Skip to main content

Vendor/product archive

redhat / enterprise_linux_server_aus CVEs

Beta · best-effort

1,049 CVEs tagged to redhat / enterprise_linux_server_aus206 Critical, 353 High, 420 Medium, 70 Low, 0 Unrated.

CVE-2016-5418

Published Sep 21, 2016

The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a…

CVSS 7.5 · High

CVE-2016-4809

Published Sep 21, 2016

The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (applicatio…

CVSS 7.5 · High

CVE-2016-4302

Published Sep 21, 2016

Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR…

CVSS 7.8 · High
evidence mentions
3
Buzz score
21.9

CVE-2016-4300

Published Sep 21, 2016

Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip…

CVSS 7.8 · High
evidence mentions
3
Buzz score
21.9

CVE-2016-6662

Published Sep 20, 2016

Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
31.5

CVE-2016-5403

Published Aug 2, 2016

The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submittin…

CVSS 5.5 · Medium

CVE-2016-5444

Published Jul 21, 2016

Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.1…

CVSS 3.7 · Low

CVE-2016-5440

Published Jul 21, 2016

Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.1…

CVSS 4.9 · Medium

CVE-2016-2775

Published Jul 19, 2016

ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of s…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2016-5388

Published Jul 19, 2016

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the prese…

CVSS 8.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2016-0758

Published Jun 27, 2016

Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.

CVSS 7.8 · High

CVE-2016-3698

Published Jun 13, 2016

libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-…

CVSS 8.1 · High

CVE-2016-2150

Published Jun 9, 2016

SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.

CVSS 7.1 · High

CVE-2016-0749

Published Jun 9, 2016

The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecti…

CVSS 9.8 · Critical

CVE-2016-5126

Published Jun 1, 2016

Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execu…

CVSS 7.8 · High

CVE-2016-4020

Published May 25, 2016

The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information fro…

CVSS 6.5 · Medium

CVE-2016-4578

Published May 23, 2016

sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memor…

CVSS 5.5 · Medium

CVE-2016-1840

Published May 20, 2016

Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS b…

CVSS 7.8 · High

CVE-2016-1839

Published May 20, 2016

The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers…

CVSS 5.5 · Medium

CVE-2016-1838

Published May 20, 2016

The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows…

CVSS 5.5 · Medium
Showing 776-800 of 1,049 CVEsPage 32 of 42