Skip to main content

Vendor/product archive

redhat / enterprise_linux_server_aus CVEs

Beta · best-effort

1,049 CVEs tagged to redhat / enterprise_linux_server_aus206 Critical, 353 High, 420 Medium, 70 Low, 0 Unrated.

CVE-2016-1837

Published May 20, 2016

Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X b…

CVSS 5.5 · Medium

CVE-2016-1836

Published May 20, 2016

Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS…

CVSS 5.5 · Medium

CVE-2016-1834

Published May 20, 2016

Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1,…

CVSS 7.8 · High

CVE-2016-1833

Published May 20, 2016

The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers…

CVSS 5.5 · Medium

CVE-2016-3627

Published May 17, 2016

The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite rec…

CVSS 7.5 · High

CVE-2015-4643

Published May 16, 2016

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary cod…

CVSS 9.8 · Critical

CVE-2015-3152

Published May 16, 2016

Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows ma…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2016-3712

Published May 11, 2016

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mod…

CVSS 5.5 · Medium

CVE-2016-3717

Published May 5, 2016

The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-2109

Published May 5, 2016

The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2016-2108

Published May 5, 2016

The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memo…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1

CVE-2016-2107

Published May 5, 2016

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obt…

CVSS 5.9 · Medium
evidence mentions
10
Buzz score
32.0

CVE-2016-2106

Published May 5, 2016

Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (h…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2016-2105

Published May 5, 2016

Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (hea…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2016-0695

Published Apr 21, 2016

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related…

CVSS 5.9 · Medium

CVE-2016-2857

Published Apr 12, 2016

The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length i…

CVSS 8.4 · High

CVE-2015-5229

Published Apr 8, 2016

The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to…

CVSS 7.5 · High
Showing 801-825 of 1,049 CVEsPage 33 of 42