Vulnerabilities
Vulnerable Software
Redhat:  Security Vulnerabilities
389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to read the default Access Control Instructions.
CVSS Score
7.5
EPSS Score
0.002
Published
2017-06-08
SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.
CVSS Score
9.8
EPSS Score
0.006
Published
2017-06-08
The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.
CVSS Score
8.8
EPSS Score
0.005
Published
2017-06-08
The PooledInvokerServlet in JBoss EAP 4.x and 5.x allows remote attackers to execute arbitrary code via a crafted serialized payload.
CVSS Score
9.8
EPSS Score
0.018
Published
2017-06-08
CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.
CVSS Score
7.5
EPSS Score
0.002
Published
2017-06-08
ManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code.
CVSS Score
8.8
EPSS Score
0.015
Published
2017-06-08
The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack.
CVSS Score
7.8
EPSS Score
0.0
Published
2017-06-07
smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.
CVSS Score
6.5
EPSS Score
0.04
Published
2017-06-06
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.
CVSS Score
8.8
EPSS Score
0.487
Published
2017-06-06
MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by logging in with an empty password and delete information which can cause a Denial of Service.
CVSS Score
5.5
EPSS Score
0.0
Published
2017-06-06


Contact Us

Shodan ® - All rights reserved