CVE-2018-10875
- EPSS 0.06%
- Veröffentlicht 13.07.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:11
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.
CVE-2018-10892
- EPSS 0.19%
- Veröffentlicht 06.07.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:14
The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightn...
CVE-2017-2615
- EPSS 0.39%
- Veröffentlicht 03.07.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:50
Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to...
CVE-2018-10855
- EPSS 2.52%
- Veröffentlicht 03.07.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:08
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible ...
CVE-2018-10874
- EPSS 0.06%
- Veröffentlicht 02.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:11
In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.
CVE-2017-7466
- EPSS 2.88%
- Veröffentlicht 22.06.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:31:57
Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could...
CVE-2018-11218
- EPSS 18.92%
- Veröffentlicht 17.06.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:55
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.
CVE-2018-11219
- EPSS 3.48%
- Veröffentlicht 17.06.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:55
An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking.
CVE-2018-11806
- EPSS 0.03%
- Veröffentlicht 13.06.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:44:04
m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.
CVE-2018-3639
- EPSS 44.99%
- Veröffentlicht 22.05.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 04:05:48
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access vi...