Skip to main content

Vendor/product archive

redhat / enterprise_linux_server_eus CVEs

Beta · best-effort

620 CVEs tagged to redhat / enterprise_linux_server_eus172 Critical, 240 High, 187 Medium, 21 Low, 0 Unrated.

CVE-2016-9583

Published Aug 1, 2018

An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.

CVSS 5.5 · Medium

CVE-2016-8635

Published Aug 1, 2018

It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private…

CVSS 5.3 · Medium

CVE-2017-7518

Published Jul 30, 2018

A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which lea…

CVSS 5.5 · Medium

CVE-2016-9603

Published Jul 27, 2018

A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update…

CVSS 5.5 · Medium

CVE-2016-9577

Published Jul 27, 2018

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap…

CVSS 7.5 · High

CVE-2017-2620

Published Jul 27, 2018

Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data…

CVSS 5.5 · Medium

CVE-2017-2618

Published Jul 27, 2018

A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by ca…

CVSS 5.5 · Medium

CVE-2017-2616

Published Jul 27, 2018

A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other pr…

CVSS 5.5 · Medium

CVE-2017-2625

Published Jul 27, 2018

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use infor…

CVSS 6.5 · Medium

CVE-2017-2590

Published Jul 27, 2018

A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authe…

CVSS 8.1 · High

CVE-2017-12151

Published Jul 27, 2018

A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the require…

CVSS 7.4 · High

CVE-2017-18344

Published Jul 26, 2018

The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly validate the sigevent->sigev_notify field, which leads to…

CVSS 5.5 · Medium

CVE-2018-14362

Published Jul 17, 2018

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as dem…

CVSS 9.8 · Critical

CVE-2018-14357

Published Jul 17, 2018

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the…

CVSS 9.8 · Critical

CVE-2018-14354

Published Jul 17, 2018

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the…

CVSS 9.8 · Critical
Showing 151-175 of 620 CVEsPage 7 of 25