Redhat
Redhat Enterprise Linux HPC Node EUS: vulnerabilidades y CVE
Redhat Enterprise Linux HPC Node EUS tiene 81 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 7 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE81
Últimos 12 meses0
Críticas7
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2016-3718 | Media (5.5) | 77% | ⚠ Explotación activa | 5 may 2016 | The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image. |
| CVE-2016-3715 | Media (5.5) | 75% | ⚠ Explotación activa | 5 may 2016 | The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2015-3149 | Media (5.5) | 0.38% | — | 25 jul 2017 | The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack. |
| CVE-2015-5300 | Alta (7.5) | 9.1% | — | 21 jul 2017 | The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time… |
| CVE-2016-7166 | Media (5.5) | 1.6% | — | 21 sept 2016 | libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file. |
| CVE-2016-5844 | Media (6.5) | 4.1% | — | 21 sept 2016 | Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file. |
| CVE-2016-5418 | Alta (7.5) | 4.7% | — | 21 sept 2016 | The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file. |
| CVE-2016-4809 | Alta (7.5) | 4.8% | — | 21 sept 2016 | The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large… |
| CVE-2016-4302 | Alta (7.8) | 4.8% | — | 21 sept 2016 | Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary. |
| CVE-2016-4300 | Alta (7.8) | 4.9% | — | 21 sept 2016 | Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams,… |
| CVE-2016-5388 | Alta (8.1) | 51% | — | 19 jul 2016 | Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the… |
| CVE-2016-4470 | Media (5.5) | 0.58% | — | 27 jun 2016 | The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system… |
| CVE-2016-0758 | Alta (7.8) | 0.40% | — | 27 jun 2016 | Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data. |
| CVE-2016-3698 | Alta (8.1) | 3.8% | — | 13 jun 2016 | libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of… |
| CVE-2016-2150 | Alta (7.1) | 0.36% | — | 9 jun 2016 | SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261. |
| CVE-2016-0749 | Crítica (9.8) | 8.5% | — | 9 jun 2016 | The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a… |
| CVE-2015-5261 | Alta (7.1) | 0.49% | — | 7 jun 2016 | Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation. |
| CVE-2015-5260 | Alta (7.8) | 0.57% | — | 7 jun 2016 | Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands… |
| CVE-2015-4605 | Alta (7.5) | 7.4% | — | 16 may 2016 | The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote… |
| CVE-2015-4604 | Alta (7.5) | 7.4% | — | 16 may 2016 | The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows… |
| CVE-2015-4603 | Crítica (9.8) | 11% | — | 16 may 2016 | The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related… |
| CVE-2015-4602 | Crítica (9.8) | 11% | — | 16 may 2016 | The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or… |
| CVE-2015-4601 | Crítica (9.8) | 8.2% | — | 16 may 2016 | PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confusion" issues in (1)… |
| CVE-2015-4600 | Crítica (9.8) | 11% | — | 16 may 2016 | The SoapClient implementation in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an… |
| CVE-2015-4599 | Crítica (9.8) | 11% | — | 16 may 2016 | The SoapFault::__toString method in ext/soap/soap.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information, cause a denial of service (application… |
| CVE-2015-4598 | Media (6.5) | 3.9% | — | 16 may 2016 | PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an… |
| CVE-2015-3412 | Media (5.3) | 4.1% | — | 16 may 2016 | PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via crafted input to an application that calls… |
| CVE-2015-3411 | Media (6.5) | 3.4% | — | 16 may 2016 | PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an… |
| CVE-2016-3718 | Media (5.5) | 77% | ⚠ Explotación activa | 5 may 2016 | The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image. |
| CVE-2016-3717 | Media (5.5) | 20% | — | 5 may 2016 | The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image. |
| CVE-2016-3716 | Baja (3.3) | 11% | — | 5 may 2016 | The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image. |
| CVE-2016-3715 | Media (5.5) | 75% | ⚠ Explotación activa | 5 may 2016 | The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. |
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 238Linux · 230