Skip to main content

Vendor/product archive

redhat / enterprise_linux_server CVEs

Beta · best-effort

1,904 CVEs tagged to redhat / enterprise_linux_server345 Critical, 710 High, 746 Medium, 103 Low, 0 Unrated.

CVE-2019-8308

Published Feb 12, 2019

Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file.

CVSS 8.2 · High

CVE-2019-7665

Published Feb 9, 2019

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault le…

CVSS 5.5 · Medium

CVE-2019-7664

Published Feb 9, 2019

In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation faul…

CVSS 5.5 · Medium

CVE-2018-18506

Published Feb 5, 2019

When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to t…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2018-18505

Published Feb 5, 2019

An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC pro…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2018-18501

Published Feb 5, 2019

Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we pre…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2018-18500

Published Feb 5, 2019

A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in us…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2019-3813

Published Feb 4, 2019

Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the wors…

CVSS 7.5 · High

CVE-2019-7310

Published Feb 3, 2019

In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of servic…

CVSS 7.8 · High

CVE-2019-7150

Published Jan 29, 2019

An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking…

CVSS 5.5 · Medium

CVE-2019-3815

Published Jan 28, 2019

A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memor…

CVSS 3.3 · Low

CVE-2018-15982

Published Jan 18, 2019

Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS 7.8 · High
evidence mentions
35
Buzz score
72.5
KEV listed

CVE-2018-5740

Published Jan 16, 2019

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2018-5733

Published Jan 16, 2019

A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially ca…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2017-3144

Published Jan 16, 2019

A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects…

CVSS 7.5 · High
evidence mentions
3
Buzz score
21.9

CVE-2017-3143

Published Jan 16, 2019

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be a…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Showing 276-300 of 1,904 CVEsPage 12 of 77