Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 250

Количество 55 250

redhat логотип

CVE-2018-20804

почти 6 лет назад

A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations. This issue affects MongoDB Server v4.0 versions prior to 4.0.10 and MongoDB Server v3.6 versions prior to 3.6.13.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2018-20803

почти 6 лет назад

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathematics processing while retaining locks. This issue affects MongoDB Server v4.0 versions prior to 4.0.5; MongoDB Server v3.6 versions prior to 3.6.10 and MongoDB Server v3.4 versions prior to 3.4.19.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2018-20802

почти 6 лет назад

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries with compound indexes affecting QueryPlanner. This issue affects MongoDB Server v3.6 versions prior to 3.6.9 and MongoDB Server v4.0 versions prior to 4.0.3.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2018-20796

больше 7 лет назад

In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-20786

больше 7 лет назад

libvterm through 0+bzr726, as used in Vim and other products, mishandles certain out-of-memory conditions, leading to a denial of service (application crash), related to screen.c, state.c, and vterm.c.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-20784

больше 7 лет назад

In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop in update_blocked_averages) or possibly have unspecified other impact by inducing a high load.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-20783

почти 8 лет назад

In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. This is related to phar_parse_pharfile in ext/phar/phar.c.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-20781

больше 9 лет назад

In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2018-20750

больше 7 лет назад

LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-20749

больше 7 лет назад

LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-20748

больше 7 лет назад

LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2018-20721

больше 7 лет назад

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-20712

больше 7 лет назад

A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2018-20710

больше 7 лет назад

No description is available for this CVE.

EPSS: Низкий
redhat логотип

CVE-2018-20699

почти 8 лет назад

Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.

CVSS3: 4.5
EPSS: Низкий
redhat логотип

CVE-2018-20685

почти 8 лет назад

In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-20679

почти 8 лет назад

An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server, client, and relay) allows a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to verification in udhcp_get_option() in networking/udhcp/common.c that 4-byte options are indeed 4 bytes.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2018-20677

около 8 лет назад

In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-20676

около 8 лет назад

In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-20673

больше 7 лет назад

The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-20804

A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations. This issue affects MongoDB Server v4.0 versions prior to 4.0.10 and MongoDB Server v3.6 versions prior to 3.6.13.

CVSS3: 6.5
1%
Низкий
почти 6 лет назад
redhat логотип
CVE-2018-20803

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathematics processing while retaining locks. This issue affects MongoDB Server v4.0 versions prior to 4.0.5; MongoDB Server v3.6 versions prior to 3.6.10 and MongoDB Server v3.4 versions prior to 3.4.19.

CVSS3: 6.5
1%
Низкий
почти 6 лет назад
redhat логотип
CVE-2018-20802

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries with compound indexes affecting QueryPlanner. This issue affects MongoDB Server v3.6 versions prior to 3.6.9 and MongoDB Server v4.0 versions prior to 4.0.3.

CVSS3: 6.5
1%
Низкий
почти 6 лет назад
redhat логотип
CVE-2018-20796

In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.

CVSS3: 5.3
5%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20786

libvterm through 0+bzr726, as used in Vim and other products, mishandles certain out-of-memory conditions, leading to a denial of service (application crash), related to screen.c, state.c, and vterm.c.

CVSS3: 5.3
3%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20784

In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop in update_blocked_averages) or possibly have unspecified other impact by inducing a high load.

CVSS3: 5.9
4%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20783

In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an attacker to read allocated or unallocated memory past the actual data when trying to parse a .phar file. This is related to phar_parse_pharfile in ext/phar/phar.c.

CVSS3: 5.3
5%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-20781

In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.

CVSS3: 4.4
1%
Низкий
больше 9 лет назад
redhat логотип
CVE-2018-20750

LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.

CVSS3: 7.5
3%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20749

LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.

CVSS3: 7.5
3%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20748

LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete.

CVSS3: 8.8
3%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20721

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.

CVSS3: 5.3
2%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20712

A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.

CVSS3: 4.7
3%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20710

No description is available for this CVE.

больше 7 лет назад
redhat логотип
CVE-2018-20699

Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.

CVSS3: 4.5
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-20685

In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.

CVSS3: 5.3
4%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-20679

An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server, client, and relay) allows a remote attacker to leak sensitive information from the stack by sending a crafted DHCP message. This is related to verification in udhcp_get_option() in networking/udhcp/common.c that 4-byte options are indeed 4 bytes.

CVSS3: 4.3
7%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-20677

In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

CVSS3: 6.1
5%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-20676

In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

CVSS3: 6.1
5%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-20673

The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.

CVSS3: 5.3
2%
Низкий
больше 7 лет назад

Уязвимостей на страницу