Skip to main content

Vendor/product archive

redhat / enterprise_linux_hpc_node_eus CVEs

Beta · best-effort

83 CVEs tagged to redhat / enterprise_linux_hpc_node_eus7 Critical, 38 High, 32 Medium, 6 Low, 0 Unrated.

CVE-2015-3315

Published Jun 26, 2017

Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a symlink attack on (1) /var/tmp/a…

CVSS 7.8 · High

CVE-2016-6325

Published Oct 13, 2016

The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/to…

CVSS 7.8 · High

CVE-2016-7166

Published Sep 21, 2016

libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash…

CVSS 5.5 · Medium

CVE-2016-5844

Published Sep 21, 2016

Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file.

CVSS 6.5 · Medium

CVE-2016-5418

Published Sep 21, 2016

The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a…

CVSS 7.5 · High

CVE-2016-4809

Published Sep 21, 2016

The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (applicatio…

CVSS 7.5 · High

CVE-2016-4302

Published Sep 21, 2016

Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR…

CVSS 7.8 · High
evidence mentions
3
Buzz score
21.9

CVE-2016-4300

Published Sep 21, 2016

Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip…

CVSS 7.8 · High
evidence mentions
3
Buzz score
21.9

CVE-2016-5388

Published Jul 19, 2016

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the prese…

CVSS 8.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2016-0758

Published Jun 27, 2016

Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.

CVSS 7.8 · High

CVE-2016-3698

Published Jun 13, 2016

libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-…

CVSS 8.1 · High

CVE-2016-2150

Published Jun 9, 2016

SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.

CVSS 7.1 · High

CVE-2016-0749

Published Jun 9, 2016

The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecti…

CVSS 9.8 · Critical

CVE-2015-5261

Published Jun 7, 2016

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creat…

CVSS 7.1 · High

CVE-2015-5260

Published Jun 7, 2016

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrar…

CVSS 7.8 · High

CVE-2015-4605

Published May 16, 2016

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a ce…

CVSS 7.5 · High

CVE-2015-4604

Published May 16, 2016

The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a cer…

CVSS 7.5 · High

CVE-2015-4603

Published May 16, 2016

The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary c…

CVSS 9.8 · Critical

CVE-2015-4602

Published May 16, 2016

The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial…

CVSS 9.8 · Critical
Showing 1-25 of 83 CVEsPage 1 of 4