CVE-2018-10913
- EPSS 0.96%
- Veröffentlicht 04.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:17
An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.
CVE-2018-10914
- EPSS 4.33%
- Veröffentlicht 04.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:17
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks an...
CVE-2018-10923
- EPSS 1.21%
- Veröffentlicht 04.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:18
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs s...
CVE-2018-10907
- EPSS 2.06%
- Veröffentlicht 04.09.2018 13:29:11
- Zuletzt bearbeitet 21.11.2024 03:42:16
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume...
CVE-2018-10904
- EPSS 1.21%
- Veröffentlicht 04.09.2018 13:29:09
- Zuletzt bearbeitet 21.11.2024 03:42:16
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exp...
CVE-2018-16435
- EPSS 0.45%
- Veröffentlicht 04.09.2018 00:29:02
- Zuletzt bearbeitet 21.11.2024 03:52:44
Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile...
CVE-2018-16430
- EPSS 1.36%
- Veröffentlicht 04.09.2018 00:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:44
GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.
CVE-2018-16402
- EPSS 1.96%
- Veröffentlicht 03.09.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:40
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
CVE-2018-16335
- EPSS 1.92%
- Veröffentlicht 02.09.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:32
newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIF...
CVE-2018-16336
- EPSS 0.3%
- Veröffentlicht 02.09.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:33
Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, a different vulnerability than CVE-2018-10999.