CVE-2018-14522
- EPSS 0.45%
- Published 23.07.2018 08:29:00
- Last modified 21.11.2024 03:49:15
An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_pitch_set_unit in pitch/pitch.c, as demonstrated by aubionotes.
CVE-2018-14523
- EPSS 0.45%
- Published 23.07.2018 08:29:00
- Last modified 21.11.2024 03:49:15
An issue was discovered in aubio 0.4.6. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotes.
CVE-2018-10861
- EPSS 0.58%
- Published 10.07.2018 14:29:00
- Last modified 21.11.2024 03:42:09
A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be a...
CVE-2018-1128
- EPSS 1.27%
- Published 10.07.2018 14:29:00
- Last modified 21.11.2024 03:59:14
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authen...
CVE-2018-1129
- EPSS 0.39%
- Published 10.07.2018 14:29:00
- Last modified 21.11.2024 03:59:15
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Cep...
CVE-2018-1000613
- EPSS 4.62%
- Published 09.07.2018 20:29:00
- Last modified 12.05.2025 17:37:16
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT priv...
CVE-2018-10892
- EPSS 0.19%
- Published 06.07.2018 16:29:00
- Last modified 21.11.2024 03:42:14
The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightn...
CVE-2018-12910
- EPSS 5.21%
- Published 05.07.2018 18:29:00
- Last modified 21.11.2024 03:46:05
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
CVE-2018-13096
- EPSS 0.63%
- Published 03.07.2018 10:29:00
- Last modified 21.11.2024 03:46:25
An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.14. A denial of service (out-of-bounds memory access and BUG) can occur upon encountering an abnormal bitmap size when mounting a crafted f2fs image.
CVE-2018-13099
- EPSS 1.61%
- Published 03.07.2018 10:29:00
- Last modified 21.11.2024 03:46:26
An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A denial of service (out-of-bounds memory access and BUG) can occur for a modified f2fs filesystem image in which an inline inode contains an invalid reserved blkaddr.