|
251121
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The ocfs2_setattr function in fs/ocfs2/file.c in the Linux kernel before 4.14.2 allows local users to cause a denial of service (deadlock) via DIO requests.
|
NVD-CWE-noinfo
|
CVE-2017-18204
|
2024-11-21 12:19 |
2018-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251122
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The dm_get_from_kobject function in drivers/md/dm.c in the Linux kernel before 4.14.3 allow local users to cause a denial of service (BUG) by leveraging a race condition with __dm_destroy during crea…
|
CWE-362
Race Condition
|
CVE-2017-18203
|
2024-11-21 12:19 |
2018-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251123
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
The __oom_reap_task_mm function in mm/oom_kill.c in the Linux kernel before 4.14.4 mishandles gather operations, which allows attackers to cause a denial of service (TLB entry leak or use-after-free)…
|
CWE-416
Use After Free
|
CVE-2017-18202
|
2024-11-21 12:19 |
2018-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251124
|
5.3 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog posts by POSTing requests to /index.php/tools/requ…
|
NVD-CWE-noinfo
|
CVE-2017-18195
|
2024-11-21 12:19 |
2018-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251125
|
9.8 |
CRITICAL
Network
|
gnu
|
libcdio
|
An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.
|
CWE-415
Double Free
|
CVE-2017-18201
|
2024-11-21 12:19 |
2018-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251126
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The f2fs implementation in the Linux kernel before 4.14 mishandles reference counts associated with f2fs_wait_discard_bios calls, which allows local users to cause a denial of service (BUG), as demon…
|
CWE-20
Improper Input Validation
|
CVE-2017-18200
|
2024-11-21 12:19 |
2018-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251127
|
6.5 |
MEDIUM
Network
|
gnu
|
libcdio
|
realloc_symlink in rock.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (NULL Pointer Dereference) via a crafted iso file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-18199
|
2024-11-21 12:19 |
2018-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251128
|
8.8 |
HIGH
Network
|
gnu
|
libcdio
|
print_iso9660_recurse in iso-info.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a craf…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-18198
|
2024-11-21 12:19 |
2018-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251129
|
9.8 |
CRITICAL
Network
|
jgraph
|
mxgraph
|
In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.
|
CWE-611
XXE
|
CVE-2017-18197
|
2024-11-21 12:19 |
2018-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251130
|
3.3 |
LOW
Local
|
leptonica
|
leptonica
|
Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrict…
|
CWE-22
Path Traversal
|
CVE-2017-18196
|
2024-11-21 12:19 |
2018-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|