|
247421
|
9.8 |
CRITICAL
Network
|
redhat
|
richfaces enterprise_linux
|
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary…
|
CWE-94
Code Injection
|
CVE-2018-14667
|
2024-11-21 12:49 |
2018-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247422
|
6.5 |
MEDIUM
Network
|
gluster redhat debian
|
glusterfs enterprise_linux_server virtualization_host virtualization debian_linux
|
A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple l…
|
-
|
CVE-2018-14660
|
2024-11-21 12:49 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247423
|
8.8 |
HIGH
Network
|
debian redhat gluster
|
debian_linux enterprise_linux glusterfs
|
It was found that the fix for CVE-2018-10927, CVE-2018-10928, CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was incomplete. A remote, authenticated attacker could use one of these flaws to execu…
|
-
|
CVE-2018-14651
|
2024-11-21 12:49 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247424
|
6.5 |
MEDIUM
Network
|
gluster debian redhat
|
glusterfs debian_linux virtualization virtualization_host enterprise_linux_server
|
It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vulnerable to a format string attack. A remote, authen…
|
-
|
CVE-2018-14661
|
2024-11-21 12:49 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247425
|
6.5 |
MEDIUM
Network
|
redhat debian
|
gluster_file_system debian_linux enterprise_linux_server virtualization virtualization_host
|
The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr. A remote, authenticated attacker could exploit t…
|
-
|
CVE-2018-14659
|
2024-11-21 12:49 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247426
|
6.5 |
MEDIUM
Network
|
redhat debian
|
gluster_storage enterprise_linux_server enterprise_linux_virtualization virtualization virtualization_host debian_linux
|
The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could exploit this via the 'GF_XATTROP_ENTRY_IN…
|
-
|
CVE-2018-14654
|
2024-11-21 12:49 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247427
|
8.8 |
HIGH
Network
|
redhat debian
|
gluster_storage debian_linux enterprise_linux_server enterprise_linux_virtualization
|
The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_getspec_req' RPC message. A remote authenticated a…
|
-
|
CVE-2018-14653
|
2024-11-21 12:49 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247428
|
6.5 |
MEDIUM
Network
|
redhat debian
|
gluster_storage debian_linux enterprise_linux_server enterprise_linux_virtualization enterprise_virtualization_host
|
The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling the 'GF_XATTR_CLRLK_CMD' xattr in the 'pl_getxattr'…
|
-
|
CVE-2018-14652
|
2024-11-21 12:49 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247429
|
9.8 |
CRITICAL
Network
|
tenda
|
ac7_firmware ac9_firmware ac10_firmware
|
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06…
|
CWE-78
OS Command
|
CVE-2018-14558
|
2024-11-21 12:49 |
2018-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247430
|
6.6 |
MEDIUM
Physics
|
x.org redhat canonical debian
|
xorg-server enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_eus enterprise_linux_server_aus ubun…
|
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in…
|
CWE-863
Incorrect Authorization
|
CVE-2018-14665
|
2024-11-21 12:49 |
2018-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|