Skip to main content

Vendor/product archive

redhat / enterprise_linux_server_eus CVEs

Beta · best-effort

620 CVEs tagged to redhat / enterprise_linux_server_eus172 Critical, 240 High, 187 Medium, 21 Low, 0 Unrated.

CVE-2017-2615

Published Jul 3, 2018

Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in…

CVSS 5.5 · Medium

CVE-2018-10850

Published Jun 13, 2018

389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load.…

CVSS 5.9 · Medium

CVE-2018-5185

Published Jun 11, 2018

Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

CVSS 6.5 · Medium

CVE-2018-5184

Published Jun 11, 2018

Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

CVSS 7.5 · High

CVE-2018-5183

Published Jun 11, 2018

Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operati…

CVSS 9.8 · Critical

CVE-2018-5178

Published Jun 11, 2018

A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or…

CVSS 8.1 · High

CVE-2018-5170

Published Jun 11, 2018

It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file typ…

CVSS 4.3 · Medium

CVE-2018-5168

Published Jun 11, 2018

Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to ins…

CVSS 5.3 · Medium

CVE-2018-5162

Published Jun 11, 2018

Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

CVSS 7.5 · High

CVE-2018-5161

Published Jun 11, 2018

Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

CVSS 4.3 · Medium

CVE-2018-5159

Published Jun 11, 2018

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lea…

CVSS 9.8 · Critical

CVE-2018-5158

Published Jun 11, 2018

The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be…

CVSS 8.8 · High

CVE-2018-5157

Published Jun 11, 2018

Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files r…

CVSS 7.5 · High

CVE-2018-5155

Published Jun 11, 2018

A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects…

CVSS 9.8 · Critical

CVE-2018-5154

Published Jun 11, 2018

A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability af…

CVSS 9.8 · Critical

CVE-2018-5150

Published Jun 11, 2018

Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and we presume that with enough eff…

CVSS 9.8 · Critical

CVE-2018-5146

Published Jun 11, 2018

An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and T…

CVSS 8.8 · High

CVE-2018-5145

Published Jun 11, 2018

Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited…

CVSS 9.8 · Critical

CVE-2018-5144

Published Jun 11, 2018

An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thun…

CVSS 7.3 · High

CVE-2018-5131

Published Jun 11, 2018

Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a c…

CVSS 5.9 · Medium

CVE-2018-5130

Published Jun 11, 2018

When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. This vulnerability affects Fire…

CVSS 8.8 · High

CVE-2018-5129

Published Jun 11, 2018

A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through mem…

CVSS 8.6 · High

CVE-2018-5127

Published Jun 11, 2018

A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vulnerability affects Thunderbird…

CVSS 8.8 · High

CVE-2018-5117

Published Jun 11, 2018

If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could…

CVSS 5.3 · Medium
Showing 176-200 of 620 CVEsPage 8 of 25