CVE-2015-5160
- EPSS 0.15%
- Veröffentlicht 20.08.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 02:32:28
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
CVE-2018-15473
- EPSS 90.29%
- Veröffentlicht 17.08.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:50:53
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-...
CVE-2018-10873
- EPSS 1.27%
- Veröffentlicht 17.08.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:11
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its p...
CVE-2018-10915
- EPSS 1.56%
- Veröffentlicht 09.08.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:17
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untru...
CVE-2018-5390
- EPSS 3.92%
- Veröffentlicht 06.08.2018 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:08:43
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
CVE-2018-1336
- EPSS 16.09%
- Veröffentlicht 02.08.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:38
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and ...
CVE-2015-9262
- EPSS 2.37%
- Veröffentlicht 01.08.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 02:40:11
_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow.
CVE-2016-9583
- EPSS 0.32%
- Veröffentlicht 01.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:26
An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.
CVE-2018-10897
- EPSS 2.76%
- Veröffentlicht 01.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:15
A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the destination d...
CVE-2016-8654
- EPSS 0.23%
- Veröffentlicht 01.08.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 02:59:46
A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.