CVE-2017-12173
- EPSS 0.47%
- Published 27.07.2018 16:29:00
- Last modified 21.11.2024 03:08:59
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a gi...
CVE-2017-12151
- EPSS 2.1%
- Published 27.07.2018 12:29:00
- Last modified 21.11.2024 03:08:56
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attac...
CVE-2017-18344
- EPSS 10.16%
- Published 26.07.2018 19:29:00
- Last modified 21.11.2024 03:19:53
The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly validate the sigevent->sigev_notify field, which leads to out-of-bounds access in the show_timer function (called when /proc/$PID...
CVE-2018-10901
- EPSS 0.15%
- Published 26.07.2018 17:29:00
- Last modified 21.11.2024 03:42:15
A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the previous host value, but instead sets it to 64KB. With a corrupted GDT limit a host's userspace code has an ability to place malicious...
CVE-2018-2952
- EPSS 0.06%
- Published 18.07.2018 13:29:02
- Last modified 21.11.2024 04:04:49
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171; JRockit: R28.3.18. Difficult t...
CVE-2018-2767
- EPSS 0.28%
- Published 18.07.2018 13:29:00
- Last modified 21.11.2024 04:04:24
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Difficult to exploit vulnerability allows low ...
CVE-2018-14354
- EPSS 3.67%
- Published 17.07.2018 17:29:00
- Last modified 21.11.2024 03:48:53
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with a manual subscription or unsubscripti...
CVE-2018-14357
- EPSS 3.31%
- Published 17.07.2018 17:29:00
- Last modified 21.11.2024 03:48:54
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription.
CVE-2018-14362
- EPSS 2.42%
- Published 17.07.2018 17:29:00
- Last modified 21.11.2024 03:48:55
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.
CVE-2018-3693
- EPSS 0.92%
- Published 10.07.2018 21:29:01
- Last modified 21.11.2024 04:05:53
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.