|
249591
|
5.4 |
MEDIUM
Network
|
redhat
|
keycloak single_sign-on
|
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further a…
|
CWE-295
Improper Certificate Validation
|
CVE-2018-10894
|
2024-11-21 12:42 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249592
|
8.1 |
HIGH
Network
|
rpm redhat
|
yum-utils enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server virtualization
|
A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may…
|
-
|
CVE-2018-10897
|
2024-11-21 12:42 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249593
|
6.5 |
MEDIUM
Network
|
lftp_project canonical opensuse
|
lftp ubuntu_linux leap
|
It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A r…
|
CWE-20
Improper Input Validation
|
CVE-2018-10916
|
2024-11-21 12:42 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249594
|
8.8 |
HIGH
Adjacent
|
dell
|
emc_networker
|
Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advanced Message Queuing …
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2018-11050
|
2024-11-21 12:42 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249595
|
8.8 |
HIGH
Adjacent
|
redhat openstack
|
openstack tripleo_heat_templates
|
A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily gues…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-10898
|
2024-11-21 12:42 |
2018-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249596
|
8.8 |
HIGH
Network
|
prosody
|
prosody
|
prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts.…
|
CWE-287
Improper Authentication
|
CVE-2018-10847
|
2024-11-21 12:42 |
2018-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249597
|
7.5 |
HIGH
Network
|
cryptography canonical redhat
|
python-cryptography ubuntu_linux openstack
|
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing…
|
CWE-20
Improper Input Validation
|
CVE-2018-10903
|
2024-11-21 12:42 |
2018-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249598
|
5.5 |
MEDIUM
Local
|
debian linux canonical redhat
|
debian_linux linux_kernel ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server
|
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_dirty_metadata(), a denial of service, and a system crash by mounting and operati…
|
-
|
CVE-2018-10883
|
2024-11-21 12:42 |
2018-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249599
|
5.5 |
MEDIUM
Local
|
linux debian canonical redhat
|
linux_kernel debian_linux ubuntu_linux enterprise_linux
|
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted …
|
-
|
CVE-2018-10882
|
2024-11-21 12:42 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249600
|
5.5 |
MEDIUM
Local
|
redhat
|
virtualization jboss_enterprise_application_platform wildfly_core
|
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance…
|
CWE-22
Path Traversal
|
CVE-2018-10862
|
2024-11-21 12:42 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|