Vulnerabilities > Redhat

DATE CVE VULNERABILITY TITLE RISK
2007-11-26 CVE-2007-6131 Configuration vulnerability in Redhat Fedora Core F7
buttonpressed.sh in scanbuttond 0.2.3 allows local users to overwrite arbitrary files via a symlink attack on the (1) scan.pnm and (2) scan.jpg temporary files.
local
low complexity
redhat CWE-16
2.1
2007-11-14 CVE-2007-4136 Remote Denial Of Service vulnerability in Redhat Conga 0.10.0
The ricci daemon in Red Hat Conga 0.10.0 allows remote attackers to cause a denial of service (loss of new connections) by repeatedly sending data or attempting connections.
network
low complexity
redhat
5.0
2007-11-10 CVE-2007-4570 Improper Input Validation vulnerability in Redhat Mcstrans 0.2.3
Algorithmic complexity vulnerability in the MCS translation daemon in mcstrans 0.2.3 allows local users to cause a denial of service (temporary daemon outage) via a large range of compartments in sensitivity labels.
local
redhat CWE-20
1.9
2007-11-08 CVE-2007-4129 Link Following vulnerability in Fedoraproject Coolkey 1.1.0
CoolKey 1.1.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files in the /tmp/.pk11ipc1/ directory.
3.3
2007-11-07 CVE-2007-5116 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicode (UTF) characters in a regular expression.
7.5
2007-11-06 CVE-2007-4994 Credentials Management vulnerability in Redhat Certificate Server 7.2
Certificate Server 7.2 in Red Hat Certificate System (RHCS) does not properly handle new revocations that occur while a Certificate Revocation List (CRL) is being generated, which might prevent certain revoked certificates from appearing on the CRL quickly and allow users with revoked certificates to bypass the intended CRL.
network
low complexity
redhat CWE-255
7.5
2007-10-23 CVE-2007-4574 Local Denial Of Service vulnerability in Redhat Enterprise Linux 5.0
Unspecified vulnerability in the "stack unwinder fixes" in kernel in Red Hat Enterprise Linux 5, when running on AMD64 and Intel 64, allows local users to cause a denial of service via unknown vectors.
local
redhat amd intel
4.7
2007-10-11 CVE-2007-5365 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.
local
low complexity
debian openbsd redhat sun ubuntu CWE-119
7.2
2007-10-01 CVE-2007-5159 Permissions, Privileges, and Access Controls vulnerability in Ntfs-3G
The ntfs-3g package before 1.913-2.fc7 in Fedora 7, and an ntfs-3g package in Ubuntu 7.10/Gutsy, assign incorrect permissions (setuid root) to mount.ntfs-3g, which allows local users with fuse group membership to read from and write to arbitrary block devices, possibly involving a file descriptor leak.
local
low complexity
redhat ntfs-3g ubuntu CWE-264
4.6
2007-09-25 CVE-2007-5079 Unspecified vulnerability in Redhat Linux 4.0
Red Hat Enterprise Linux 4 does not properly compile and link gdm with tcp_wrappers on x86_64 platforms, which might allow remote attackers to bypass intended access restrictions.
network
redhat
6.0