CVE-2015-5160
- EPSS 0.15%
- Published 20.08.2018 21:29:00
- Last modified 21.11.2024 02:32:28
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
CVE-2018-15473
- EPSS 90.29%
- Published 17.08.2018 19:29:00
- Last modified 21.11.2024 03:50:53
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-...
CVE-2018-10873
- EPSS 1.27%
- Published 17.08.2018 12:29:00
- Last modified 21.11.2024 03:42:11
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its p...
CVE-2018-10915
- EPSS 1.56%
- Published 09.08.2018 20:29:00
- Last modified 21.11.2024 03:42:17
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untru...
CVE-2018-5390
- EPSS 3.92%
- Published 06.08.2018 20:29:01
- Last modified 21.11.2024 04:08:43
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
CVE-2018-1336
- EPSS 16.09%
- Published 02.08.2018 14:29:00
- Last modified 21.11.2024 03:59:38
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and ...
CVE-2015-9262
- EPSS 2.37%
- Published 01.08.2018 23:29:00
- Last modified 21.11.2024 02:40:11
_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow.
CVE-2016-9583
- EPSS 0.32%
- Published 01.08.2018 17:29:00
- Last modified 21.11.2024 03:01:26
An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.
CVE-2018-10897
- EPSS 2.76%
- Published 01.08.2018 17:29:00
- Last modified 21.11.2024 03:42:15
A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the destination d...
CVE-2016-8654
- EPSS 0.23%
- Published 01.08.2018 16:29:00
- Last modified 21.11.2024 02:59:46
A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.