|
247021
|
5.3 |
MEDIUM
Network
|
docker mobyproject redhat opensuse
|
docker moby enterprise_linux enterprise_linux_server openstack leap
|
The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disa…
|
-
|
CVE-2018-10892
|
2024-11-21 12:42 |
2018-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247022
|
5.4 |
MEDIUM
Network
|
opmantek
|
open-audit
|
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted attribut…
|
CWE-79
Cross-site Scripting
|
CVE-2018-11124
|
2024-11-21 12:42 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247023
|
7.8 |
HIGH
Local
|
diqee
|
diqee360_firmware
|
An issue was discovered on Diqee Diqee360 devices. A firmware update process, integrated into the firmware, starts at boot and tries to find the update folder on the microSD card. It executes code, w…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2018-10988
|
2024-11-21 12:42 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247024
|
7.5 |
HIGH
Network
|
diqee
|
diqee360_firmware
|
An issue was discovered on Dongguan Diqee Diqee360 devices. The affected vacuum cleaner suffers from an authenticated remote code execution vulnerability. An authenticated attacker can send a special…
|
CWE-78
OS Command
|
CVE-2018-10987
|
2024-11-21 12:42 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247025
|
7.5 |
HIGH
Network
|
redhat
|
openshift
|
In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash when using ovs-networkpolicy plugin. An attacker can use this flaw to cause a D…
|
CWE-20
Improper Input Validation
|
CVE-2018-10885
|
2024-11-21 12:42 |
2018-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247026
|
9.8 |
CRITICAL
Network
|
dellemc
|
elastic_cloud_storage
|
Dell EMC ECS versions 3.2.0.0 and 3.2.0.1 contain an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulnerability to read and modify S3 objects by supplying…
|
CWE-287
Improper Authentication
|
CVE-2018-11052
|
2024-11-21 12:42 |
2018-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247027
|
7.5 |
HIGH
Network
|
emc
|
rsa_certificate_manager
|
RSA Certificate Manager Versions 6.9 build 560 through 6.9 build 564 contain a path traversal vulnerability in the RSA CMP Enroll Server and the RSA REST Enroll Server. A remote unauthenticated attac…
|
CWE-22
Path Traversal
|
CVE-2018-11051
|
2024-11-21 12:42 |
2018-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247028
|
8.8 |
HIGH
Network
|
libpod_project
|
libpod
|
It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being granted to the container.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10856
|
2024-11-21 12:42 |
2018-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247029
|
5.9 |
MEDIUM
Network
|
redhat debian canonical
|
virtualization cloudforms ansible_engine openstack debian_linux ubuntu_linux
|
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-10855
|
2024-11-21 12:42 |
2018-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247030
|
8.8 |
HIGH
Network
|
redhat
|
openshift_container_platform
|
source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the assemble script to …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10843
|
2024-11-21 12:42 |
2018-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|