Skip to main content

Vendor/product archive

redhat / enterprise_linux_server_aus CVEs

Beta · best-effort

1,049 CVEs tagged to redhat / enterprise_linux_server_aus206 Critical, 353 High, 420 Medium, 70 Low, 0 Unrated.

CVE-2015-3147

Published Jan 14, 2020

daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or pos…

CVSS 6.5 · Medium

CVE-2020-6851

Published Jan 13, 2020

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

CVSS 7.5 · High

CVE-2019-17024

Published Jan 8, 2020

Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough…

CVSS 8.8 · High

CVE-2019-17022

Published Jan 8, 2020

When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted dir…

CVSS 6.1 · Medium

CVE-2019-17017

Published Jan 8, 2020

Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run…

CVSS 8.8 · High

CVE-2019-17016

Published Jan 8, 2020

When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain…

CVSS 6.1 · Medium

CVE-2018-1311

Published Dec 18, 2019

The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained ve…

CVSS 8.1 · High

CVE-2019-10216

Published Nov 27, 2019

In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could ab…

CVSS 7.8 · High

CVE-2017-5333

Published Nov 4, 2019

Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process cras…

CVSS 7.8 · High

CVE-2017-5332

Published Nov 4, 2019

The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (proces…

CVSS 7.8 · High

CVE-2019-14287

Published Oct 17, 2019

In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invo…

CVSS 8.8 · High
evidence mentions
3
Buzz score
29.7
Public PoC observed
Showing 101-125 of 1,049 CVEsPage 5 of 42