CVE-2017-2634
- EPSS 3.66%
- Published 27.07.2018 19:29:00
- Last modified 21.11.2024 03:23:52
It was found that the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation before 2.6.22.17 used the IPv4-only inet_sk_rebuild_header() function for both IPv4 and IPv6 DCCP connections, which could result in memory corruptions. A...
CVE-2017-2590
- EPSS 0.18%
- Published 27.07.2018 18:29:00
- Last modified 21.11.2024 03:23:47
A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable,...
CVE-2017-2625
- EPSS 0.03%
- Published 27.07.2018 18:29:00
- Last modified 21.11.2024 03:23:51
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing...
CVE-2017-2640
- EPSS 1%
- Published 27.07.2018 18:29:00
- Last modified 21.11.2024 03:23:53
An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this flaw to crash Pidgin or execute arbitrary code in the context of the pidgin process.
CVE-2017-12173
- EPSS 0.47%
- Published 27.07.2018 16:29:00
- Last modified 21.11.2024 03:08:59
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a gi...
CVE-2017-18344
- EPSS 10.16%
- Published 26.07.2018 19:29:00
- Last modified 21.11.2024 03:19:53
The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly validate the sigevent->sigev_notify field, which leads to out-of-bounds access in the show_timer function (called when /proc/$PID...
CVE-2017-12150
- EPSS 19.42%
- Published 26.07.2018 18:29:00
- Last modified 21.11.2024 03:08:56
It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in pl...
CVE-2018-10878
- EPSS 0.04%
- Published 26.07.2018 18:29:00
- Last modified 21.11.2024 03:42:12
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image.
CVE-2018-10879
- EPSS 0.03%
- Published 26.07.2018 18:29:00
- Last modified 21.11.2024 03:42:12
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause a use-after-free in ext4_xattr_set_entry function and a denial of service or unspecified other impact may occur by renaming a file in a crafted ext4 filesystem image.
CVE-2018-10881
- EPSS 0.04%
- Published 26.07.2018 18:29:00
- Last modified 21.11.2024 03:42:12
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound access in ext4_get_group_info function, a denial of service, and a system crash by mounting and operating on a crafted ext4 filesystem image.