CVE-2018-1120
- EPSS 0.99%
- Published 20.06.2018 13:29:00
- Last modified 21.11.2024 03:59:13
A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containing command line arguments (or environment strings), an attacker can cause utilities from psutils or procps (such as ps, w...
CVE-2018-1073
- EPSS 0.27%
- Published 19.06.2018 12:29:00
- Last modified 21.11.2024 03:59:07
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
CVE-2018-5848
- EPSS 0.13%
- Published 12.06.2018 20:29:00
- Last modified 21.11.2024 04:09:32
In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS...
CVE-2018-5803
- EPSS 0.06%
- Published 12.06.2018 16:29:00
- Last modified 21.11.2024 04:09:26
In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function (net/sctp/sm_make_chunk.c) when handling SCTP packets length can be exploited to cause a kernel crash.
CVE-2018-1067
- EPSS 0.62%
- Published 21.05.2018 17:29:00
- Last modified 21.11.2024 03:59:06
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization...
CVE-2018-11237
- EPSS 0.59%
- Published 18.05.2018 16:29:00
- Last modified 21.11.2024 03:42:58
An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupper.
CVE-2018-11236
- EPSS 0.89%
- Published 18.05.2018 16:29:00
- Last modified 21.11.2024 03:42:57
stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer over...
CVE-2018-1118
- EPSS 0.11%
- Published 10.05.2018 22:29:00
- Last modified 21.11.2024 03:59:13
Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This can allow local privileged users to read some kernel ...
CVE-2018-10675
- EPSS 0.04%
- Published 02.05.2018 18:29:00
- Last modified 21.11.2024 03:41:49
The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.
CVE-2018-10237
- EPSS 3.26%
- Published 26.04.2018 21:29:00
- Last modified 21.11.2024 03:41:04
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray...