Vulnerabilities > Redhat > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-03-09 CVE-2016-9585 Deserialization of Untrusted Data vulnerability in Redhat Jboss Enterprise Application Platform 5.0.0
Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes the credentials passed to it.
network
high complexity
redhat CWE-502
5.3
2018-03-07 CVE-2018-7740 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The resv_map_release function in mm/hugetlb.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (BUG) via a crafted application that makes mmap system calls and has a large pgoff argument to the remap_file_pages system call.
local
low complexity
linux redhat debian canonical CWE-119
5.5
2018-03-06 CVE-2018-5729 NULL Pointer Dereference vulnerability in multiple products
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagged data that is internal to the database module.
network
low complexity
mit fedoraproject debian redhat CWE-476
4.7
2018-03-06 CVE-2018-7727 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
An issue was discovered in ZZIPlib 0.13.68.
network
low complexity
zziplib-project redhat CWE-772
6.5
2018-03-06 CVE-2018-7726 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
An issue was discovered in ZZIPlib 0.13.68.
network
low complexity
zziplib-project canonical redhat CWE-119
6.5
2018-03-06 CVE-2018-7725 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
An issue was discovered in ZZIPlib 0.13.68.
network
low complexity
zziplib-project canonical redhat CWE-119
6.5
2018-03-06 CVE-2018-1062 Improper Cross-boundary Removal of Sensitive Data vulnerability in Redhat Ovirt-Engine
A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed by oVirt, could cause a disk to be incompletely zeroed when removed from a VM.
network
high complexity
redhat CWE-212
5.3
2018-03-02 CVE-2018-7642 NULL Pointer Dereference vulnerability in multiple products
The swap_std_reloc_in function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (aout_32_swap_std_reloc_out NULL pointer dereference and application crash) via a crafted ELF file, as demonstrated by objcopy.
local
low complexity
gnu redhat CWE-476
5.5
2018-03-02 CVE-2018-1063 Link Following vulnerability in multiple products
Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity to change the SELinux context of an arbitrary file to a context with few restrictions.
local
low complexity
redhat selinux-project CWE-59
4.4
2018-02-28 CVE-2018-7569 Integer Underflow (Wrap or Wraparound) vulnerability in multiple products
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (integer underflow or overflow, and application crash) via an ELF file with a corrupt DWARF FORM block, as demonstrated by nm.
local
low complexity
gnu redhat CWE-191
5.5