CVEs (128)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianQemu+1 more4Debian Linux QemuUbuntu Linux+1 moreNov 21, 2024 Jul 27, 2018 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste CPU time on reading up...Show more |
2Ovirt Redhat2Ovirt VirtualizationNov 21, 2024 Jul 27, 2018 N/A· v4 6.6 MEDIUM· v3 3.5 LOW· v2 ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents...Show more |
1Redhat 3Jboss Enterprise Application Platform VirtualizationWildfly CoreNov 21, 2024 Jul 27, 2018 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extraction of crafted .war archives to overwrite arbitrary files. This is an instance of the 'Zip Slip' vu...Show more |
2Qemu Redhat3Openstack QemuVirtualizationNov 21, 2024 Jul 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection negotiation, where the I/O coroutine was undefined. This could crash the qemu-nbd server if a clien...Show more |
1Redhat 2Ansible Engine VirtualizationNov 21, 2024 Jul 26, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it...Show more |
3Canonical DebianRedhat9Ansible Engine Debian LinuxGluster Storage+6 moreNov 21, 2024 Jul 19, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2...Show more |
4Canonical DebianRedhat+1 more10Ansible Engine Ceph StorageDebian Linux+7 moreNov 21, 2024 Jul 13, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execu...Show more |
6Canonical DebianF5+3 more27Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+24 moreNov 21, 2024 Jul 6, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writab...Show more |
3Canonical DebianRedhat6Ansible Engine CloudformsDebian Linux+3 moreNov 21, 2024 Jul 3, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does...Show more |
1Redhat 4Ansible Engine OpenstackVirtualization+1 moreNov 21, 2024 Jul 2, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result. |
2Ovirt Redhat3Ovirt Engine VirtualizationVirtualization HostNov 21, 2024 Jun 19, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts. |
4Canonical DebianQemu+1 more11Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreNov 21, 2024 Jun 13, 2018 N/A· v4 8.2 HIGH· v3 7.2 HIGH· v2 m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams. |
5Bouncycastle DebianNetapp+2 more20Api Gateway Bc JavaBusiness Process Management Suite+17 moreMay 12, 2025 Jun 5, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have l...Show more |
12Arm CanonicalDebian+9 more282Atom C Atom EAtom X5 E3930+279 moreMay 29, 2026 May 22, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an atta...Show more |
3Google OracleRedhat17Banking Payments Communications Ip Service ActivatorCustomer Management And Segmentation Foundation+14 moreNov 21, 2024 Apr 26, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data,...Show more |
3Canonical DpdkRedhat9Ceph Storage Data Plane Development KitEnterprise Linux+6 moreNov 21, 2024 Apr 24, 2018 N/A· v4 6.1 MEDIUM· v3 2.9 LOW· v2 The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead t...Show more |
3Debian OpensuseRedhat6Debian Linux Enterprise Linux ServerGluster Storage+3 moreNov 21, 2024 Apr 18, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss FuseUndertow+1 moreNov 21, 2024 Apr 18, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP r...Show more |
3Oracle QosRedhat13Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+10 moreJun 17, 2026 Mar 20, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has b...Show more |
3Debian ParamikoRedhat11Ansible Engine CloudformsDebian Linux+8 moreJun 17, 2026 Mar 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly chec...Show more |