CVE-2018-14648
- EPSS 4.25%
- Veröffentlicht 28.09.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:30
A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.
CVE-2018-11763
- EPSS 17.4%
- Veröffentlicht 25.09.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:58
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitiga...
CVE-2018-14645
- EPSS 0.23%
- Veröffentlicht 21.09.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:29
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
CVE-2016-7056
- EPSS 0.33%
- Veröffentlicht 10.09.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 02:57:22
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
- EPSS 0.6%
- Veröffentlicht 05.09.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:26
curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocat...
CVE-2018-16540
- EPSS 0.28%
- Veröffentlicht 05.09.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:56
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.
CVE-2018-16542
- EPSS 0.43%
- Veröffentlicht 05.09.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:56
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter.
CVE-2018-10930
- EPSS 1.35%
- Veröffentlicht 04.09.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:19
A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.
CVE-2018-10926
- EPSS 1.39%
- Veröffentlicht 04.09.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:19
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execute arbitrary code on a glusterfs server node.
CVE-2018-10928
- EPSS 1.65%
- Veröffentlicht 04.09.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:19
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing any...