Skip to main content

Vendor/product archive

redhat / enterprise_linux_server_eus CVEs

Beta · best-effort

620 CVEs tagged to redhat / enterprise_linux_server_eus172 Critical, 240 High, 187 Medium, 21 Low, 0 Unrated.

CVE-2016-1833

Published May 20, 2016

The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers…

CVSS 5.5 · Medium

CVE-2015-4643

Published May 16, 2016

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary cod…

CVSS 9.8 · Critical

CVE-2015-4605

Published May 16, 2016

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a ce…

CVSS 7.5 · High

CVE-2015-4604

Published May 16, 2016

The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a cer…

CVSS 7.5 · High

CVE-2015-4603

Published May 16, 2016

The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary c…

CVSS 9.8 · Critical

CVE-2015-4602

Published May 16, 2016

The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial…

CVSS 9.8 · Critical

CVE-2015-4598

Published May 16, 2016

PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary…

CVSS 6.5 · Medium

CVE-2015-3412

Published May 16, 2016

PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via cr…

CVSS 5.3 · Medium

CVE-2015-3411

Published May 16, 2016

PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary…

CVSS 6.5 · Medium

CVE-2016-3712

Published May 11, 2016

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mod…

CVSS 5.5 · Medium

CVE-2016-3717

Published May 5, 2016

The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-2109

Published May 5, 2016

The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2016-2108

Published May 5, 2016

The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memo…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1

CVE-2016-2107

Published May 5, 2016

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obt…

CVSS 5.9 · Medium
evidence mentions
10
Buzz score
32.0

CVE-2016-2106

Published May 5, 2016

Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (h…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2016-2105

Published May 5, 2016

Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (hea…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2015-4170

Published May 2, 2016

Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_do…

CVSS 4.7 · Medium

CVE-2016-0695

Published Apr 21, 2016

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related…

CVSS 5.9 · Medium

CVE-2010-5325

Published Apr 15, 2016

Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of service (memory corruption and c…

CVSS 9.8 · Critical
Showing 451-475 of 620 CVEsPage 19 of 25