- EPSS 0.03%
- Published 23.10.2020 13:15:16
- Last modified 21.11.2024 05:20:52
In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can obser...
CVE-2018-20002
- EPSS 0.49%
- Published 10.12.2018 02:29:00
- Last modified 21.11.2024 04:00:43
The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a denial of service (memory consumption), as demo...
CVE-2018-19931
- EPSS 0.42%
- Published 07.12.2018 07:29:00
- Last modified 21.11.2024 03:58:49
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h because the number of program headers is not r...
CVE-2018-19932
- EPSS 0.32%
- Published 07.12.2018 07:29:00
- Last modified 21.11.2024 03:58:50
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.
CVE-2018-15473
- EPSS 90.29%
- Published 17.08.2018 19:29:00
- Last modified 21.11.2024 03:50:53
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-...
CVE-2018-2825
- EPSS 1.13%
- Published 19.04.2018 02:29:05
- Last modified 06.05.2025 15:15:56
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols t...
CVE-2018-2826
- EPSS 2.92%
- Published 19.04.2018 02:29:05
- Last modified 06.05.2025 15:15:56
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols t...
CVE-2018-6485
- EPSS 0.73%
- Published 01.02.2018 14:29:00
- Last modified 21.11.2024 04:10:45
An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to ...
CVE-2016-10708
- EPSS 3.2%
- Published 21.01.2018 22:29:00
- Last modified 21.11.2024 02:44:33
sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.
CVE-2016-6904
- EPSS 0.23%
- Published 11.12.2017 15:29:00
- Last modified 20.04.2025 01:37:25
Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentication. This could allow an unauthenticated attacker to obtain authentication credentials.