CVE-2018-10858
- EPSS 7.56%
- Veröffentlicht 22.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:09
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and ...
CVE-2015-5160
- EPSS 0.15%
- Veröffentlicht 20.08.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 02:32:28
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
CVE-2018-10873
- EPSS 1.27%
- Veröffentlicht 17.08.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:11
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its p...
CVE-2018-10915
- EPSS 1.56%
- Veröffentlicht 09.08.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:17
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untru...
CVE-2018-10908
- EPSS 0.32%
- Veröffentlicht 09.08.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:16
It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image, an attacker could cause the qemu-img process to consume unbounded amounts of memory of CPU time, ca...
CVE-2018-5390
- EPSS 3.92%
- Veröffentlicht 06.08.2018 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:08:43
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
CVE-2018-10897
- EPSS 2.76%
- Veröffentlicht 01.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:15
A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the destination d...
CVE-2017-15113
- EPSS 0.34%
- Veröffentlicht 27.07.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:05
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-level logs a...
CVE-2017-15119
- EPSS 1.55%
- Veröffentlicht 27.07.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:06
The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste CPU time on reading up to 4GB per request. A client ...
CVE-2018-10862
- EPSS 0.33%
- Veröffentlicht 27.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:10
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vulnerability.