Redhat Enterprise Mrg vulnerabilities
73 known vulnerabilities affecting redhat/enterprise_mrg.
Total CVEs
73
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH20MEDIUM45LOW7
Vulnerabilities
Page 4 of 4
CVE-2009-5136P4MEDIUMCVSS 4.0v1.0v1.0.1+6 more2013-10-11
CVE-2009-5136 [MEDIUM] CWE-20 CVE-2009-5136: The policy definition evaluator in Condor before 7.4.2 does not properly handle attributes in a WANT
The policy definition evaluator in Condor before 7.4.2 does not properly handle attributes in a WANT_SUSPEND policy that evaluate to an UNDEFINED state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.
nvd
CVE-2013-2015P4MEDIUMCVSS 4.7v2.02013-04-29
CVE-2013-2015 [MEDIUM] CWE-399 CVE-2013-2015: The ext4_orphan_del function in fs/ext4/namei.c in the Linux kernel before 3.7.3 does not properly h
The ext4_orphan_del function in fs/ext4/namei.c in the Linux kernel before 3.7.3 does not properly handle orphan-list entries for non-journal filesystems, which allows physically proximate attackers to cause a denial of service (system hang) via a crafted filesystem on removable media, as demonstrated by the e2fsprogs tests/f_orphan_extents_inode/imag
nvd
CVE-2015-7553P4MEDIUMCVSS 4.7v2.02017-09-14
CVE-2015-7553 [MEDIUM] CWE-362 CVE-2015-7553: Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2,
Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2, when the nfnetlink_log module is loaded, allows local users to cause a denial of service (panic) by creating netlink sockets.
nvd
CVE-2012-2685P4MEDIUMCVSS 4.0v2.02012-09-28
CVE-2012-2685 [MEDIUM] CWE-399 CVE-2012-2685: Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows
Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote authenticated users to cause a denial of service (memory consumption) via a large size in an image request.
nvd
CVE-2013-4255P4LOWCVSS 3.5v2.0v2.1+2 more2013-10-11
CVE-2013-4255 [LOW] CWE-20 CVE-2013-4255: The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attribu
The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attributes in a (1) PREEMPT, (2) SUSPEND, (3) CONTINUE, (4) WANT_VACATE, or (5) KILL policy that evaluate to an Unconfigured, Undefined, or Error state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.
nvd
CVE-2014-3940P4MEDIUMCVSS 4.0v2.02014-06-05
CVE-2014-3940 [MEDIUM] CWE-362 CVE-2014-3940: The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which al
The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by triggering a race condition via numa_maps read operations during hugepage migration, related to fs/proc/task_mmu.
nvd
CVE-2010-3701P4MEDIUMCVSS 4.0≤ 1.2v1.0+5 more2010-10-12
CVE-2010-3701 [MEDIUM] CWE-399 CVE-2010-3701: lib/MessageStoreImpl.cpp in Red Hat Enterprise MRG before 1.2.2 allows remote authenticated users to
lib/MessageStoreImpl.cpp in Red Hat Enterprise MRG before 1.2.2 allows remote authenticated users to cause a denial of service (stack memory exhaustion and broker crash) via a large persistent message.
nvd
CVE-2013-1774P4MEDIUMCVSS 4.0v2.02013-02-28
CVE-2013-1774 [MEDIUM] CWE-264 CVE-2013-1774: The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local
The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local users to cause a denial of service (NULL pointer dereference and system crash) via an attempted /dev/ttyUSB read or write operation on a disconnected Edgeport USB serial converter.
nvd
CVE-2014-3917P4LOWCVSS 3.3v2.02014-06-05
CVE-2014-3917 [LOW] CWE-200 CVE-2014-3917: kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certai
kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a large value of a syscall number.
nvd
CVE-2013-2548P4LOWCVSS 2.1v2.02013-03-15
CVE-2013-2548 [LOW] CWE-310 CVE-2013-2548: The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configur
The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect length value during a copy operation, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability.
nvd
CVE-2013-2546P4LOWCVSS 2.1v2.02013-03-15
CVE-2013-2546 [LOW] CWE-310 CVE-2013-2546: The report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorr
The report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect C library function for copying strings, which allows local users to obtain sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN capability.
nvd
CVE-2013-2164P4LOWCVSS 2.1v2.02013-07-04
CVE-2013-2164 [LOW] CWE-200 CVE-2013-2164: The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux kernel through 3.10 all
The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux kernel through 3.10 allows local users to obtain sensitive information from kernel memory via a read operation on a malfunctioning CD-ROM drive.
nvd
CVE-2013-2547P4LOWCVSS 2.1v2.02013-03-15
CVE-2013-2547 [LOW] CWE-310 CVE-2013-2547: The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configur
The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 does not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability.
nvd
← Previous4 / 4