|
1071
|
9.8
7.5
|
CRITICAL
Network
|
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git …
|
CWE-88
Argument Injection
|
CVE-2018-17456
|
cpe:2.3:o:redhat:enterprise_linux:7.6:* cpe:2.3:o:redhat:enterprise_linux:7.5:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 12:54
2018-10-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1072
|
7.5
7.8
|
HIGH
Network
|
A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to prov…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-14648
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 12:49
2018-09-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1073
|
5.9
4.3
|
MEDIUM
Network
|
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This…
|
NVD-CWE-noinfo
|
CVE-2018-11763
|
cpe:2.3:o:redhat:enterprise_linux:7.6:* cpe:2.3:o:redhat:enterprise_linux:7.5:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 12:43
2018-09-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1074
|
7.5
5.0
|
HIGH
Network
|
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-14645
|
cpe:2.3:o:redhat:enterprise_linux:7.6:* cpe:2.3:o:redhat:enterprise_linux:7.5:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 12:49
2018-09-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1075
|
5.5
2.1
|
MEDIUM
Local
|
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
|
-
|
CVE-2016-7056
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:57
2018-09-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1076
|
9.8
10.0
|
CRITICAL
Network
|
curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to fig…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-14618
|
cpe:2.3:o:redhat:enterprise_linux:7.6:* cpe:2.3:o:redhat:enterprise_linux:7.5:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 12:49
2018-09-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1077
|
5.5
4.3
|
MEDIUM
Local
|
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-16542
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 12:52
2018-09-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1078
|
7.8
6.8
|
HIGH
Local
|
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or poss…
|
CWE-416
Use After Free
|
CVE-2018-16540
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 12:52
2018-09-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1079
|
6.5
4.0
|
MEDIUM
Network
|
A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.
|
-
|
CVE-2018-10930
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:42
2018-09-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1080
|
8.8
6.5
|
HIGH
Network
|
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use …
|
-
|
CVE-2018-10928
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:42
2018-09-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|