CVE-2018-11235
- EPSS 41.72%
- Veröffentlicht 30.05.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:57
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that ...
CVE-2018-1000199
- EPSS 0.17%
- Veröffentlicht 24.05.2018 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:39:55
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptra...
CVE-2018-1124
- EPSS 0.43%
- Veröffentlicht 23.05.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:13
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which co...
CVE-2018-1126
- EPSS 0.3%
- Veröffentlicht 23.05.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:14
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
CVE-2018-1111
- EPSS 89.38%
- Veröffentlicht 17.05.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:12
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network ab...
CVE-2018-1087
- EPSS 0.04%
- Veröffentlicht 15.05.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:09
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS ...
CVE-2018-10184
- EPSS 25.06%
- Veröffentlicht 09.05.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:58
An issue was discovered in HAProxy before 1.8.8. The incoming H2 frame length was checked against the max_frame_size setting instead of being checked against the bufsize. The max_frame_size only applies to outgoing traffic and not to incoming, so if ...
CVE-2017-2591
- EPSS 6.83%
- Veröffentlicht 30.04.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:47
389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or possibly unauthenticated, attacker c...
CVE-2018-10392
- EPSS 1.36%
- Veröffentlicht 26.04.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:19
mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a ...
CVE-2018-10393
- EPSS 0.35%
- Veröffentlicht 26.04.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:19
bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.