CVE-2018-14678
- EPSS 0.08%
- Veröffentlicht 28.07.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:34
An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which allows local users to cause a denial of service (unin...
CVE-2018-0497
- EPSS 0.33%
- Veröffentlicht 28.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:21
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vulnerability exists because of an incorrect fix (wit...
CVE-2018-0498
- EPSS 0.21%
- Veröffentlicht 28.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:21
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack.
CVE-2016-9578
- EPSS 3.34%
- Veröffentlicht 27.07.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:25
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
CVE-2016-9603
- EPSS 1.59%
- Veröffentlicht 27.07.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:29
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged...
CVE-2016-9577
- EPSS 3.67%
- Veröffentlicht 27.07.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:25
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
CVE-2017-2616
- EPSS 0.06%
- Veröffentlicht 27.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:50
A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
CVE-2017-2618
- EPSS 0.05%
- Veröffentlicht 27.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:50
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
CVE-2017-2620
- EPSS 2.41%
- Veröffentlicht 27.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:50
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use t...
CVE-2018-1056
- EPSS 0.42%
- Veröffentlicht 27.07.2018 18:29:01
- Zuletzt bearbeitet 21.11.2024 03:59:04
An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the advzip utility by tricking it into processing crafted ZIP files.