CVE-2018-1111
- EPSS 89.18%
- Veröffentlicht 17.05.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:12
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network ab...
CVE-2018-1087
- EPSS 0.04%
- Veröffentlicht 15.05.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:09
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS ...
CVE-2018-10184
- EPSS 25.06%
- Veröffentlicht 09.05.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:58
An issue was discovered in HAProxy before 1.8.8. The incoming H2 frame length was checked against the max_frame_size setting instead of being checked against the bufsize. The max_frame_size only applies to outgoing traffic and not to incoming, so if ...
CVE-2017-2591
- EPSS 6.83%
- Veröffentlicht 30.04.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:47
389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or possibly unauthenticated, attacker c...
CVE-2018-10392
- EPSS 1.32%
- Veröffentlicht 26.04.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:19
mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a ...
CVE-2018-10393
- EPSS 0.27%
- Veröffentlicht 26.04.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:19
bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.
CVE-2018-1059
- EPSS 0.17%
- Veröffentlicht 24.04.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:05
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing v...
CVE-2018-1079
- EPSS 0.41%
- Veröffentlicht 12.04.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:08
pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd service did not properly sanitize the file name from the /remote/put_file query. If the /etc/booth dir...
CVE-2018-6914
- EPSS 2.37%
- Veröffentlicht 03.04.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:24
Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files vi...
CVE-2018-8777
- EPSS 1.86%
- Veröffentlicht 03.04.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:17
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with a crafted header to WEBrick server or a crafted body to WEBrick server/handler and cause a denial of...