VYPR

Enterprise Linux Server

by Red Hat

CVEs (3,563)

  • CVE-2020-14356HigAug 19, 2020
    risk 0.51cvss 7.8epss 0.01

    A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.

  • CVE-2014-8141HigJan 31, 2020
    risk 0.51cvss 7.8epss 0.07

    Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

  • CVE-2014-8140HigJan 31, 2020
    risk 0.51cvss 7.8epss 0.07

    Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

  • CVE-2014-8139HigJan 31, 2020
    risk 0.51cvss 7.8epss 0.07

    Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

  • CVE-2014-7844HigJan 14, 2020
    risk 0.51cvss 7.8epss 0.02

    BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.

  • CVE-2012-2142HigJan 9, 2020
    risk 0.51cvss 7.8epss 0.03

    The error function in Error.cc in poppler before 0.21.4 allows remote attackers to execute arbitrary commands via a PDF containing an escape sequence for a terminal emulator.

  • CVE-2019-10216HigNov 27, 2019
    risk 0.51cvss 7.8epss 0.02

    In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and…

  • CVE-2011-1145HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.00

    The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.

  • CVE-2010-4661HigNov 13, 2019
    risk 0.51cvss 7.8epss 0.00

    udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.

  • CVE-2017-5333HigNov 4, 2019
    risk 0.51cvss 7.8epss 0.02

    Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.

  • CVE-2017-5332HigNov 4, 2019
    risk 0.51cvss 7.8epss 0.02

    The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.

  • CVE-2019-14835HigSep 17, 2019
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to…

  • CVE-2019-9518HigAug 13, 2019
    risk 0.51cvss 7.5epss 0.25

    Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE.…

  • CVE-2019-9517HigAug 13, 2019
    risk 0.51cvss 7.5epss 0.28

    Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually…

  • CVE-2019-14744HigAug 7, 2019
    risk 0.51cvss 7.8epss 0.04

    In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon…

  • CVE-2019-10168HigAug 2, 2019
    risk 0.51cvss 7.8epss 0.01

    The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe…

  • CVE-2019-10167HigAug 2, 2019
    risk 0.51cvss 7.8epss 0.01

    The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities.…

  • CVE-2019-10166HigAug 2, 2019
    risk 0.51cvss 7.8epss 0.00

    It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a…

  • CVE-2019-10161HigJul 30, 2019
    risk 0.51cvss 7.8epss 0.01

    It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the…

  • CVE-2019-13313HigJul 5, 2019
    risk 0.51cvss 7.8epss 0.00

    libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.

Page 43 of 179