CVE-2017-7658
- EPSS 8.69%
- Veröffentlicht 26.06.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:23
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a...
CVE-2018-1000544
- EPSS 0.68%
- Veröffentlicht 26.06.2018 16:29:02
- Zuletzt bearbeitet 21.11.2024 03:40:09
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip ...
CVE-2018-1000550
- EPSS 0.45%
- Veröffentlicht 26.06.2018 16:29:02
- Zuletzt bearbeitet 21.11.2024 03:40:10
The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server filesystem. This attack appear to ...
CVE-2018-1000517
- EPSS 33.18%
- Veröffentlicht 26.06.2018 16:29:01
- Zuletzt bearbeitet 09.06.2025 16:15:28
BusyBox project BusyBox wget version prior to commit 8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow vulnerability in Busybox wget that can result in heap buffer overflow. This attack appear to be exploitable via network connectiv...
CVE-2018-1000528
- EPSS 0.49%
- Veröffentlicht 26.06.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:40:07
GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password form (html/password.php, #308) that can result in injection of arbitrary web script or HTML. This attac...
CVE-2017-7657
- EPSS 9.1%
- Veröffentlicht 26.06.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:23
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow...
CVE-2017-7656
- EPSS 7.77%
- Veröffentlicht 26.06.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:23
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space URI space version) that declare...
CVE-2018-1000204
- EPSS 0.24%
- Veröffentlicht 26.06.2018 14:29:02
- Zuletzt bearbeitet 21.11.2024 03:39:55
Linux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on /dev/sg0 with dxfer_direction=SG_DXFER_FROM_DEV and an empty 6-byte cmdp. This may lead to copying up to 1000 kernel heap pages to the userspace. This has been fixed upstream in ...
CVE-2018-10852
- EPSS 0.3%
- Veröffentlicht 26.06.2018 14:29:02
- Zuletzt bearbeitet 21.11.2024 03:42:08
The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available fo...
CVE-2018-11039
- EPSS 2.6%
- Veröffentlicht 25.06.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:32
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring ...