|
249931
|
7.1 |
HIGH
Local
|
canonical
|
cloud-init
|
The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances…
|
-
|
CVE-2018-10896
|
2024-11-21 12:42 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249932
|
5.4 |
MEDIUM
Network
|
redhat
|
keycloak single_sign-on
|
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further a…
|
CWE-295
Improper Certificate Validation
|
CVE-2018-10894
|
2024-11-21 12:42 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249933
|
8.1 |
HIGH
Network
|
rpm redhat
|
yum-utils enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server virtualization
|
A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may…
|
-
|
CVE-2018-10897
|
2024-11-21 12:42 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249934
|
6.5 |
MEDIUM
Network
|
lftp_project canonical opensuse
|
lftp ubuntu_linux leap
|
It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A r…
|
CWE-20
Improper Input Validation
|
CVE-2018-10916
|
2024-11-21 12:42 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249935
|
8.8 |
HIGH
Adjacent
|
dell
|
emc_networker
|
Dell EMC NetWorker versions between 9.0 and 9.1.1.8 through 9.2.1.3, and the version 18.1.0.1 contain a Clear-Text authentication over network vulnerability in the Rabbit MQ Advanced Message Queuing …
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2018-11050
|
2024-11-21 12:42 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249936
|
8.8 |
HIGH
Adjacent
|
redhat openstack
|
openstack tripleo_heat_templates
|
A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily gues…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-10898
|
2024-11-21 12:42 |
2018-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249937
|
8.8 |
HIGH
Network
|
prosody
|
prosody
|
prosody before versions 0.10.2, 0.9.14 is vulnerable to an Authentication Bypass. Prosody did not verify that the virtual host associated with a user session remained the same across stream restarts.…
|
CWE-287
Improper Authentication
|
CVE-2018-10847
|
2024-11-21 12:42 |
2018-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249938
|
7.5 |
HIGH
Network
|
cryptography canonical redhat
|
python-cryptography ubuntu_linux openstack
|
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing…
|
CWE-20
Improper Input Validation
|
CVE-2018-10903
|
2024-11-21 12:42 |
2018-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249939
|
5.5 |
MEDIUM
Local
|
debian linux canonical redhat
|
debian_linux linux_kernel ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server
|
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_dirty_metadata(), a denial of service, and a system crash by mounting and operati…
|
-
|
CVE-2018-10883
|
2024-11-21 12:42 |
2018-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249940
|
5.5 |
MEDIUM
Local
|
linux debian canonical redhat
|
linux_kernel debian_linux ubuntu_linux enterprise_linux
|
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted …
|
-
|
CVE-2018-10882
|
2024-11-21 12:42 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|