cbcvebase.

Redhat Enterprise Linux Server Supplementary vulnerabilities

84 known vulnerabilities affecting redhat/enterprise_linux_server_supplementary.

Total CVEs
84
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL22HIGH31MEDIUM30LOW1

Vulnerabilities

Page 3 of 5
CVE-2015-3044P4MEDIUMCVSS 5.0v6.02015-04-14
CVE-2015-3044 [MEDIUM] CWE-200 CVE-2015-3044: Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
nvd
CVE-2014-7926P4HIGHCVSS 7.5v6.02015-01-22
CVE-2014-7926 [HIGH] CWE-17 CVE-2014-7926: The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a zero-length quantifier.
nvd
CVE-2014-7923P4HIGHCVSS 7.5v6.02015-01-22
CVE-2014-7923 [HIGH] CWE-17 CVE-2014-7923: The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a look-behind expression.
nvd
CVE-2015-1284P4HIGHCVSS 7.5v6.0v6.7.z2015-07-23
CVE-2015-1284 [HIGH] CWE-20 CVE-2015-1284: The LocalFrame::isURLAllowed function in core/frame/LocalFrame.cpp in Blink, as used in Google Chrom The LocalFrame::isURLAllowed function in core/frame/LocalFrame.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly check for a page's maximum number of frames, which allows remote attackers to cause a denial of service (invalid count value and use-after-free) or possibly have unspecified other impact via crafted JavaScript code
nvd
CVE-2015-1217P4HIGHCVSS 7.5v6.02015-03-09
CVE-2015-1217 [HIGH] CWE-17 CVE-2015-1217: The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, does not properly compile listeners, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
nvd
CVE-2015-1230P4HIGHCVSS 7.5v6.02015-03-09
CVE-2015-1230 [HIGH] CVE-2015-1230: The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via JavaScript code that adds an AudioContext event listener and triggers "type conf
nvd
CVE-2015-1215P4HIGHCVSS 7.5v6.02015-03-09
CVE-2015-1215 [HIGH] CWE-119 CVE-2015-1215: The filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote atta The filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation.
nvd
CVE-2015-1277P4HIGHCVSS 7.5v6.02015-07-23
CVE-2015-1277 [HIGH] CVE-2015-1277: Use-after-free vulnerability in the accessibility implementation in Google Chrome before 44.0.2403.8 Use-after-free vulnerability in the accessibility implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging lack of certain validity checks for accessibility-tree data structures.
nvd
CVE-2015-1280P4HIGHCVSS 7.5v6.02015-07-23
CVE-2015-1280 [HIGH] CWE-119 CVE-2015-1280: SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers t SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging access to a renderer process and providing crafted serialized data.
nvd
CVE-2014-3191P4HIGHCVSS 7.5v6.02014-10-08
CVE-2014-3191 [HIGH] CWE-416 CVE-2014-3191: Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers a widget-position update that improperly interacts with the render tree, related to the FrameView::updateLayoutAndStyleForPainting fu
nvd
CVE-2015-1219P4HIGHCVSS 7.5v6.02015-03-09
CVE-2015-1219 [HIGH] CWE-189 CVE-2015-1219: Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted allocation of a large amount of memory during WebGL rendering.
nvd
CVE-2015-1250P4HIGHCVSS 7.5v6.02015-05-01
CVE-2015-1250 [HIGH] CVE-2015-1250: Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.135 allow attackers to cause Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.135 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
nvd
CVE-2014-7942P4HIGHCVSS 7.5v6.02015-01-22
CVE-2014-7942 [HIGH] CWE-399 CVE-2014-7942: The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2014-3194P4HIGHCVSS 7.5v6.02014-10-08
CVE-2014-3194 [HIGH] CWE-416 CVE-2014-3194: Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2011-4111P4MEDIUMCVSS 6.8v6.1.z2014-02-26
CVE-2011-4111 [MEDIUM] CWE-119 CVE-2011-4111: Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU b Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.
nvd
CVE-2015-1271P4MEDIUMCVSS 6.8v6.02015-07-23
CVE-2015-1271 [MEDIUM] CWE-119 CVE-2015-1271: PDFium, as used in Google Chrome before 44.0.2403.89, does not properly handle certain out-of-memory PDFium, as used in Google Chrome before 44.0.2403.89, does not properly handle certain out-of-memory conditions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted PDF document that triggers a large memory allocation.
nvd
CVE-2015-1273P4MEDIUMCVSS 6.8v6.02015-07-23
CVE-2015-1273 [MEDIUM] CWE-119 CVE-2015-1273: Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome bef Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid JPEG2000 data in a PDF document.
nvd
CVE-2013-5895P4MEDIUMCVSS 5.0v5.0v6.02014-01-15
CVE-2013-5895 [MEDIUM] CVE-2013-5895: Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect confidentiality via unknown vectors related to JavaFX.
nvd
CVE-2016-1665P4MEDIUMCVSS 6.5v6.02016-05-14
CVE-2016-1665 [MEDIUM] CWE-20 CVE-2016-1665: The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrom The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote attackers to obtain sensitive information via crafted JavaScript code.
nvd
CVE-2015-1214P4HIGHCVSS 7.5v6.02015-03-09
CVE-2015-1214 [HIGH] CWE-190 CVE-2015-1214: Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters im Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a reset action with a large count value, leading to an out-of-bound
nvd
Redhat Enterprise Linux Server Supplementary vulnerabilities | cvebase