Skip to main content

Vendor/product archive

redhat / enterprise_linux_server_eus CVEs

Beta · best-effort

620 CVEs tagged to redhat / enterprise_linux_server_eus172 Critical, 240 High, 187 Medium, 21 Low, 0 Unrated.

CVE-2015-0192

Published Jul 2, 2015

Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to…

CVSS 9.8 · Critical

CVE-2015-4148

Published Jun 9, 2015

The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property is a string, which allows remo…

CVSS 5.0 · Medium

CVE-2015-4147

Published Jun 9, 2015

The SoapClient::__call method in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that __default_headers is an array, which allows…

CVSS 7.5 · High

CVE-2015-4026

Published Jun 9, 2015

The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote a…

CVSS 7.5 · High

CVE-2015-4025

Published Jun 9, 2015

PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypa…

CVSS 7.5 · High

CVE-2015-4024

Published Jun 9, 2015

Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote att…

CVSS 5.0 · Medium

CVE-2015-4022

Published Jun 9, 2015

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP servers to execute arbitrary code…

CVSS 7.5 · High

CVE-2015-4021

Published Jun 9, 2015

The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 does not verify that the first character of a filename is diffe…

CVSS 5.0 · Medium

CVE-2015-3330

Published Jun 9, 2015

The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows…

CVSS 6.8 · Medium

CVE-2015-3329

Published Jun 9, 2015

Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to…

CVSS 7.5 · High

CVE-2015-3307

Published Jun 9, 2015

The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (heap me…

CVSS 7.5 · High

CVE-2015-2783

Published Jun 9, 2015

ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information from process memory or cause a denial of…

CVSS 5.8 · Medium

CVE-2015-1863

Published Apr 28, 2015

Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via craf…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2015-1241

Published Apr 19, 2015

Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers…

CVSS 4.3 · Medium

CVE-2015-0251

Published Apr 8, 2015

The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protoco…

CVSS 4.0 · Medium

CVE-2015-0248

Published Apr 8, 2015

The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and…

CVSS 5.0 · Medium

CVE-2015-2787

Published Mar 30, 2015

Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remot…

CVSS 7.5 · High

CVE-2015-2348

Published Mar 30, 2015

The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a…

CVSS 5.0 · Medium

CVE-2015-2301

Published Mar 30, 2015

Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service…

CVSS 7.5 · High

CVE-2014-9675

Published Feb 8, 2015

bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer valu…

CVSS 5.0 · Medium

CVE-2014-9674

Published Feb 8, 2015

The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote att…

CVSS 7.5 · High

CVE-2014-9673

Published Feb 8, 2015

Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (heap-based buffer o…

CVSS 6.8 · Medium

CVE-2014-9671

Published Feb 8, 2015

Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and ap…

CVSS 4.3 · Medium

CVE-2014-9670

Published Feb 8, 2015

Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflo…

CVSS 4.3 · Medium
Showing 501-525 of 620 CVEsPage 21 of 25