Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function.
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
nvd
CVE-2017-11282CRITICALCVSS 9.8PoCv6.02017-12-01
CVE-2017-11282 [CRITICAL] CWE-119 CVE-2017-11282: Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Succes
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
nvd
CVE-2017-14746CRITICALCVSS 9.8v6.0v7.02017-11-27
CVE-2017-14746 [CRITICAL] CWE-416 CVE-2017-14746: Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
nvd
CVE-2017-15275HIGHCVSS 7.5v6.0v7.02017-11-27
CVE-2017-15275 [HIGH] CWE-119 CVE-2017-15275: Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failur
Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.
nvd
CVE-2017-7550CRITICALCVSS 9.8v7.02017-11-21
CVE-2017-7550 [CRITICAL] CWE-532 CVE-2017-7550: A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain para
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module
nvd
CVE-2017-3157MEDIUMCVSS 5.5v6.0v7.02017-11-20
CVE-2017-3157 [MEDIUM] CWE-200 CVE-2017-3157: By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could cra
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send t
nvd
CVE-2016-8610HIGHCVSS 7.5v6.0v7.02017-11-13
CVE-2016-8610 [HIGH] CWE-400 CVE-2016-8610: A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the w
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
nvd
CVE-2015-7529HIGHCVSS 7.8v6.0v7.02017-11-06
CVE-2015-7529 [HIGH] CWE-59 CVE-2015-7529: sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain
sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.
nvd
CVE-2017-16541MEDIUMCVSS 6.5v6.0v7.02017-11-04
CVE-2017-16541 [MEDIUM] CWE-200 CVE-2017-16541: Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity
Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected.
nvd
CVE-2017-5053CRITICALCVSS 9.6v6.02017-10-27
CVE-2017-5053 [CRITICAL] CWE-125 CVE-2017-5053: An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and
An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to Array.prototype.indexOf.
nvd
CVE-2017-5121HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5121 [HIGH] CWE-20 CVE-2017-5121: Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windo
Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windows, and Mac allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to the escape analysis phase.
nvd
CVE-2017-5091HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5091 [HIGH] CWE-416 CVE-2017-5091: A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, an
A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, and Mac allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2017-5057HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5057 [HIGH] CWE-843 CVE-2017-5057: Type confusion in PDFium in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.
Type confusion in PDFium in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
nvd