CVE-2019-1559
- EPSS 5.05%
- Veröffentlicht 27.02.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:36:48
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid...
CVE-2018-16881
- EPSS 2.77%
- Veröffentlicht 25.01.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:31
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
CVE-2018-14660
- EPSS 1.66%
- Veröffentlicht 01.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:32
A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitivel...
CVE-2018-14661
- EPSS 3.1%
- Veröffentlicht 31.10.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:32
It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vulnerable to a format string attack. A remote, authenticated attacker could use this flaw to cause remot...
CVE-2018-14654
- EPSS 2.09%
- Veröffentlicht 31.10.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:31
The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could exploit this via the 'GF_XATTROP_ENTRY_IN_KEY' xattrop to create arbitrary, empty files on t...
CVE-2018-14659
- EPSS 2.59%
- Veröffentlicht 31.10.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:31
The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr. A remote, authenticated attacker could exploit this by mounting a Gluster volume and repeatedly cal...
CVE-2018-17963
- EPSS 2.08%
- Veröffentlicht 09.10.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:17
qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.
CVE-2018-17958
- EPSS 1.21%
- Veröffentlicht 09.10.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:16
Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used.
CVE-2018-1114
- EPSS 0.68%
- Veröffentlicht 11.09.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:12
It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.
CVE-2018-10930
- EPSS 0.63%
- Veröffentlicht 04.09.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:19
A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.