|
247001
|
4.9 |
MEDIUM
Network
|
redhat
|
keycloak single_sign-on
|
keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infin…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-10912
|
2024-11-21 12:42 |
2018-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247002
|
9.8 |
CRITICAL
Network
|
redhat
|
certification
|
redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any file, potentially gaining remote code execution.
|
CWE-20
Improper Input Validation
|
CVE-2018-10870
|
2024-11-21 12:42 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247003
|
7.5 |
HIGH
Network
|
redhat
|
enterprise_linux certification
|
redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd.
|
-
|
CVE-2018-10869
|
2024-11-21 12:42 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247004
|
6.5 |
MEDIUM
Local
|
canonical linux debian redhat
|
ubuntu_linux linux_kernel debian_linux enterprise_linux
|
Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating on a crafted ext4 filesystem image.
|
-
|
CVE-2018-10877
|
2024-11-21 12:42 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247005
|
7.2 |
HIGH
Network
|
fedoraproject debian
|
389_directory_server debian_linux
|
389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2018-10871
|
2024-11-21 12:42 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247006
|
7.5 |
HIGH
Network
|
git-annex_project debian
|
git-annex debian_linux
|
git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on loca…
|
CWE-200
Information Exposure
|
CVE-2018-10857
|
2024-11-21 12:42 |
2018-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247007
|
6.6 |
MEDIUM
Physics
|
linux canonical redhat
|
linux_kernel ubuntu_linux enterprise_linux
|
Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by operating on a mounted crafted ext4 image.
|
-
|
CVE-2018-10840
|
2024-11-21 12:42 |
2018-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247008
|
7.5 |
HIGH
Network
|
git-annex_project debian
|
git-annex debian_linux
|
git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user's gpg key…
|
CWE-200
Information Exposure
|
CVE-2018-10859
|
2024-11-21 12:42 |
2018-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247009
|
7.8 |
HIGH
Local
|
redhat debian suse canonical
|
openshift virtualization_host virtualization ceph_storage ansible_engine openstack gluster_storage debian_linux package_hub ubuntu_linux
|
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing …
|
CWE-426
Untrusted Search Path
|
CVE-2018-10875
|
2024-11-21 12:42 |
2018-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247010
|
8.8 |
HIGH
Network
|
qutebrowser
|
qutebrowser
|
qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious website could exploit this to load a 'qute://settings/s…
|
CWE-352
Origin Validation Error
|
CVE-2018-10895
|
2024-11-21 12:42 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|