CVE-2017-12171
- EPSS 1.54%
- Veröffentlicht 26.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:08:58
A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator could unintentionally allow any client to access a res...
CVE-2018-10901
- EPSS 0.15%
- Veröffentlicht 26.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:15
A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the previous host value, but instead sets it to 64KB. With a corrupted GDT limit a host's userspace code has an ability to place malicious...
CVE-2017-12163
- EPSS 27.33%
- Veröffentlicht 26.07.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:08:57
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to ...
CVE-2017-7562
- EPSS 0.26%
- Veröffentlicht 26.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:10
An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote attacker able to communicate with the KDC could potentially use this flaw to impersonate arbitrary prin...
CVE-2017-7537
- EPSS 0.08%
- Veröffentlicht 26.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:06
It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially use this flaw to bypass the regular authentication process and trick t...
CVE-2018-13988
- EPSS 0.84%
- Veröffentlicht 25.07.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:22
Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitab...
CVE-2018-10906
- EPSS 0.06%
- Veröffentlicht 24.07.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:16
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_...
CVE-2018-5007
- EPSS 6.12%
- Veröffentlicht 20.07.2018 19:29:02
- Zuletzt bearbeitet 21.11.2024 04:07:54
Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
CVE-2018-5008
- EPSS 6.87%
- Veröffentlicht 20.07.2018 19:29:02
- Zuletzt bearbeitet 21.11.2024 04:07:54
Adobe Flash Player 30.0.0.113 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
CVE-2018-3066
- EPSS 0.14%
- Veröffentlicht 18.07.2018 13:29:08
- Zuletzt bearbeitet 21.11.2024 04:05:05
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Difficult to exploit vulnerability allows high privileged a...