CVE-2018-1064
- EPSS 1.42%
- Veröffentlicht 28.03.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:06
libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.
- EPSS 10.89%
- Veröffentlicht 28.03.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:07:54
An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.
CVE-2018-1083
- EPSS 0.07%
- Veröffentlicht 28.03.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:08
Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to ...
CVE-2018-0739
- EPSS 14.45%
- Veröffentlicht 27.03.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:50
Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used w...
CVE-2018-8048
- EPSS 0.69%
- Veröffentlicht 27.03.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:11
In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.
CVE-2018-8763
- EPSS 0.45%
- Veröffentlicht 27.03.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:15
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.
CVE-2018-8764
- EPSS 0.36%
- Veröffentlicht 27.03.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:16
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.
CVE-2018-0202
- EPSS 2.18%
- Veröffentlicht 27.03.2018 09:29:00
- Zuletzt bearbeitet 21.11.2024 03:37:43
clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanis...
- EPSS 0.06%
- Veröffentlicht 26.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:40
The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track an allocated nid, which allows local users to cause a denial of service (race condition) or possibly have unspecified other impact via concurrent thre...
CVE-2017-15710
- EPSS 11.99%
- Veröffentlicht 26.03.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:15:03
In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If th...