Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 249

Количество 55 249

redhat логотип

CVE-2018-15501

около 8 лет назад

In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-15494

около 8 лет назад

In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-15473

около 8 лет назад

OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.

CVSS3: 5.3
EPSS: Критический
redhat логотип

CVE-2018-15471

около 8 лет назад

An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used in Xen through 4.11.x and other products. The Linux netback driver allows frontends to control mapping of requests to request queues. When processing a request to set or change this mapping, some input validation (e.g., for an integer overflow) was missing or flawed, leading to OOB access in hash handling. A malicious or buggy frontend may cause the (usually privileged) backend to make out of bounds memory accesses, potentially resulting in one or more of privilege escalation, Denial of Service (DoS), or information leaks.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2018-15470

около 8 лет назад

An issue was discovered in Xen through 4.11.x. The logic in oxenstored for handling writes depended on the order of evaluation of expressions making up a tuple. As indicated in section 7.7.3 "Operations on data structures" of the OCaml manual, the order of evaluation of subexpressions is not specified. In practice, different implementations behave differently. Thus, oxenstored may not enforce the configured quota-maxentity. This allows a malicious or buggy guest to write as many xenstore entries as it wishes, causing unbounded memory usage in oxenstored. This can lead to a system-wide DoS.

CVSS3: 6
EPSS: Низкий
redhat логотип

CVE-2018-15469

около 8 лет назад

An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either in the hypervisor or in Linux. Unfortunately, an ARM guest can still request v2 grant tables; they will simply not be properly set up, resulting in subsequent grant-related hypercalls hitting BUG() checks. An unprivileged guest can cause a BUG() check in the hypervisor, resulting in a denial-of-service (crash).

CVSS3: 6
EPSS: Низкий
redhat логотип

CVE-2018-15468

около 8 лет назад

An issue was discovered in Xen through 4.11.x. The DEBUGCTL MSR contains several debugging features, some of which virtualise cleanly, but some do not. In particular, Branch Trace Store is not virtualised by the processor, and software has to be careful to configure it suitably not to lock up the core. As a result, it must only be available to fully trusted guests. Unfortunately, in the case that vPMU is disabled, all value checking was skipped, allowing the guest to choose any MSR_DEBUGCTL setting it likes. A malicious or buggy guest administrator (on Intel x86 HVM or PVH) can lock up the entire host, causing a Denial of Service.

CVSS3: 6
EPSS: Низкий
redhat логотип

CVE-2018-15209

около 8 лет назад

ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, as demonstrated by tiff2pdf.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-1517

около 8 лет назад

A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data. IBM X-Force ID: 141681.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-15173

около 8 лет назад

Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted TCP-based service.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-15127

больше 7 лет назад

LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2018-15126

больше 7 лет назад

LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2018-15120

около 8 лет назад

libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.

CVSS3: 4.3
EPSS: Средний
redhat логотип

CVE-2018-14955

около 8 лет назад

The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute).

CVSS3: 8.7
EPSS: Низкий
redhat логотип

CVE-2018-14954

около 8 лет назад

The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute.

CVSS3: 8.7
EPSS: Низкий
redhat логотип

CVE-2018-14953

около 8 лет назад

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.

CVSS3: 8.7
EPSS: Низкий
redhat логотип

CVE-2018-14952

около 8 лет назад

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack.

CVSS3: 8.7
EPSS: Низкий
redhat логотип

CVE-2018-14951

около 8 лет назад

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack.

CVSS3: 8.7
EPSS: Низкий
redhat логотип

CVE-2018-14950

около 8 лет назад

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack.

CVSS3: 8.7
EPSS: Низкий
redhat логотип

CVE-2018-14939

около 8 лет назад

The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environments such as FreeBSD libc, which might allow attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact if LibreOffice is automatically launched during web browsing with pathnames controlled by a remote web site.

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-15501

In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.

CVSS3: 5.3
4%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-15494

In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.

CVSS3: 6.1
3%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-15473

OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.

CVSS3: 5.3
99%
Критический
около 8 лет назад
redhat логотип
CVE-2018-15471

An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used in Xen through 4.11.x and other products. The Linux netback driver allows frontends to control mapping of requests to request queues. When processing a request to set or change this mapping, some input validation (e.g., for an integer overflow) was missing or flawed, leading to OOB access in hash handling. A malicious or buggy frontend may cause the (usually privileged) backend to make out of bounds memory accesses, potentially resulting in one or more of privilege escalation, Denial of Service (DoS), or information leaks.

CVSS3: 8.2
0%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-15470

An issue was discovered in Xen through 4.11.x. The logic in oxenstored for handling writes depended on the order of evaluation of expressions making up a tuple. As indicated in section 7.7.3 "Operations on data structures" of the OCaml manual, the order of evaluation of subexpressions is not specified. In practice, different implementations behave differently. Thus, oxenstored may not enforce the configured quota-maxentity. This allows a malicious or buggy guest to write as many xenstore entries as it wishes, causing unbounded memory usage in oxenstored. This can lead to a system-wide DoS.

CVSS3: 6
0%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-15469

An issue was discovered in Xen through 4.11.x. ARM never properly implemented grant table v2, either in the hypervisor or in Linux. Unfortunately, an ARM guest can still request v2 grant tables; they will simply not be properly set up, resulting in subsequent grant-related hypercalls hitting BUG() checks. An unprivileged guest can cause a BUG() check in the hypervisor, resulting in a denial-of-service (crash).

CVSS3: 6
0%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-15468

An issue was discovered in Xen through 4.11.x. The DEBUGCTL MSR contains several debugging features, some of which virtualise cleanly, but some do not. In particular, Branch Trace Store is not virtualised by the processor, and software has to be careful to configure it suitably not to lock up the core. As a result, it must only be available to fully trusted guests. Unfortunately, in the case that vPMU is disabled, all value checking was skipped, allowing the guest to choose any MSR_DEBUGCTL setting it likes. A malicious or buggy guest administrator (on Intel x86 HVM or PVH) can lock up the entire host, causing a Denial of Service.

CVSS3: 6
0%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-15209

ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, as demonstrated by tiff2pdf.

CVSS3: 5.3
4%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-1517

A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data. IBM X-Force ID: 141681.

CVSS3: 7.5
4%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-15173

Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted TCP-based service.

CVSS3: 3.3
6%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-15127

LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution

CVSS3: 7.5
15%
Средний
больше 7 лет назад
redhat логотип
CVE-2018-15126

LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution

CVSS3: 7.5
12%
Средний
больше 7 лет назад
redhat логотип
CVE-2018-15120

libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.

CVSS3: 4.3
11%
Средний
около 8 лет назад
redhat логотип
CVE-2018-14955

The mail message display page in SquirrelMail through 1.4.22 has XSS via SVG animations (animate to attribute).

CVSS3: 8.7
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14954

The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute.

CVSS3: 8.7
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14953

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.

CVSS3: 8.7
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14952

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math><maction xlink:href=" attack.

CVSS3: 8.7
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14951

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack.

CVSS3: 8.7
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14950

The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<svg><a xlink:href=" attack.

CVSS3: 8.7
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14939

The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environments such as FreeBSD libc, which might allow attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact if LibreOffice is automatically launched during web browsing with pathnames controlled by a remote web site.

CVSS3: 3.3
2%
Низкий
около 8 лет назад

Уязвимостей на страницу