cbcvebase.

Redhat Enterprise Linux Server Eus vulnerabilities

622 known vulnerabilities affecting redhat/enterprise_linux_server_eus.

Total CVEs
622
CISA KEV
9
actively exploited
Public exploits
50
Exploited in wild
18
Severity breakdown
CRITICAL179HIGH238MEDIUM183LOW22

Vulnerabilities

Page 2 of 32
CVE-2017-17405P2HIGHCVSS 8.8PoCv7.4v7.5+1 more2017-12-15
CVE-2017-17405 [HIGH] CWE-78 CVE-2017-17405: Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the "|" pipe character, the command following the pipe character is executed. The default value of localfile is File.basename(remotefile), so malici
nvd
CVE-2018-7750P2CRITICALCVSS 9.8PoCv6.72018-03-13
CVE-2018-7750 [CRITICAL] CWE-287 CVE-2018-7750: transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client ca
nvd
CVE-2017-9462P2HIGHCVSS 8.8PoCv7.3v7.4+2 more2017-06-06
CVE-2017-9462 [HIGH] CWE-732 CVE-2017-9462: In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.
nvd
CVE-2016-2107P2MEDIUMCVSS 5.9PoCv7.22016-05-05
CVE-2016-2107 [MEDIUM] CVE-2016-2107: The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.
nvd
CVE-2017-1000083P2HIGHCVSS 7.8PoCv7.4v7.5+1 more2017-09-05
CVE-2017-1000083 [HIGH] CVE-2017-1000083: backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows r backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.
nvd
CVE-2018-11235P2HIGHCVSS 7.8PoCv7.52018-05-30
CVE-2018-11235 [HIGH] CWE-22 CVE-2018-11235: In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x b In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs "git clone --recurse-submodules" because submodule "names" are obtained from this file, and then ap
nvd
CVE-2018-6871P2CRITICALCVSS 9.8PoCv7.4v7.5+1 more2018-02-09
CVE-2018-6871 [CRITICAL] CVE-2018-6871: LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =W LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
nvd
CVE-2019-6116P2HIGHCVSS 7.8PoCv7.62019-03-21
CVE-2019-6116 [HIGH] CVE-2019-6116: In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system op In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.
nvd
CVE-2019-6974P2HIGHCVSS 8.1PoCv7.62019-02-15
CVE-2019-6974 [HIGH] CWE-362 CVE-2019-6974: In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles referen In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.
nvd
CVE-2016-9899P2CRITICALCVSS 9.8PoCv7.3v7.4+1 more2018-06-11
CVE-2016-9899 [CRITICAL] CWE-416 CVE-2016-9899: Use-after-free while manipulating DOM events and removing audio elements due to errors in the handli Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2018-5159P2CRITICALCVSS 9.8PoCv7.5v7.62018-06-11
CVE-2018-5159 [CRITICAL] CWE-190 CVE-2018-5159: An integer overflow can occur in the Skia library due to 32-bit integer use in an array without inte An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8
nvd
CVE-2017-0901P2HIGHCVSS 7.5PoCv7.4v7.5+1 more2017-08-31
CVE-2017-0901 [HIGH] CWE-22 CVE-2017-0901: RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously cr RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
nvd
CVE-2017-1000251P2HIGHCVSS 8.0PoCv6.7v7.2+5 more2017-09-12
CVE-2017-1000251 [HIGH] CWE-787 CVE-2017-1000251: The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.
nvd
CVE-2017-5447P2CRITICALCVSS 9.1PoCv7.3v7.4+1 more2018-06-11
CVE-2017-5447 [CRITICAL] CWE-416 CVE-2017-5447: An out-of-bounds read during the processing of glyph widths during text layout. This results in a po An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2018-11784P3MEDIUMCVSS 4.3PoCv7.62018-10-04
CVE-2018-11784 [MEDIUM] CWE-601 CVE-2018-11784: When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.
nvd
CVE-2017-5404P2CRITICALCVSS 9.8PoCv7.3v7.4+1 more2018-06-11
CVE-2017-5404 [CRITICAL] CWE-416 CVE-2017-5404: A use-after-free error can occur when manipulating ranges in selections with one node inside a nativ A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2017-5465P2CRITICALCVSS 9.1PoCv7.3v7.4+1 more2018-06-11
CVE-2017-5465 [CRITICAL] CWE-125 CVE-2017-5465: An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and a An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2016-2108P2CRITICALCVSS 9.8v7.22016-05-05
CVE-2016-2108 [CRITICAL] CWE-119 CVE-2016-2108: The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the "negative zero" issue.
nvd
CVE-2018-17961P3HIGHCVSS 8.6PoCv7.62018-10-15
CVE-2018-17961 [HIGH] CVE-2018-17961: Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via v Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.
nvd
CVE-2012-4512P3HIGHCVSS 8.8PoCv6.32020-02-08
CVE-2012-4512 [HIGH] CWE-843 CVE-2012-4512: The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
nvd
Redhat Enterprise Linux Server Eus vulnerabilities | cvebase