Redhat
Redhat Enterprise Linux FOR Scientific Computing: vulnerabilidades y CVE
Redhat Enterprise Linux FOR Scientific Computing tiene 71 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 9 figuran en el catálogo de explotación activa de CISA.
CVE71
Últimos 12 meses0
Críticas4
Explotadas activamente9
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-4034 | Alta (7.8) | 94% | ⚠ Explotación activa | 28 ene 2022 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined… |
| CVE-2019-8720 | Alta (8.8) | 1.6% | ⚠ Explotación activa | 6 mar 2023 | A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption… |
| CVE-2017-12615 | Alta (8.1) | 100% | ⚠ Explotación activa | 19 sept 2017 | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a… |
| CVE-2019-11043 | Crítica (9.8) | 100% | ⚠ Explotación activa | 28 oct 2019 | In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI… |
| CVE-2013-1675 | Media (6.5) | 6.7% | ⚠ Explotación activa | 16 may 2013 | Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and… |
| CVE-2015-4902 | Media (5.3) | 14% | ⚠ Explotación activa | 22 oct 2015 | Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment. |
| CVE-2014-6271 | Crítica (9.8) | 100% | ⚠ Explotación activa | 24 sept 2014 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by… |
| CVE-2014-7169 | Crítica (9.8) | 100% | ⚠ Explotación activa | 25 sept 2014 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown… |
| CVE-2021-40438 | Crítica (9) | 100% | ⚠ Explotación activa | 16 sept 2021 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-0409 | Alta (7.8) | 0.36% | — | 18 ene 2024 | A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that… |
| CVE-2024-0408 | Media (5.5) | 0.32% | — | 18 ene 2024 | A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a… |
| CVE-2023-5455 | Media (6.5) | 0.57% | — | 10 ene 2024 | A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as… |
| CVE-2023-5869 | Alta (8.8) | 4.3% | — | 10 dic 2023 | A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during… |
| CVE-2023-3972 | Alta (7.8) | 0.27% | — | 1 nov 2023 | A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the… |
| CVE-2023-5367 | Alta (7.8) | 0.62% | — | 25 oct 2023 | A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in… |
| CVE-2023-3899 | Alta (7.8) | 0.24% | — | 23 ago 2023 | A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that… |
| CVE-2023-0494 | Alta (7.8) | 0.90% | — | 27 mar 2023 | A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory.… |
| CVE-2019-8720 | Alta (8.8) | 1.6% | ⚠ Explotación activa | 6 mar 2023 | A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption… |
| CVE-2022-4254 | Alta (8.8) | 0.95% | — | 1 feb 2023 | sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters |
| CVE-2022-0330 | Alta (7.8) | 0.38% | — | 25 mar 2022 | A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their… |
| CVE-2021-3656 | Alta (8.8) | 0.66% | — | 4 mar 2022 | A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due… |
| CVE-2021-44142 | Alta (8.8) | 73% | — | 21 feb 2022 | The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17,… |
| CVE-2021-4091 | Alta (7.5) | 2.0% | — | 18 feb 2022 | A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker could send a series of search requests, forcing the server to behave unexpectedly, and crash. |
| CVE-2020-25719 | Alta (7.2) | 1.7% | — | 18 feb 2022 | A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not… |
| CVE-2020-25717 | Alta (8.1) | 1.6% | — | 18 feb 2022 | A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation. |
| CVE-2016-2124 | Media (5.9) | 1.8% | — | 18 feb 2022 | A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required. |
| CVE-2021-4034 | Alta (7.8) | 94% | ⚠ Explotación activa | 28 ene 2022 | A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined… |
| CVE-2021-40438 | Crítica (9) | 100% | ⚠ Explotación activa | 16 sept 2021 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
| CVE-2019-13763 | Media (4.3) | 1.2% | — | 10 dic 2019 | Insufficient policy enforcement in payments in Google Chrome prior to 79.0.3945.79 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. |
| CVE-2019-13762 | Baja (3.3) | 0.17% | — | 10 dic 2019 | Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code. |
| CVE-2019-13761 | Media (4.3) | 1.1% | — | 10 dic 2019 | Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. |
| CVE-2019-13759 | Media (4.3) | 1.3% | — | 10 dic 2019 | Incorrect security UI in interstitials in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page. |
| CVE-2019-13758 | Media (4.3) | 1.2% | — | 10 dic 2019 | Insufficient policy enforcement in navigation in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. |
| CVE-2019-13757 | Media (4.3) | 1.2% | — | 10 dic 2019 | Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. |
| CVE-2019-13756 | Media (4.3) | 1.3% | — | 10 dic 2019 | Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page. |
| CVE-2019-13755 | Media (4.3) | 1.2% | — | 10 dic 2019 | Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to disable extensions via a crafted HTML page. |
| CVE-2019-13754 | Media (4.3) | 1.3% | — | 10 dic 2019 | Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. |
| CVE-2019-13753 | Media (6.5) | 1.7% | — | 10 dic 2019 | Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. |
| CVE-2019-13752 | Media (6.5) | 1.7% | — | 10 dic 2019 | Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 238Linux · 230