|
249891
|
8.1 |
HIGH
Network
|
redhat debian gluster opensuse
|
enterprise_linux_server debian_linux glusterfs virtualization_host leap
|
A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by crashing gluster b…
|
-
|
CVE-2018-10927
|
2024-11-21 12:42 |
2018-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249892
|
8.8 |
HIGH
Network
|
redhat debian gluster opensuse
|
enterprise_linux enterprise_linux_server debian_linux virtualization_host glusterfs leap
|
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execut…
|
-
|
CVE-2018-10926
|
2024-11-21 12:42 |
2018-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249893
|
6.5 |
MEDIUM
Network
|
gluster
|
glusterfs
|
It was discovered that fsync(2) system call in glusterfs client code leaks memory. An authenticated attacker could use this flaw to launch a denial of service attack by making gluster clients consume…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-10924
|
2024-11-21 12:42 |
2018-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249894
|
8.1 |
HIGH
Network
|
gluster redhat debian opensuse
|
glusterfs enterprise_linux_server debian_linux virtualization_host leap
|
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and re…
|
-
|
CVE-2018-10923
|
2024-11-21 12:42 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249895
|
6.5 |
MEDIUM
Network
|
gluster redhat debian opensuse
|
glusterfs enterprise_linux_server virtualization_host debian_linux leap
|
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enable…
|
-
|
CVE-2018-10914
|
2024-11-21 12:42 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249896
|
6.5 |
MEDIUM
Network
|
gluster redhat debian opensuse
|
glusterfs enterprise_linux_server debian_linux virtualization_host leap
|
An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.
|
-
|
CVE-2018-10913
|
2024-11-21 12:42 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249897
|
7.5 |
HIGH
Network
|
gluster redhat debian opensuse
|
glusterfs enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server virtualization_host debian_linux leap
|
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict …
|
-
|
CVE-2018-10911
|
2024-11-21 12:42 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249898
|
8.8 |
HIGH
Network
|
gluster redhat debian opensuse
|
glusterfs enterprise_linux_server virtualization_host debian_linux leap
|
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attac…
|
-
|
CVE-2018-10907
|
2024-11-21 12:42 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249899
|
8.8 |
HIGH
Network
|
gluster redhat debian opensuse
|
glusterfs enterprise_linux_server virtualization_host debian_linux leap
|
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw…
|
-
|
CVE-2018-10904
|
2024-11-21 12:42 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249900
|
5.9 |
MEDIUM
Network
|
dell oracle
|
bsafe jd_edwards_enterpriseone_tools security_service enterprise_manager_ops_center application_testing_suite retail_predictive_application_server communications_ip_service_activato…
|
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2018-11057
|
2024-11-21 12:42 |
2018-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|