- EPSS 5.54%
- Published 26.08.2018 16:29:00
- Last modified 21.11.2024 01:28:55
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control ...
CVE-2018-14599
- EPSS 2.46%
- Published 24.08.2018 19:29:01
- Last modified 21.11.2024 03:49:23
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact.
CVE-2018-10858
- EPSS 7.56%
- Published 22.08.2018 17:29:00
- Last modified 21.11.2024 03:42:09
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and ...
CVE-2018-1139
- EPSS 1.73%
- Published 22.08.2018 14:29:00
- Last modified 21.11.2024 03:59:16
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between ...
CVE-2018-10844
- EPSS 0.19%
- Published 22.08.2018 13:29:00
- Last modified 21.11.2024 03:42:07
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data...
CVE-2018-10845
- EPSS 1.09%
- Published 22.08.2018 13:29:00
- Last modified 21.11.2024 03:42:07
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing dat...
CVE-2018-10846
- EPSS 0.01%
- Published 22.08.2018 13:29:00
- Last modified 21.11.2024 03:42:07
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain ...
CVE-2018-10902
- EPSS 0.08%
- Published 21.08.2018 19:29:00
- Last modified 21.11.2024 03:42:15
It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmi...
CVE-2018-1517
- EPSS 0.59%
- Published 20.08.2018 21:29:01
- Last modified 21.11.2024 03:59:57
A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data. IBM X-Force ID: 141681.
CVE-2018-1656
- EPSS 0.53%
- Published 20.08.2018 21:29:01
- Last modified 21.11.2024 04:00:08
The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files. IBM X-Force ID: 144882.