- EPSS 5.54%
- Published 26.08.2018 16:29:00
- Last modified 21.11.2024 01:28:55
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control ...
CVE-2015-5160
- EPSS 0.15%
- Published 20.08.2018 21:29:00
- Last modified 21.11.2024 02:32:28
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
CVE-2018-10883
- EPSS 0.04%
- Published 30.07.2018 16:29:00
- Last modified 21.11.2024 03:42:13
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_dirty_metadata(), a denial of service, and a system crash by mounting and operating on a crafted ext4 filesystem image.
CVE-2017-7518
- EPSS 0.09%
- Published 30.07.2018 15:29:00
- Last modified 21.11.2024 03:32:03
A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug exception(#DB) being raised in the guest stack. A user/pr...
CVE-2017-15118
- EPSS 2.28%
- Published 27.07.2018 21:29:00
- Last modified 21.11.2024 03:14:06
A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack ...
CVE-2017-2618
- EPSS 0.05%
- Published 27.07.2018 19:29:00
- Last modified 21.11.2024 03:23:50
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
CVE-2018-10882
- EPSS 0.07%
- Published 27.07.2018 18:29:01
- Last modified 21.11.2024 03:42:13
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted ext4 filesystem image.
CVE-2017-2590
- EPSS 0.18%
- Published 27.07.2018 18:29:00
- Last modified 21.11.2024 03:23:47
A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable,...
CVE-2017-2623
- EPSS 0.28%
- Published 27.07.2018 18:29:00
- Last modified 21.11.2024 03:23:51
It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially...
CVE-2017-2625
- EPSS 0.03%
- Published 27.07.2018 18:29:00
- Last modified 21.11.2024 03:23:51
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing...