CVE-2017-2633
- EPSS 0.56%
- Veröffentlicht 27.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:52
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use t...
CVE-2017-2634
- EPSS 3.66%
- Veröffentlicht 27.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:52
It was found that the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation before 2.6.22.17 used the IPv4-only inet_sk_rebuild_header() function for both IPv4 and IPv6 DCCP connections, which could result in memory corruptions. A...
CVE-2017-2590
- EPSS 0.18%
- Veröffentlicht 27.07.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:47
A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable,...
CVE-2017-2625
- EPSS 0.08%
- Veröffentlicht 27.07.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:51
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing...
CVE-2017-2640
- EPSS 0.73%
- Veröffentlicht 27.07.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:53
An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this flaw to crash Pidgin or execute arbitrary code in the context of the pidgin process.
CVE-2017-12173
- EPSS 0.45%
- Veröffentlicht 27.07.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:08:59
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a gi...
CVE-2017-12151
- EPSS 4.15%
- Veröffentlicht 27.07.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:08:56
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attac...
CVE-2017-18344
- EPSS 12.86%
- Veröffentlicht 26.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:53
The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly validate the sigevent->sigev_notify field, which leads to out-of-bounds access in the show_timer function (called when /proc/$PID...
CVE-2018-10901
- EPSS 0.16%
- Veröffentlicht 26.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:15
A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the previous host value, but instead sets it to 64KB. With a corrupted GDT limit a host's userspace code has an ability to place malicious...
CVE-2018-2952
- EPSS 0.11%
- Veröffentlicht 18.07.2018 13:29:02
- Zuletzt bearbeitet 21.11.2024 04:04:49
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171; JRockit: R28.3.18. Difficult t...