Vulnerabilities > Redhat > Enterprise Linux > Medium

DATE CVE VULNERABILITY TITLE RISK
2008-05-08 CVE-2008-1615 Resource Management Errors vulnerability in Redhat Enterprise Linux and Enterprise Linux Desktop
Linux kernel 2.6.18, and possibly other versions, when running on AMD64 architectures, allows local users to cause a denial of service (crash) via certain ptrace calls.
local
low complexity
redhat amd CWE-399
4.9
2008-05-08 CVE-2007-5001 Resource Management Errors vulnerability in Redhat Enterprise Linux and Enterprise Linux Desktop
Linux kernel before 2.4.21 allows local users to cause a denial of service (kernel panic) via asynchronous input or output on a FIFO special file.
local
low complexity
redhat CWE-399
4.9
2008-02-26 CVE-2008-0597 Resource Management Errors vulnerability in Easy Software products Cups 1.1.17/1.1.22
Use-after-free vulnerability in CUPS before 1.1.22, and possibly other versions, allows remote attackers to cause a denial of service (crash) via crafted IPP packets.
network
low complexity
redhat easy-software-products CWE-399
5.0
2007-12-20 CVE-2007-6285 Configuration vulnerability in Redhat Enterprise Linux 4.0/5.0
The default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 4 and 5, does not specify the nodev mount option for the -hosts map, which allows local users to access "important devices" by operating a remote NFS server and creating special device files on that server, as demonstrated by the /dev/mem device.
local
high complexity
redhat CWE-16
6.2
2007-12-18 CVE-2007-6283 Information Exposure vulnerability in multiple products
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.
local
low complexity
redhat fedoraproject oracle centos CWE-200
4.9
2007-12-13 CVE-2007-5964 Configuration vulnerability in Redhat Enterprise Linux 5.0
The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/net filesystem) map, which allows local users to gain privileges via a setuid program on a remote NFS server.
local
redhat CWE-16
6.9
2007-12-03 CVE-2006-7226 Denial Of Service vulnerability in PCRE Perl Compatible Regular Expression Subpattern Memory Allocation
Perl-Compatible Regular Expression (PCRE) library before 6.7 does not properly calculate the compiled memory allocation for regular expressions that involve a quantified "subpattern containing a named recursion or subroutine reference," which allows context-dependent attackers to cause a denial of service (error or crash).
network
redhat
4.3
2007-11-30 CVE-2007-5494 Resource Management Errors vulnerability in Redhat Enterprise Linux 4.0/5.0
Memory leak in the Red Hat Content Accelerator kernel patch in Red Hat Enterprise Linux (RHEL) 4 and 5 allows local users to cause a denial of service (memory consumption) via a large number of open requests involving O_ATOMICLOOKUP.
local
low complexity
redhat CWE-399
4.9
2007-10-23 CVE-2007-4574 Local Denial Of Service vulnerability in Redhat Enterprise Linux 5.0
Unspecified vulnerability in the "stack unwinder fixes" in kernel in Red Hat Enterprise Linux 5, when running on AMD64 and Intel 64, allows local users to cause a denial of service via unknown vectors.
local
redhat amd intel
4.7
2007-09-14 CVE-2007-3739 Buffer Errors vulnerability in Redhat Enterprise Linux 5.0
mm/mmap.c in the hugetlb kernel, when run on PowerPC systems, does not prevent stack expansion from entering into reserved kernel page memory, which allows local users to cause a denial of service (OOPS) via unspecified vectors.
4.7