|
1201
|
8.1
6.8
|
HIGH
Network
|
In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could…
|
CWE-20
Improper Input Validation
|
CVE-2017-15715
|
cpe:2.3:o:redhat:enterprise_linux:7.6:* cpe:2.3:o:redhat:enterprise_linux:7.5:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 12:15
2018-03-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1202
|
7.5
5.0
|
HIGH
Network
|
In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset en…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-15710
|
cpe:2.3:o:redhat:enterprise_linux:7.6:* cpe:2.3:o:redhat:enterprise_linux:7.5:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 12:15
2018-03-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1203
|
7.5
6.0
|
HIGH
Network
|
Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file system not exported under the share definition.
|
CWE-362 CWE-59
Race Condition Link Following
|
CVE-2017-2619
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:23
2018-03-13
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1204
|
8.8
6.8
|
HIGH
Network
|
Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified oth…
|
CWE-787
Out-of-bounds Write
|
CVE-2016-5314
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:54
2018-03-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1205
|
4.3
3.3
|
MEDIUM
Adjacent
|
Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Validation in the protocol parsing logic in the load balancer resulting in a Segmentation Fault in the se…
|
-
|
CVE-2016-8612
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:59
2018-03-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1206
|
4.4
3.3
|
MEDIUM
Local
|
Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity to change the SELinux context of an arbitrary file to a context with few restr…
|
-
|
CVE-2018-1063
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 12:59
2018-03-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1207
|
7.5
5.0
|
HIGH
Network
|
A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated atta…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15134
|
cpe:2.3:o:redhat:enterprise_linux:7.4:*
|
|
|
|
|
2024-11-21 12:14
2018-03-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1208
|
5.9
4.3
|
MEDIUM
Network
|
In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint …
|
CWE-362
Race Condition
|
CVE-2018-1049
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 12:59
2018-02-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1209
|
7.7
6.8
|
HIGH
Network
|
Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmwar…
|
CWE-20
Improper Input Validation
|
CVE-2018-1000026
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 12:39
2018-02-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1210
|
5.5
4.9
|
MEDIUM
Local
|
The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.
|
CWE-399
Resource Management Errors
|
CVE-2014-8171
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:18
2018-02-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|