Redhat Enterprise Linux Workstation vulnerabilities
1,845 known vulnerabilities affecting redhat/enterprise_linux_workstation.
Total CVEs
1,845
CISA KEV
57
actively exploited
Public exploits
136
Exploited in wild
62
Severity breakdown
CRITICAL335HIGH699MEDIUM713LOW98
Vulnerabilities
Page 49 of 93
CVE-2017-1000410HIGHCVSS 7.5v6.0v7.02017-12-07
CVE-2017-1000410 [HIGH] CVE-2017-1000410: The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of
The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned to an attacker in their uninitialized state. By manipulating the code flows that precede the handling of th
nvd
CVE-2017-15121MEDIUMCVSS 5.5v6.0v7.02017-12-07
CVE-2017-15121 [MEDIUM] CWE-20 CVE-2017-15121: A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an app
A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary.
nvd
CVE-2017-11281CRITICALCVSS 9.8PoCv6.02017-12-01
CVE-2017-11281 [CRITICAL] CWE-119 CVE-2017-11281: Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function.
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
nvd
CVE-2017-11282CRITICALCVSS 9.8PoCv6.02017-12-01
CVE-2017-11282 [CRITICAL] CWE-119 CVE-2017-11282: Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Succes
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
nvd
CVE-2017-14746CRITICALCVSS 9.8v6.0v7.02017-11-27
CVE-2017-14746 [CRITICAL] CWE-416 CVE-2017-14746: Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
nvd
CVE-2017-15275HIGHCVSS 7.5v6.0v7.02017-11-27
CVE-2017-15275 [HIGH] CWE-119 CVE-2017-15275: Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failur
Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.
nvd
CVE-2017-3157MEDIUMCVSS 5.5v6.0v7.02017-11-20
CVE-2017-3157 [MEDIUM] CWE-200 CVE-2017-3157: By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could cra
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send t
nvd
CVE-2016-8610HIGHCVSS 7.5v6.0v7.02017-11-13
CVE-2016-8610 [HIGH] CWE-400 CVE-2016-8610: A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the w
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
nvd
CVE-2015-7529HIGHCVSS 7.8v6.0v7.02017-11-06
CVE-2015-7529 [HIGH] CWE-59 CVE-2015-7529: sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain
sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.
nvd
CVE-2017-16541MEDIUMCVSS 6.5v6.0v7.02017-11-04
CVE-2017-16541 [MEDIUM] CWE-200 CVE-2017-16541: Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity
Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected.
nvd
CVE-2017-5053CRITICALCVSS 9.6v6.02017-10-27
CVE-2017-5053 [CRITICAL] CWE-125 CVE-2017-5053: An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and
An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to Array.prototype.indexOf.
nvd
CVE-2017-5121HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5121 [HIGH] CWE-20 CVE-2017-5121: Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windo
Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windows, and Mac allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to the escape analysis phase.
nvd
CVE-2017-5091HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5091 [HIGH] CWE-416 CVE-2017-5091: A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, an
A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, and Mac allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2017-5057HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5057 [HIGH] CWE-843 CVE-2017-5057: Type confusion in PDFium in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.
Type confusion in PDFium in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.
nvd
CVE-2017-5098HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5098 [HIGH] CWE-416 CVE-2017-5098: A use after free in V8 in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android a
A use after free in V8 in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2017-5095HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5095 [HIGH] CWE-787 CVE-2017-5095: Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed
Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit stack corruption via a crafted PDF file.
nvd
CVE-2017-5087HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5087 [HIGH] CWE-416 CVE-2017-5087: A use after free in Blink in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 5
A use after free in Blink in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page, aka an IndexedDB sandbox escape.
nvd
CVE-2017-5100HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5100 [HIGH] CWE-416 CVE-2017-5100: A use after free in Apps in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacke
A use after free in Apps in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
nvd
CVE-2017-5114HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5114 [HIGH] CWE-119 CVE-2017-5114: Inappropriate use of partition alloc in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Win
Inappropriate use of partition alloc in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac, and 61.0.3163.81 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted PDF file.
nvd
CVE-2017-5078HIGHCVSS 8.8v6.02017-10-27
CVE-2017-5078 [HIGH] CVE-2017-5078: Insufficient validation of untrusted input in Blink's mailto: handling in Google Chrome prior to 59.
Insufficient validation of untrusted input in Blink's mailto: handling in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac allowed a remote attacker to perform command injection via a crafted HTML page, a similar issue to CVE-2004-0121. For example, characters such as * have an incorrect interaction with xdg-email in xdg-utils, and a space charac
nvd