CVE-2018-10322
- EPSS 0.05%
- Published 24.04.2018 06:29:00
- Last modified 21.11.2024 03:41:13
The xfs_dinode_verify function in fs/xfs/libxfs/xfs_inode_buf.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_ilock_attr_map_shared invalid pointer dereference) via a crafted xfs image.
CVE-2018-1088
- EPSS 5.68%
- Published 18.04.2018 16:29:00
- Last modified 21.11.2024 03:59:09
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
CVE-2018-8088
- EPSS 0.84%
- Published 20.03.2018 16:29:00
- Last modified 21.11.2024 04:13:14
org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1....
CVE-2018-1068
- EPSS 0.04%
- Published 16.03.2018 16:29:00
- Last modified 21.11.2024 03:59:06
A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privileged user to arbitrarily write to a limited range of kernel memory.
CVE-2018-7740
- EPSS 0.08%
- Published 07.03.2018 08:29:00
- Last modified 21.11.2024 04:12:38
The resv_map_release function in mm/hugetlb.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (BUG) via a crafted application that makes mmap system calls and has a large pgoff argument to the remap_file_pages syste...
CVE-2018-6927
- EPSS 0.06%
- Published 12.02.2018 19:29:01
- Last modified 21.11.2024 04:11:26
The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact by triggering a negative wake or requeue value.
CVE-2017-7525
- EPSS 77.34%
- Published 06.02.2018 15:29:00
- Last modified 21.11.2024 03:32:04
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the Obj...
CVE-2018-6485
- EPSS 0.73%
- Published 01.02.2018 14:29:00
- Last modified 21.11.2024 04:10:45
An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to ...
CVE-2018-1000001
- EPSS 44.63%
- Published 31.01.2018 14:29:00
- Last modified 21.11.2024 03:39:23
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.
CVE-2018-5750
- EPSS 0.04%
- Published 26.01.2018 19:29:00
- Last modified 21.11.2024 04:09:18
The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain sensitive address information by reading dmesg data from an SBS HC printk call.