CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache NetappRedhat3Enterprise Linux Http ServerStorage Automation StoreNov 21, 2024 Mar 9, 2018 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Validation in the protocol parsing logic in the load balancer resulting in a Segmentation Fault in the serving httpd process. |
2Redhat Selinux Project2Enterprise Linux SelinuxNov 21, 2024 Mar 2, 2018 N/A· v4 4.4 MEDIUM· v3 3.3 LOW· v2 Context relabeling of filesystems is vulnerable to symbolic link attack, allowing a local, unprivileged malicious entity to change the SELinux context of an arbitrary file to a context with few restrictions. This only ha...Show more |
2Fedoraproject Redhat5389 Directory Server Enterprise LinuxEnterprise Linux Desktop+2 moreNov 21, 2024 Mar 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated attacker could potentiall...Show more |
4Canonical DebianRedhat+1 more11Debian Linux Enterprise LinuxEnterprise Linux Aus+8 moreNov 21, 2024 Feb 16, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes tha...Show more |
4Canonical DebianLinux+1 more7Debian Linux Enterprise LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Feb 9, 2018 N/A· v4 7.7 HIGH· v3 6.8 MEDIUM· v2 Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes car...Show more |
2Linux Redhat3Enterprise Linux Enterprise MrgLinux KernelNov 21, 2024 Feb 9, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup. |
3Debian Libpam4j ProjectRedhat3Debian Linux Enterprise LinuxLibpam4jNov 21, 2024 Jan 18, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possib...Show more |
2Linux Redhat3Enterprise Linux Enterprise MrgLinux KernelNov 21, 2024 Jan 14, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.12. A lack of size check could cause a denial of service (BUG). |
2Linux Redhat3Enterprise Linux Enterprise MrgLinux KernelNov 21, 2024 Jan 14, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13. A superfluous implicit page unlock for VM_SHARED hugetlbfs mapping could trigger a local denial of service (BUG). |
1Redhat 2Enterprise Linux Jboss Enterprise Application PlatformNov 21, 2024 Jan 10, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This issue is a result of an...Show more |
2Freedesktop Redhat2Enterprise Linux Xdg User DirsNov 21, 2024 Jan 9, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped...Show more |
4Canonical FedoraprojectLinux+1 more20Enterprise Linux Enterprise Linux Compute Node EusEnterprise Linux Desktop+17 moreNov 21, 2024 Jan 9, 2018 N/A· v4 4.7 MEDIUM· v3 4.9 MEDIUM· v2 A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it...Show more |
3Fedoraproject NumpyRedhat3Enterprise Linux FedoraNumpyNov 21, 2024 Jan 8, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary f...Show more |
3Fedoraproject Netcf ProjectRedhat3Enterprise Linux FedoraNetcfMay 13, 2026 Dec 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions. |
2Linux Redhat2Enterprise Linux Linux KernelMay 13, 2026 Dec 29, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leveraging failure to disable APEI error injecti...Show more |
2Heketi Project Redhat2Enterprise Linux HeketiMay 13, 2026 Dec 18, 2017 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file. |
2Heketi Project Redhat2Enterprise Linux HeketiMay 13, 2026 Dec 18, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as...Show more |
1Redhat 7Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreMay 13, 2026 Dec 7, 2017 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary. |
2Linux Redhat2Enterprise Linux Linux KernelMay 13, 2026 Nov 30, 2017 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference). |
3Canonical LinuxRedhat3Enterprise Linux Linux KernelUbuntu LinuxMay 13, 2026 Nov 15, 2017 N/A· v4 6.3 MEDIUM· v3 6.9 MEDIUM· v2 The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-w...Show more |