Skip to main content

Vendor/product archive

redhat / enterprise_linux CVEs

Beta · best-effort

2,186 CVEs tagged to redhat / enterprise_linux201 Critical, 706 High, 1,086 Medium, 193 Low, 0 Unrated.

CVE-2015-4025

Published Jun 9, 2015

PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypa…

CVSS 7.5 · High

CVE-2015-4024

Published Jun 9, 2015

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote att…

CVSS 5.0 · Medium

CVE-2015-4022

Published Jun 9, 2015

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP servers to execute arbitrary code…

CVSS 7.5 · High

CVE-2015-4021

Published Jun 9, 2015

The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 does not verify that the first character of a filename is diffe…

CVSS 5.0 · Medium

CVE-2015-3330

Published Jun 9, 2015

The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows…

CVSS 6.8 · Medium

CVE-2015-3329

Published Jun 9, 2015

Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to…

CVSS 7.5 · High

CVE-2015-3307

Published Jun 9, 2015

The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (heap me…

CVSS 7.5 · High

CVE-2015-2783

Published Jun 9, 2015

ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information from process memory or cause a denial of…

CVSS 5.8 · Medium

CVE-2015-0240

Published Feb 24, 2015

The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on…

CVSS 10.0 · Critical
evidence mentions
5
Buzz score
25.9
Showing 1,726-1,750 of 2,186 CVEsPage 70 of 88