The Vigil@nce team watches public vulnerabilities impacting your computers, and then offers security solutions, a vigilance database and tools to fix them.

Computer vulnerabilities of RHEL

Squid: assertion error via Large HTTP Response
An attacker can use an HTTP reply containing a large header, to force an assertion error in Squid, in order to trigger a denial of service...
CVE-2016-2569, CVE-2016-2570, CVE-2016-2571, CVE-2016-2572, DSA-3522-1, openSUSE-SU-2016:2081-1, RHSA-2016:2600-02, SQUID-2016:2, SUSE-SU-2016:1996-1, SUSE-SU-2016:2089-1, USN-2921-1, USN-3557-1, VIGILANCE-VUL-19018
libssh2: generation of ephemeral key of 128 bits
An attacker can act as a Man-in-the-Middle on an application linked with libssh2, in because some ephemeral keys are too short...
bulletinoct2016, CVE-2016-0787, DSA-3487-1, FEDORA-2016-215a2219b1, FEDORA-2016-7942ee2cc5, openSUSE-SU-2016:0639-1, RHSA-2016:0428-01, SA120, SB10156, SOL21531693, VIGILANCE-VUL-19013
libssh: generation of ephemeral key of 128 bits
An attacker can act as a Man-in-the-Middle on an application linked with libssh, in because some ephemeral keys are too short...
CVE-2016-0739, DSA-3488-1, FEDORA-2016-d9f950c779, FEDORA-2016-dc9e8da03c, openSUSE-SU-2016:0722-1, openSUSE-SU-2016:0880-1, RHSA-2016:0566-01, SOL57255643, SSA:2016-057-01, USN-2912-1, VIGILANCE-VUL-19010
libxml2: unreachable memory reading via xmlDictAddString
An attacker can invite the victim to open a malicious XML document, with an application linked with libxml2, to force a read at an invalid address in the xmlDictAddString() function, in order to trigger a denial of service...
CERTFR-2017-AVI-012, CVE-2016-1839, DLA-503-1, DSA-2019-197, DSA-3593-1, FEDORA-2017-a3a47973eb, FEDORA-2017-be8574d593, HT206567, HT206568, JSA10770, K26422113, openSUSE-SU-2016:1594-1, openSUSE-SU-2016:1595-1, openSUSE-SU-2017:1510-1, RHSA-2016:1292-01, SA129, SB10170, SPL-119440, SPL-121159, SPL-123095, SUSE-SU-2016:1538-1, SUSE-SU-2016:1604-1, TNS-2017-03, USN-2994-1, VIGILANCE-VUL-19007
libxml2: unreachable memory reading via xmlNextChar
An attacker can invite the victim to open a malicious XML document, with an application linked with libxml2, to force a read at an invalid address in the xmlDictAddString() function, in order to trigger a denial of service...
758606, bulletinjul2016, CERTFR-2017-AVI-012, CERTFR-2017-AVI-022, CVE-2016-1833, DLA-503-1, DSA-2019-197, DSA-3593-1, FEDORA-2017-a3a47973eb, FEDORA-2017-be8574d593, HT206567, HT206568, JSA10770, JSA10774, openSUSE-SU-2016:1594-1, openSUSE-SU-2016:1595-1, RHSA-2016:1292-01, SA129, SB10170, SPL-119440, SPL-121159, SPL-123095, SUSE-SU-2016:1538-1, SUSE-SU-2016:1604-1, TNS-2017-03, USN-2994-1, VIGILANCE-VUL-19006
libxml2: unreachable memory reading via xmlParseEndTag2
An attacker can invite the victim to open a malicious XML document, with an application linked with libxml2, to force a read at an invalid address in the xmlParseEndTag2() function, in order to trigger a denial of service...
758588, 758589, CERTFR-2017-AVI-012, CVE-2016-1838, DLA-503-1, DSA-2019-197, DSA-3593-1, FEDORA-2017-a3a47973eb, FEDORA-2017-be8574d593, HT206567, HT206568, JSA10770, K71926235, openSUSE-SU-2016:1594-1, openSUSE-SU-2016:1595-1, RHSA-2016:1292-01, SA129, SB10170, SPL-119440, SPL-121159, SPL-123095, SUSE-SU-2016:1538-1, SUSE-SU-2016:1604-1, TNS-2017-03, USN-2994-1, VIGILANCE-VUL-19005
Apache Tomcat: read-write access via setGlobalContext
An attacker, who is allowed to upload a malicious web application on the service, can bypass access restrictions via setGlobalContext of Apache Tomcat, in order to read or alter data...
1980693, c05150442, c05324755, cpuapr2017, cpuoct2017, CVE-2016-0763, DSA-3530-1, DSA-3552-1, DSA-3609-1, FEDORA-2016-e6651efbaf, HPSBGN03669, HPSBUX03606, NTAP-20180531-0001, openSUSE-SU-2016:0865-1, RHSA-2016:1087-01, RHSA-2016:1088-01, RHSA-2016:1089-01, RHSA-2016:2599-02, RHSA-2016:2807-01, RHSA-2016:2808-01, SUSE-SU-2016:0769-1, SUSE-SU-2016:0822-1, USN-3024-1, VIGILANCE-VUL-18999
Apache Tomcat: code execution via PersistentManager
An attacker, who is allowed to upload a malicious web application on the service, can use the PersistentManager of Apache Tomcat, in order to run code...
1980693, 1983989, c05054964, c05150442, cpuapr2017, cpujul2018, cpuoct2017, CVE-2016-0714, DSA-3530-1, DSA-3552-1, DSA-3609-1, HPSBUX03561, HPSBUX03606, K30971148, NTAP-20180531-0001, openSUSE-SU-2016:0865-1, RHSA-2016:1087-01, RHSA-2016:1088-01, RHSA-2016:1089-01, RHSA-2016:2045-01, RHSA-2016:2599-02, RHSA-2016:2807-01, RHSA-2016:2808-01, SOL30971148, SUSE-SU-2016:0769-1, SUSE-SU-2016:0822-1, SUSE-SU-2016:0839-1, USN-3024-1, VIGILANCE-VUL-18998
Apache Tomcat: information disclosure via StatusManagerServlet
An attacker, who is allowed to upload a malicious web application on the service, can use a vulnerability in StatusManagerServlet of Apache Tomcat, in order to obtain sensitive information...
1980693, 1983989, c05054964, c05150442, cpuapr2017, cpujul2018, cpuoct2017, CVE-2016-0706, DSA-3530-1, DSA-3552-1, DSA-3609-1, HPSBUX03561, HPSBUX03606, K30971148, NTAP-20180531-0001, openSUSE-SU-2016:0865-1, RHSA-2016:1087-01, RHSA-2016:1088-01, RHSA-2016:1089-01, RHSA-2016:2045-01, RHSA-2016:2599-02, RHSA-2016:2807-01, RHSA-2016:2808-01, SOL30971148, SUSE-SU-2016:0769-1, SUSE-SU-2016:0822-1, SUSE-SU-2016:0839-1, USN-3024-1, VIGILANCE-VUL-18997
Apache Tomcat: Cross Site Request Forgery via Manager / Host Manager
An attacker can trigger a Cross Site Request Forgery of Apache Tomcat, in order to force the victim to perform operations...
1980693, c05150442, cpuapr2017, cpujul2018, cpuoct2017, CVE-2015-5351, DSA-3530-1, DSA-3552-1, DSA-3609-1, HPSBUX03606, NTAP-20180531-0001, openSUSE-SU-2016:0865-1, RHSA-2016:1087-01, RHSA-2016:1088-01, RHSA-2016:1089-01, RHSA-2016:2599-02, RHSA-2016:2807-01, RHSA-2016:2808-01, SUSE-SU-2016:0769-1, SUSE-SU-2016:0822-1, USN-3024-1, VIGILANCE-VUL-18996
Our database contains other pages. You can request a free trial to read them.

Display information about RHEL: