|
253311
|
6.5 |
MEDIUM
Network
|
canonical samba
|
ubuntu_linux samba
|
A null pointer dereference flaw was found in the way samba checked database outputs from the LDB database layer. An authenticated attacker could use this flaw to crash a samba server in an Active Dir…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-10918
|
2024-11-21 12:42 |
2018-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253312
|
8.8 |
HIGH
Network
|
debian canonical samba redhat
|
debian_linux ubuntu_linux samba enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server virtualization_host virtualization
|
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a sam…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10858
|
2024-11-21 12:42 |
2018-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253313
|
8.8 |
HIGH
Network
|
redhat
|
ansible_tower
|
Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users i…
|
CWE-352
Origin Validation Error
|
CVE-2018-10884
|
2024-11-21 12:42 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253314
|
5.6 |
MEDIUM
Local
|
gnu redhat canonical fedoraproject debian
|
gnutls enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server ubuntu_linux fedora debian_linux
|
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in…
|
-
|
CVE-2018-10846
|
2024-11-21 12:42 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253315
|
5.9 |
MEDIUM
Network
|
gnu redhat canonical fedoraproject debian
|
gnutls enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server ubuntu_linux fedora debian_linux
|
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text reco…
|
-
|
CVE-2018-10845
|
2024-11-21 12:42 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253316
|
5.9 |
MEDIUM
Network
|
gnu redhat canonical fedoraproject debian
|
gnutls enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server ubuntu_linux fedora debian_linux
|
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recov…
|
-
|
CVE-2018-10844
|
2024-11-21 12:42 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253317
|
7.8 |
HIGH
Local
|
debian canonical linux redhat
|
debian_linux ubuntu_linux linux_kernel enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() whi…
|
-
|
CVE-2018-10902
|
2024-11-21 12:42 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253318
|
4.3 |
MEDIUM
Adjacent
|
intel
|
lldptool
|
lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the …
|
-
|
CVE-2018-10932
|
2024-11-21 12:42 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253319
|
8.8 |
HIGH
Network
|
spice_project debian canonical redhat
|
spice debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server virtualization_host virtualization enterprise_linux_server_eus
|
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authenticat…
|
CWE-20
Improper Input Validation
|
CVE-2018-10873
|
2024-11-21 12:42 |
2018-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253320
|
9.8 |
CRITICAL
Network
|
nasdaq
|
bwise
|
The JMX/RMI interface in Nasdaq BWise 5.0 does not require authentication for an SAP BO Component, which allows remote attackers to execute arbitrary code via a session on port 81.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2018-11247
|
2024-11-21 12:42 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|