CVE-2018-15473
- EPSS 90.36%
- Veröffentlicht 17.08.2018 19:29:00
- Zuletzt bearbeitet 17.12.2025 22:15:54
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-...
CVE-2018-15469
- EPSS 0.18%
- Veröffentlicht 17.08.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:50:52
An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either in the hypervisor or in Linux. Unfortunately, an ARM guest can still request v2 grant tables; they will simply not be properly set up, resulting in s...
CVE-2018-10873
- EPSS 1.27%
- Veröffentlicht 17.08.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:11
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its p...
CVE-2018-14567
- EPSS 0.58%
- Veröffentlicht 16.08.2018 20:29:02
- Zuletzt bearbeitet 21.11.2024 03:49:19
libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-201...
CVE-2018-14348
- EPSS 0.45%
- Veröffentlicht 14.08.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:52
libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.
CVE-2018-6553
- EPSS 0.15%
- Veröffentlicht 10.08.2018 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:10:53
The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-...
CVE-2018-10925
- EPSS 0.4%
- Veröffentlicht 09.08.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:19
It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "CREATE TABLE" privileges could...
CVE-2018-10915
- EPSS 1.56%
- Veröffentlicht 09.08.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:17
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untru...
CVE-2018-14526
- EPSS 1.14%
- Veröffentlicht 08.08.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:15
An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the Access Point and client can abu...
CVE-2018-15209
- EPSS 0.66%
- Veröffentlicht 08.08.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:50:31
ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, as demonstrated...