|
247361
|
6.6 |
MEDIUM
Physics
|
linux canonical redhat
|
linux_kernel ubuntu_linux enterprise_linux
|
Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by operating on a mounted crafted ext4 image.
|
-
|
CVE-2018-10840
|
2024-11-21 12:42 |
2018-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247362
|
7.5 |
HIGH
Network
|
git-annex_project debian
|
git-annex debian_linux
|
git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user's gpg key…
|
CWE-200
Information Exposure
|
CVE-2018-10859
|
2024-11-21 12:42 |
2018-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247363
|
7.8 |
HIGH
Local
|
redhat debian suse canonical
|
openshift virtualization_host virtualization ceph_storage ansible_engine openstack gluster_storage debian_linux package_hub ubuntu_linux
|
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing …
|
CWE-426
Untrusted Search Path
|
CVE-2018-10875
|
2024-11-21 12:42 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247364
|
8.8 |
HIGH
Network
|
qutebrowser
|
qutebrowser
|
qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious website could exploit this to load a 'qute://settings/s…
|
CWE-352
Origin Validation Error
|
CVE-2018-10895
|
2024-11-21 12:42 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247365
|
7.3 |
HIGH
Local
|
emc rsa
|
rsa_identity_management_and_governance rsa_identity_governance_and_lifecycle rsa_via_lifecycle_and_governance
|
RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an uni…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2018-11049
|
2024-11-21 12:42 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247366
|
5.9 |
MEDIUM
Network
|
pivotal_software
|
operations_manager
|
Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance i…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2018-11045
|
2024-11-21 12:42 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247367
|
5.5 |
MEDIUM
Local
|
redhat
|
enterprise_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
A flaw was found in the way the Linux kernel handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, processor does not deliv…
|
-
|
CVE-2018-10872
|
2024-11-21 12:42 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247368
|
7.3 |
HIGH
Network
|
moodle
|
moodle
|
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. When a quiz question bank is imported, it was possible for the question preview that is displayed to execute JavaScript that is…
|
NVD-CWE-noinfo
|
CVE-2018-10891
|
2024-11-21 12:42 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247369
|
5.3 |
MEDIUM
Network
|
moodle
|
moodle
|
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7, 3.1.13. It was possible for the core_course_get_categories web service to return hidden categories, which should be omitted when fetchi…
|
CWE-200
Information Exposure
|
CVE-2018-10890
|
2024-11-21 12:42 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247370
|
5.3 |
MEDIUM
Network
|
moodle
|
moodle
|
A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details of other users who interacted with the requester.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-10889
|
2024-11-21 12:42 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|