Vulnerabilities > Redhat

DATE CVE VULNERABILITY TITLE RISK
2017-09-05 CVE-2017-1000083 backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.
local
low complexity
gnome debian redhat
7.8
2017-08-31 CVE-2017-0902 Origin Validation Error vulnerability in multiple products
RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.
network
high complexity
rubygems debian canonical redhat CWE-346
8.1
2017-08-31 CVE-2017-0901 Improper Input Validation vulnerability in multiple products
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
network
low complexity
rubygems debian canonical redhat CWE-20
7.5
2017-08-31 CVE-2017-0900 Improper Input Validation vulnerability in multiple products
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.
network
low complexity
rubygems debian redhat CWE-20
7.5
2017-08-31 CVE-2017-0899 Code Injection vulnerability in multiple products
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.
network
low complexity
rubygems debian redhat CWE-94
critical
9.8
2017-08-31 CVE-2017-14064 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call.
network
low complexity
ruby-lang debian canonical redhat CWE-119
critical
9.8
2017-08-28 CVE-2014-8163 Path Traversal vulnerability in Redhat Satellite 5.0
Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.
network
low complexity
redhat CWE-22
6.5
2017-08-28 CVE-2014-8168 Improper Access Control vulnerability in Redhat Satellite 6.0
Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.
local
low complexity
redhat CWE-284
6.1
2017-08-28 CVE-2014-0141 Cross-site Scripting vulnerability in Redhat Satellite 6.0.3
Cross-site scripting (XSS) vulnerability in Red Hat Satellite 6.0.3.
network
low complexity
redhat CWE-79
6.1
2017-08-24 CVE-2015-5293 Improper Access Control vulnerability in Redhat Enterprise Virtualization Manager
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable.
network
high complexity
redhat CWE-284
5.9