Skip to main content

Vendor/product archive

redhat / enterprise_linux_server_tus CVEs

Beta · best-effort

756 CVEs tagged to redhat / enterprise_linux_server_tus104 Critical, 266 High, 332 Medium, 54 Low, 0 Unrated.

CVE-2016-9446

Published Jan 23, 2017

The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 f…

CVSS 7.5 · High

CVE-2016-9811

Published Jan 13, 2017

The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-…

CVSS 4.7 · Medium

CVE-2016-7426

Published Jan 13, 2017

NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial o…

CVSS 7.5 · High

CVE-2016-9131

Published Jan 12, 2017

named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2016-8864

Published Nov 2, 2016

named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit…

CVSS 7.5 · High

CVE-2016-5629

Published Oct 25, 2016

Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows remote administrators to affect availability via vectors related to…

CVSS 4.9 · Medium

CVE-2016-5612

Published Oct 25, 2016

Unspecified vulnerability in Oracle MySQL 5.5.50 and earlier, 5.6.31 and earlier, and 5.7.13 and earlier allows remote authenticated users to affect availability via vectors relat…

CVSS 6.5 · Medium

CVE-2016-3492

Published Oct 25, 2016

Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows remote authenticated users to affect availability via vectors relat…

CVSS 6.5 · Medium

CVE-2016-5425

Published Oct 13, 2016

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2016-7163

Published Sep 21, 2016

Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds…

CVSS 7.8 · High

CVE-2016-6662

Published Sep 20, 2016

Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
31.5

CVE-2016-5403

Published Aug 2, 2016

The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submittin…

CVSS 5.5 · Medium

CVE-2016-5444

Published Jul 21, 2016

Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.1…

CVSS 3.7 · Low

CVE-2016-5440

Published Jul 21, 2016

Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.1…

CVSS 4.9 · Medium

CVE-2016-2775

Published Jul 19, 2016

ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of s…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2016-5388

Published Jul 19, 2016

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the prese…

CVSS 8.1 · High
evidence mentions
2
Buzz score
17.5

CVE-2016-5126

Published Jun 1, 2016

Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execu…

CVSS 7.8 · High

CVE-2016-4020

Published May 25, 2016

The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information fro…

CVSS 6.5 · Medium

CVE-2016-4578

Published May 23, 2016

sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memor…

CVSS 5.5 · Medium
Showing 601-625 of 756 CVEsPage 25 of 31