CVE-2018-10767
- EPSS 0.85%
- Veröffentlicht 06.05.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:00
There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will l...
CVE-2018-10733
- EPSS 0.8%
- Veröffentlicht 04.05.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:56
There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.
CVE-2018-1104
- EPSS 0.44%
- Veröffentlicht 02.05.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:11
Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server.
CVE-2018-1101
- EPSS 0.46%
- Veröffentlicht 02.05.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:11
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization adm...