VendorsRed Hatenterprise_linux_hpc_node_eus7.1
Vulnerabilities

Red Hat Enterprise Linux HPC Node Extended Update Support (EUS) 7.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

44CVEs
CVE-2015-2348
The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attackers to bypass intended extension restrictions and create files with unexpected names via a crafted second argument. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-7243.
Published 2015-03-30 · Modified
5.0EPSS 0.086
CVE-2014-9675
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
Published 2015-02-08 · Modified
5.0EPSS 0.042
CVE-2014-9670
Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first column and first row.
Published 2015-02-08 · Modified
4.3EPSS 0.042
CVE-2014-9671
Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PCF file with a 0xffffffff size value that is improperly incremented.
Published 2015-02-08 · Modified
4.3EPSS 0.035
← Prev2 / 2