Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 175

Количество 55 175

redhat логотип

CVE-2018-11207

больше 8 лет назад

A division by zero was discovered in H5D__chunk_init in H5Dchunk.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-11206

больше 8 лет назад

An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-11205

больше 8 лет назад

A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-11204

больше 8 лет назад

A NULL pointer dereference was discovered in H5O__chunk_deserialize in H5Ocache.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-11203

больше 8 лет назад

A division by zero was discovered in H5D__btree_decode_key in H5Dbtree.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-11202

больше 8 лет назад

A NULL pointer dereference was discovered in H5S_hyper_make_spans in H5Shyper.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-1118

больше 8 лет назад

Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net device file.

CVSS3: 2.3
EPSS: Низкий
redhat логотип

CVE-2018-1117

больше 8 лет назад

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.

CVSS3: 5
EPSS: Низкий
redhat логотип

CVE-2018-1116

около 8 лет назад

A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2018-1115

больше 8 лет назад

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.

CVSS3: 4.2
EPSS: Низкий
redhat логотип

CVE-2018-1114

больше 8 лет назад

It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2018-1113

больше 8 лет назад

setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates security assumptions made by pam_shells and some daemons which allow access based on a user's shell being listed in /etc/shells. Under some circumstances, users which had their shell changed to /sbin/nologin could still access the system.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2018-1112

больше 8 лет назад

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

CVSS3: 8
EPSS: Низкий
redhat логотип

CVE-2018-11125

больше 8 лет назад

No description is available for this CVE.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-1111

больше 8 лет назад

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.

CVSS3: 7.5
EPSS: Критический
redhat логотип

CVE-2018-1109

больше 8 лет назад

A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks.

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2018-1108

больше 8 лет назад

kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-1107

больше 8 лет назад

It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON fields defined to have email format. A specially crafted JSON file could cause it to consume an excessive amount of CPU time when validated.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-1106

больше 8 лет назад

An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2018-1104

больше 8 лет назад

Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-11207

A division by zero was discovered in H5D__chunk_init in H5Dchunk.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.

CVSS3: 3.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-11206

An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

CVSS3: 3.3
3%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-11205

A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.

CVSS3: 3.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-11204

A NULL pointer dereference was discovered in H5O__chunk_deserialize in H5Ocache.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.

CVSS3: 3.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-11203

A division by zero was discovered in H5D__btree_decode_key in H5Dbtree.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.

CVSS3: 3.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-11202

A NULL pointer dereference was discovered in H5S_hyper_make_spans in H5Shyper.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.

CVSS3: 3.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1118

Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net device file.

CVSS3: 2.3
0%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1117

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently disclosing admin passwords in the provisioning log. In an environment where logs are shared with other parties, this could lead to privilege escalation.

CVSS3: 5
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1116

A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a local DoS and information disclosure.

CVSS3: 4.4
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-1115

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.

CVSS3: 4.2
4%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1114

It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.

CVSS3: 6.5
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1113

setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates security assumptions made by pam_shells and some daemons which allow access based on a user's shell being listed in /etc/shells. Under some circumstances, users which had their shell changed to /sbin/nologin could still access the system.

CVSS3: 4.8
0%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1112

glusterfs server before versions 3.10.12, 4.0.2 is vulnerable when using 'auth.allow' option which allows any unauthenticated gluster client to connect from any network to mount gluster storage volumes. NOTE: this vulnerability exists because of a CVE-2018-1088 regression.

CVSS3: 8
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-11125

No description is available for this CVE.

CVSS3: 3.3
больше 8 лет назад
redhat логотип
CVE-2018-1111

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.

CVSS3: 7.5
98%
Критический
больше 8 лет назад
redhat логотип
CVE-2018-1109

A vulnerability was found in Braces versions 2.2.0 and above, prior to 2.3.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks.

CVSS3: 4
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1108

kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.

CVSS3: 5.9
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1107

It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON fields defined to have email format. A specially crafted JSON file could cause it to consume an excessive amount of CPU time when validated.

CVSS3: 5.3
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1106

An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a system.

CVSS3: 5.5
0%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1104

Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server.

CVSS3: 8.8
3%
Низкий
больше 8 лет назад

Уязвимостей на страницу