Skip to main content

Vendor/product archive

redhat / enterprise_linux_server_eus CVEs

Beta · best-effort

620 CVEs tagged to redhat / enterprise_linux_server_eus172 Critical, 240 High, 187 Medium, 21 Low, 0 Unrated.

CVE-2021-20233

Published Mar 3, 2021

A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single q…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2021-20225

Published Mar 3, 2021

A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2020-27779

Published Mar 3, 2021

A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory cre…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2020-27749

Published Mar 3, 2021

A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variable contents, using a 1kB stack…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2020-25647

Published Mar 3, 2021

A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assumes the USB device is providin…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2020-25632

Published Mar 3, 2021

A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2020-14372

Published Mar 3, 2021

A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with priv…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2014-8140

Published Jan 31, 2020

Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t comma…

CVSS 7.8 · High

CVE-2014-8139

Published Jan 31, 2020

Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command a…

CVSS 7.8 · High

CVE-2015-3147

Published Jan 14, 2020

daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or pos…

CVSS 6.5 · Medium

CVE-2019-10216

Published Nov 27, 2019

In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could ab…

CVSS 7.8 · High

CVE-2017-5333

Published Nov 4, 2019

Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process cras…

CVSS 7.8 · High

CVE-2017-5332

Published Nov 4, 2019

The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (proces…

CVSS 7.8 · High

CVE-2019-14813

Published Sep 6, 2019

A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSA…

CVSS 9.8 · Critical

CVE-2019-10168

Published Aug 2, 2019

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the p…

CVSS 7.8 · High
Showing 1-25 of 620 CVEsPage 1 of 25