CVE-2018-10914
- EPSS 3.87%
- Published 04.09.2018 14:29:00
- Last modified 21.11.2024 03:42:17
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks an...
CVE-2018-10923
- EPSS 0.91%
- Published 04.09.2018 14:29:00
- Last modified 21.11.2024 03:42:18
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs s...
CVE-2018-10907
- EPSS 2.11%
- Published 04.09.2018 13:29:11
- Last modified 21.11.2024 03:42:16
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume...
CVE-2018-10904
- EPSS 1.26%
- Published 04.09.2018 13:29:09
- Last modified 21.11.2024 03:42:16
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exp...
CVE-2018-16412
- EPSS 1.56%
- Published 03.09.2018 19:29:01
- Last modified 21.11.2024 03:52:41
ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the coders/psd.c ParseImageResourceBlocks function.
CVE-2018-16402
- EPSS 1.52%
- Published 03.09.2018 19:29:00
- Last modified 21.11.2024 03:52:40
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
CVE-2018-16062
- EPSS 0.09%
- Published 29.08.2018 03:29:00
- Last modified 21.11.2024 03:52:01
dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
CVE-2018-6556
- EPSS 0.04%
- Published 10.08.2018 15:29:01
- Last modified 21.11.2024 04:10:53
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also ...
CVE-2018-10916
- EPSS 0.71%
- Published 01.08.2018 14:29:00
- Last modified 21.11.2024 03:42:17
It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirr...
CVE-2016-9597
- EPSS 1.33%
- Published 30.07.2018 14:29:02
- Last modified 21.11.2024 03:01:28
It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression C...