CVE-2018-14598
- EPSS 3.14%
- Published 24.08.2018 19:29:01
- Last modified 21.11.2024 03:49:22
An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that will be freed later on, leading to DoS (segmentation f...
CVE-2018-14599
- EPSS 2.46%
- Published 24.08.2018 19:29:01
- Last modified 21.11.2024 03:49:23
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact.
CVE-2018-10844
- EPSS 0.19%
- Published 22.08.2018 13:29:00
- Last modified 21.11.2024 03:42:07
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data...
CVE-2018-10845
- EPSS 1.09%
- Published 22.08.2018 13:29:00
- Last modified 21.11.2024 03:42:07
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing dat...
CVE-2018-10846
- EPSS 0.01%
- Published 22.08.2018 13:29:00
- Last modified 21.11.2024 03:42:07
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain ...
CVE-2018-14348
- EPSS 0.45%
- Published 14.08.2018 18:29:00
- Last modified 21.11.2024 03:48:52
libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.
CVE-2018-13405
- EPSS 0.15%
- Published 06.07.2018 14:29:01
- Last modified 21.11.2024 03:47:02
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a memb...
CVE-2017-18342
- EPSS 4.7%
- Published 27.06.2018 12:29:00
- Last modified 21.11.2024 03:19:53
In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function.
CVE-2018-10811
- EPSS 16.95%
- Published 19.06.2018 21:29:00
- Last modified 21.11.2024 03:42:04
strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.
CVE-2018-1061
- EPSS 0.93%
- Published 19.06.2018 12:29:00
- Last modified 21.11.2024 03:59:05
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.