Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 175

Количество 55 175

redhat логотип

CVE-2018-1078

больше 8 лет назад

OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expired or should expire shortly being re-installed and their timers reset resulting in traffic being allowed that should be expired.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2018-10780

больше 8 лет назад

Exiv2::Image::byteSwap2 in image.cpp in Exiv2 0.26 has a heap-based buffer over-read.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-1077

больше 8 лет назад

Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.

CVSS3: 5
EPSS: Низкий
redhat логотип

CVE-2018-10779

больше 8 лет назад

TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer over-read, as demonstrated by bmp2tiff.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-10775

больше 8 лет назад

NULL pointer dereference in the _fields_add function in fields.c in libbibcore.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by end2xml.

CVSS3: 2.8
EPSS: Низкий
redhat логотип

CVE-2018-10774

больше 8 лет назад

Read access violation in the isiin_keyword function in isiin.c in libbibutils.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by isi2xml.

CVSS3: 2.8
EPSS: Низкий
redhat логотип

CVE-2018-10773

больше 8 лет назад

NULL pointer deference in the addsn function in serialno.c in libbibcore.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by copac2xml.

CVSS3: 2.8
EPSS: Низкий
redhat логотип

CVE-2018-10772

больше 8 лет назад

The tEXtToDataBuf function in pngimage.cpp in Exiv2 through 0.26 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2018-10768

больше 8 лет назад

There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-10767

больше 8 лет назад

There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-1075

около 8 лет назад

ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.

CVSS3: 5
EPSS: Низкий
redhat логотип

CVE-2018-10754

больше 8 лет назад

A NULL pointer dereference was found in the way the _nc_parse_entry function parses terminfo data for compilation. An attacker able to provide specially crafted terminfo data could use this flaw to crash the application parsing it.

CVSS3: 2.8
EPSS: Низкий
redhat логотип

CVE-2018-1074

больше 8 лет назад

ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.

CVSS3: 7.7
EPSS: Низкий
redhat логотип

CVE-2018-1073

больше 8 лет назад

The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-10733

больше 8 лет назад

There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-1072

около 8 лет назад

ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.

CVSS3: 5
EPSS: Низкий
redhat логотип

CVE-2018-1071

больше 8 лет назад

zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a denial of service.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-1070

больше 8 лет назад

routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to be brought down. A malicious user can use this vulnerability to cause a Denial of Service attack for other users of the router shard.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2018-1069

больше 8 лет назад

Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesystem.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2018-1068

больше 8 лет назад

A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privileged user to arbitrarily write to a limited range of kernel memory.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-1078

OpenDayLight version Carbon SR3 and earlier contain a vulnerability during node reconciliation that can result in traffic flows that should be expired or should expire shortly being re-installed and their timers reset resulting in traffic being allowed that should be expired.

CVSS3: 4.8
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-10780

Exiv2::Image::byteSwap2 in image.cpp in Exiv2 0.26 has a heap-based buffer over-read.

CVSS3: 3.3
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1077

Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.

CVSS3: 5
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-10779

TIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer over-read, as demonstrated by bmp2tiff.

CVSS3: 5.3
3%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-10775

NULL pointer dereference in the _fields_add function in fields.c in libbibcore.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by end2xml.

CVSS3: 2.8
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-10774

Read access violation in the isiin_keyword function in isiin.c in libbibutils.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by isi2xml.

CVSS3: 2.8
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-10773

NULL pointer deference in the addsn function in serialno.c in libbibcore.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by copac2xml.

CVSS3: 2.8
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-10772

The tEXtToDataBuf function in pngimage.cpp in Exiv2 through 0.26 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.

CVSS3: 4.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-10768

There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected.

CVSS3: 3.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-10767

There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack.

CVSS3: 3.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1075

ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.

CVSS3: 5
0%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-10754

A NULL pointer dereference was found in the way the _nc_parse_entry function parses terminfo data for compilation. An attacker able to provide specially crafted terminfo data could use this flaw to crash the application parsing it.

CVSS3: 2.8
больше 8 лет назад
redhat логотип
CVE-2018-1074

ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.

CVSS3: 7.7
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1073

The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.

CVSS3: 5.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-10733

There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.

CVSS3: 3.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1072

ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the database username and password were logged in cleartext. Sharing the provisioning log might inadvertently leak database passwords.

CVSS3: 5
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-1071

zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cause a denial of service.

CVSS3: 3.3
0%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1070

routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to be brought down. A malicious user can use this vulnerability to cause a Denial of Service attack for other users of the router shard.

CVSS3: 6.5
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1069

Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesystem.

CVSS3: 7.1
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1068

A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privileged user to arbitrarily write to a limited range of kernel memory.

CVSS3: 8.1
0%
Низкий
больше 8 лет назад

Уязвимостей на страницу