Skip to main content

Vendor/product archive

redhat / enterprise_linux_server_eus CVEs

Beta · best-effort

620 CVEs tagged to redhat / enterprise_linux_server_eus172 Critical, 240 High, 187 Medium, 21 Low, 0 Unrated.

CVE-2018-2582

Published Jan 18, 2018

Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 8u152 and 9.0.1; Java SE Embe…

CVSS 6.5 · Medium

CVE-2018-5345

Published Jan 12, 2018

A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab f…

CVSS 7.8 · High

CVE-2017-17405

Published Dec 15, 2017

Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the loc…

CVSS 8.8 · High

CVE-2017-1000407

Published Dec 11, 2017

The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.

CVSS 7.4 · High

CVE-2017-1000410

Published Dec 7, 2017

The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info…

CVSS 7.5 · High

CVE-2017-15121

Published Dec 7, 2017

A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary.

CVSS 5.5 · Medium

CVE-2017-3157

Published Nov 20, 2017

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Informa…

CVSS 5.5 · Medium

CVE-2015-7529

Published Nov 6, 2017

sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, a…

CVSS 7.8 · High

CVE-2017-0903

Published Oct 11, 2017

RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white list…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2017-1000116

Published Oct 5, 2017

Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2017-1000111

Published Oct 5, 2017

Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state…

CVSS 7.8 · High

CVE-2017-1000251

Published Sep 12, 2017

The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerabilit…

CVSS 8.0 · High
evidence mentions
4
Buzz score
25.6

CVE-2017-1000083

Published Sep 5, 2017

backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR arc…

CVSS 7.8 · High

CVE-2017-0902

Published Aug 31, 2017

RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a ser…

CVSS 8.1 · High

CVE-2017-0901

Published Aug 31, 2017

RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.

CVSS 7.5 · High

CVE-2017-0900

Published Aug 31, 2017

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query`…

CVSS 7.5 · High

CVE-2017-0899

Published Aug 31, 2017

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute t…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Showing 351-375 of 620 CVEsPage 15 of 25