|
246931
|
6.5 |
MEDIUM
Network
|
redhat
|
389_directory_server
|
A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.
|
CWE-20
Improper Input Validation
|
CVE-2018-10935
|
2024-11-21 12:42 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246932
|
8.8 |
HIGH
Network
|
spice_project
|
spice
|
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute ar…
|
-
|
CVE-2018-10893
|
2024-11-21 12:42 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246933
|
7.8 |
HIGH
Local
|
canonical debian linux
|
ubuntu_linux debian_linux linux_kernel
|
A flaw was found in the way Linux kernel KVM hypervisor before 4.18 emulated instructions such as sgdt/sidt/fxsave/fxrstor. It did not check current privilege(CPL) level while emulating unprivileged …
|
CWE-269
Improper Privilege Management
|
CVE-2018-10853
|
2024-11-21 12:42 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246934
|
6.5 |
MEDIUM
Network
|
gluster redhat debian opensuse
|
glusterfs enterprise_linux enterprise_linux_server debian_linux virtualization virtualization_host leap
|
A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.
|
-
|
CVE-2018-10930
|
2024-11-21 12:42 |
2018-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246935
|
8.8 |
HIGH
Network
|
redhat debian gluster opensuse
|
enterprise_linux_server debian_linux glusterfs virtualization_host leap
|
A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw to create arbitrary files and execute arbitrary code on glusterfs server nodes.
|
-
|
CVE-2018-10929
|
2024-11-21 12:42 |
2018-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246936
|
8.8 |
HIGH
Network
|
redhat debian gluster opensuse
|
enterprise_linux enterprise_linux_server debian_linux glusterfs gluster_storage virtualization_host leap
|
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use …
|
-
|
CVE-2018-10928
|
2024-11-21 12:42 |
2018-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246937
|
8.1 |
HIGH
Network
|
redhat debian gluster opensuse
|
enterprise_linux_server debian_linux glusterfs virtualization_host leap
|
A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by crashing gluster b…
|
-
|
CVE-2018-10927
|
2024-11-21 12:42 |
2018-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246938
|
8.8 |
HIGH
Network
|
redhat debian gluster opensuse
|
enterprise_linux enterprise_linux_server debian_linux virtualization_host glusterfs leap
|
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execut…
|
-
|
CVE-2018-10926
|
2024-11-21 12:42 |
2018-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246939
|
6.5 |
MEDIUM
Network
|
gluster
|
glusterfs
|
It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-10924
|
2024-11-21 12:42 |
2018-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246940
|
8.1 |
HIGH
Network
|
gluster redhat debian opensuse
|
glusterfs enterprise_linux_server debian_linux virtualization_host leap
|
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and re…
|
-
|
CVE-2018-10923
|
2024-11-21 12:42 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|