CVE-2014-3219
- EPSS 0.04%
- Veröffentlicht 09.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 02:07:42
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER.
CVE-2014-3005
- EPSS 4.29%
- Veröffentlicht 01.02.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 02:07:18
XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in...
CVE-2017-15365
- EPSS 0.57%
- Veröffentlicht 25.01.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:33
sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass intended access restrictions an...
CVE-2018-6003
- EPSS 1.58%
- Veröffentlicht 22.01.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:51
An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS.
CVE-2018-5345
- EPSS 0.75%
- Veröffentlicht 12.01.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:37
A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file.
CVE-2017-15129
- EPSS 0.07%
- Veröffentlicht 09.01.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:07
A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in ne...
CVE-2014-1859
- EPSS 0.05%
- Veröffentlicht 08.01.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 02:05:10
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
CVE-2014-4978
- EPSS 0.05%
- Veröffentlicht 29.12.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1) /tmp/rs-filter-graph.png or (2) /tmp/rs-filter-graph.
CVE-2014-8119
- EPSS 2.41%
- Veröffentlicht 29.12.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.
CVE-2015-8008
- EPSS 0.55%
- Veröffentlicht 29.12.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictions by making an API request with an existing token.