CVE-2018-12892
- EPSS 2.77%
- Veröffentlicht 02.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:03
An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probably an erroneous merge conflict resolution. Malicious guest administrators or (in some situations) user...
CVE-2018-12893
- EPSS 0.07%
- Veröffentlicht 02.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:03
An issue was discovered in Xen through 4.10.x. One of the fixes in XSA-260 added some safety checks to help prevent Xen livelocking with debug exceptions. Unfortunately, due to an oversight, at least one of these safety checks can be triggered by a g...
CVE-2018-12896
- EPSS 0.03%
- Veröffentlicht 02.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:03
An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be ...
CVE-2018-13054
- EPSS 0.25%
- Veröffentlicht 02.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:19
An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These ic...
CVE-2018-13053
- EPSS 0.03%
- Veröffentlicht 02.07.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:18
The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has an integer overflow via a large relative timeout because ktime_add_safe is not used.
CVE-2018-10860
- EPSS 5.74%
- Veröffentlicht 29.06.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:09
perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing coul...
CVE-2018-13005
- EPSS 0.57%
- Veröffentlicht 29.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:14
An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read.
CVE-2018-13006
- EPSS 0.67%
- Veröffentlicht 29.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:14
An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump.
CVE-2018-12895
- EPSS 89.02%
- Veröffentlicht 26.06.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:03
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to mis...
CVE-2018-3760
- EPSS 93.89%
- Veröffentlicht 26.06.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:01
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application'...