CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianLinux+1 more10Debian Linux Enterprise LinuxEnterprise Linux Desktop+7 moreNov 21, 2024 May 24, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code executi...Show more |
5Canonical DebianProcps Ng Project+2 more10Debian Linux Enterprise LinuxEnterprise Linux Desktop+7 moreNov 21, 2024 May 23, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124. |
6Canonical DebianOpensuse+3 more9Debian Linux Enterprise LinuxEnterprise Linux Desktop+6 moreNov 21, 2024 May 23, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs b...Show more |
2Fedoraproject Redhat7Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 May 17, 2018 N/A· v4 7.5 HIGH· v3 7.9 HIGH· v2 DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an at...Show more |
4Canonical DebianLinux+1 more11Debian Linux Enterprise LinuxEnterprise Linux Desktop+8 moreNov 21, 2024 May 15, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stac...Show more |
2Haproxy Redhat2Enterprise Linux HaproxyNov 21, 2024 May 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in HAProxy before 1.8.8. The incoming H2 frame length was checked against the max_frame_size setting instead of being checked against the bufsize. The max_frame_size only applies to outgoing traff...Show more |
2Fedoraproject Redhat2389 Directory Server Enterprise LinuxNov 21, 2024 Apr 30, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or possib...Show more |
3Debian RedhatXiph.org6Debian Linux Enterprise LinuxEnterprise Linux Eus+3 moreNov 21, 2024 Apr 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read. |
3Debian RedhatXiph.org6Debian Linux Enterprise LinuxEnterprise Linux Eus+3 moreNov 21, 2024 Apr 26, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have u...Show more |
3Canonical DpdkRedhat9Ceph Storage Data Plane Development KitEnterprise Linux+6 moreNov 21, 2024 Apr 24, 2018 N/A· v4 6.1 MEDIUM· v3 2.9 LOW· v2 The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead t...Show more |
2Clusterlabs Redhat2Enterprise Linux Pacemaker Command Line InterfaceNov 21, 2024 Apr 12, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of the pcsd service did not properly sanitize the file name from the /remote/put_fil...Show more |
4Canonical DebianRedhat+1 more4Debian Linux Enterprise LinuxRuby+1 moreJun 17, 2026 Apr 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-re...Show more |
4Canonical DebianRedhat+1 more4Debian Linux Enterprise LinuxRuby+1 moreJun 17, 2026 Apr 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with a crafted header to WEBrick server or a crafted body to WEBrick server...Show more |
4Canonical DebianRedhat+1 more4Debian Linux Enterprise LinuxRuby+1 moreJun 17, 2026 Apr 3, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arb...Show more |
5Apache CanonicalDebian+2 more8Clustered Data Ontap Debian LinuxEnterprise Linux+5 moreNov 21, 2024 Mar 26, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very...Show more |
5Apache CanonicalDebian+2 more8Clustered Data Ontap Debian LinuxEnterprise Linux+5 moreNov 21, 2024 Mar 26, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. Thi...Show more |
5Apache CanonicalDebian+2 more8Clustered Data Ontap Debian LinuxEnterprise Linux+5 moreNov 21, 2024 Mar 26, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in envi...Show more |
5Apache CanonicalDebian+2 more8Clustered Data Ontap Debian LinuxEnterprise Linux+5 moreNov 21, 2024 Mar 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying...Show more |
3Debian RedhatSamba3Debian Linux Enterprise LinuxSambaNov 21, 2024 Mar 12, 2018 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file system not exported under the share definition. |
4Debian LibtiffOpensuse+1 more5Debian Linux Enterprise LinuxLeap+2 moreNov 21, 2024 Mar 12, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a craft...Show more |