CVE-2016-9578
- EPSS 3.47%
- Published 27.07.2018 21:29:00
- Last modified 21.11.2024 03:01:25
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
CVE-2016-9603
- EPSS 1.52%
- Published 27.07.2018 21:29:00
- Last modified 21.11.2024 03:01:29
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged...
CVE-2016-9577
- EPSS 3.86%
- Published 27.07.2018 20:29:00
- Last modified 21.11.2024 03:01:25
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
CVE-2017-15097
- EPSS 0.03%
- Published 27.07.2018 20:29:00
- Last modified 21.11.2024 03:14:03
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.
CVE-2017-15101
- EPSS 0.32%
- Published 27.07.2018 20:29:00
- Last modified 21.11.2024 03:14:04
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution.
CVE-2017-2616
- EPSS 0.06%
- Published 27.07.2018 19:29:00
- Last modified 21.11.2024 03:23:50
A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
CVE-2017-2618
- EPSS 0.05%
- Published 27.07.2018 19:29:00
- Last modified 21.11.2024 03:23:50
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
CVE-2017-2620
- EPSS 0.77%
- Published 27.07.2018 19:29:00
- Last modified 21.11.2024 03:23:50
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use t...
CVE-2017-2626
- EPSS 0.03%
- Published 27.07.2018 19:29:00
- Last modified 21.11.2024 03:23:51
It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.
CVE-2017-2633
- EPSS 0.56%
- Published 27.07.2018 19:29:00
- Last modified 21.11.2024 03:23:52
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use t...