|
246261
|
5.5 |
MEDIUM
Local
|
linux redhat
|
linux_kernel enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_tus enterprise_linux_server_aus
|
The Linux kernel before 4.15-rc8 was found to be vulnerable to a NULL pointer dereference bug in the __netlink_ns_capable() function in the net/netlink/af_netlink.c file. A local attacker could explo…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-14646
|
2024-11-21 12:49 |
2018-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246262
|
6.1 |
MEDIUM
Network
|
redhat
|
keycloak
|
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. Th…
|
CWE-601
Open Redirect
|
CVE-2018-14658
|
2024-11-21 12:49 |
2018-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246263
|
8.1 |
HIGH
Network
|
redhat
|
keycloak single_sign-on
|
A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not enforce its protection measures.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2018-14657
|
2024-11-21 12:49 |
2018-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246264
|
5.4 |
MEDIUM
Network
|
redhat
|
keycloak single_sign-on
|
A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascript-Code via the 'state'-parameter in the authentica…
|
CWE-79
Cross-site Scripting
|
CVE-2018-14655
|
2024-11-21 12:49 |
2018-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246265
|
5.9 |
MEDIUM
Network
|
powerdns
|
recursor
|
An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can lead to a zone being wrongly cached as failing DN…
|
CWE-20
Improper Input Validation
|
CVE-2018-14644
|
2024-11-21 12:49 |
2018-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246266
|
9.8 |
CRITICAL
Network
|
redhat
|
richfaces enterprise_linux
|
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary…
|
CWE-94
Code Injection
|
CVE-2018-14667
|
2024-11-21 12:49 |
2018-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246267
|
6.5 |
MEDIUM
Network
|
gluster redhat debian
|
glusterfs enterprise_linux_server virtualization_host virtualization debian_linux
|
A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple l…
|
-
|
CVE-2018-14660
|
2024-11-21 12:49 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246268
|
8.8 |
HIGH
Network
|
debian redhat gluster
|
debian_linux enterprise_linux glusterfs
|
It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of these flaws to execu…
|
-
|
CVE-2018-14651
|
2024-11-21 12:49 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246269
|
6.5 |
MEDIUM
Network
|
gluster debian redhat
|
glusterfs debian_linux virtualization virtualization_host enterprise_linux_server
|
It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vulnerable to a format string attack. A remote, authen…
|
-
|
CVE-2018-14661
|
2024-11-21 12:49 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246270
|
6.5 |
MEDIUM
Network
|
redhat debian
|
gluster_file_system debian_linux enterprise_linux_server virtualization virtualization_host
|
The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr. A remote, authenticated attacker could exploit t…
|
-
|
CVE-2018-14659
|
2024-11-21 12:49 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|