VYPR

Enterprise Linux Server

by Red Hat

CVEs (3,563)

  • CVE-2021-3569MedJun 3, 2021
    risk 0.36cvss 5.5epss 0.00

    A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SIGBUS (bad memory access) and termination of swtpm. The highest threat from this vulnerability is to system availability.

  • CVE-2021-30471MedMay 26, 2021
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary function in src/podofo/doc/PdfNamesTree.cpp can lead to a stack overflow.

  • CVE-2021-30470MedMay 26, 2021
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVariant() and PdfTokenizer::ReadDataType() functions can lead to a stack overflow.

  • CVE-2021-30469MedMay 26, 2021
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can cause a denial of service via a crafted PDF file.

  • CVE-2021-3421MedMay 19, 2021
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corruption. The highest threat from this vulnerability is to…

  • CVE-2020-27824MedMay 13, 2021
    risk 0.36cvss 5.5epss 0.02

    A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat from this vulnerability is to system availability.

  • CVE-2021-3505MedApr 19, 2021
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number…

  • CVE-2021-3446MedMar 25, 2021
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were used. Instead of returning the last IV it returned the…

  • CVE-2021-3443MedMar 25, 2021
    risk 0.36cvss 5.5epss 0.01

    A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.

  • CVE-2020-35522MedMar 9, 2021
    risk 0.36cvss 5.5epss 0.02

    In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a remote denial of service attack.

  • CVE-2020-35521MedMar 9, 2021
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service.

  • CVE-2020-27842MedJan 5, 2021
    risk 0.36cvss 5.5epss 0.01

    There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability.

  • CVE-2020-35507MedJan 4, 2021
    risk 0.36cvss 5.5epss 0.01

    There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application…

  • CVE-2020-14373MedSep 3, 2020
    risk 0.36cvss 5.5epss 0.00

    A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service.

  • CVE-2019-19338MedJul 13, 2020
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CPUs handle speculative execution of instructions when a TSX Asynchronous Abort (TAA) error occurs. When a guest is running on a host CPU affected by the TAA…

  • CVE-2020-10769MedJun 26, 2020
    risk 0.36cvss 5.5epss 0.00

    A buffer over-read flaw was found in RH kernel versions before 5.0 in crypto_authenc_extractkeys in crypto/authenc.c in the IPsec Cryptographic algorithm's module, authenc. When a payload longer than 4 bytes, and is not following 4-byte alignment boundary guidelines, it causes a…

  • CVE-2012-5644MedNov 25, 2019
    risk 0.36cvss 5.5epss 0.00

    libuser has information disclosure when moving user's home directory

  • CVE-2012-6136MedNov 20, 2019
    risk 0.36cvss 5.5epss 0.00

    tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.

  • CVE-2014-5118MedNov 18, 2019
    risk 0.36cvss 5.5epss 0.00

    Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability

  • CVE-2014-8181MedNov 6, 2019
    risk 0.36cvss 5.5epss 0.00

    The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.

Page 96 of 179