CVE-2018-10911
- EPSS 4.33%
- Veröffentlicht 04.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:17
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
CVE-2018-10913
- EPSS 0.96%
- Veröffentlicht 04.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:17
An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.
CVE-2018-10914
- EPSS 5.77%
- Veröffentlicht 04.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:17
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks an...
CVE-2018-10923
- EPSS 1.21%
- Veröffentlicht 04.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:18
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs s...
CVE-2018-10907
- EPSS 2.06%
- Veröffentlicht 04.09.2018 13:29:11
- Zuletzt bearbeitet 21.11.2024 03:42:16
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume...
CVE-2018-10904
- EPSS 1.21%
- Veröffentlicht 04.09.2018 13:29:09
- Zuletzt bearbeitet 21.11.2024 03:42:16
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exp...
CVE-2018-16435
- EPSS 0.45%
- Veröffentlicht 04.09.2018 00:29:02
- Zuletzt bearbeitet 21.11.2024 03:52:44
Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile...
CVE-2018-16430
- EPSS 1.36%
- Veröffentlicht 04.09.2018 00:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:44
GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.
CVE-2018-16402
- EPSS 1.45%
- Veröffentlicht 03.09.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:40
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
CVE-2018-16335
- EPSS 1.83%
- Veröffentlicht 02.09.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:32
newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIF...