Show filters
252 Total Results
Displaying 121-130 of 252
Sort by:
Attacker Value
Unknown
CVE-2018-1124
Disclosure Date: May 23, 2018 (last updated November 26, 2024)
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities run by other users.
0
Attacker Value
Unknown
CVE-2017-18215
Disclosure Date: March 05, 2018 (last updated November 26, 2024)
xvpng.c in xv 3.10a has memory corruption (out-of-bounds write) when decoding PNG comment fields, leading to crashes or potentially code execution, because it uses an incorrect length value.
0
Attacker Value
Unknown
CVE-2018-6954
Disclosure Date: February 13, 2018 (last updated November 08, 2023)
systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.
0
Attacker Value
Unknown
CVE-2017-18078
Disclosure Date: January 29, 2018 (last updated November 08, 2023)
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.
0
Attacker Value
Unknown
CVE-2017-17805
Disclosure Date: December 20, 2017 (last updated November 26, 2024)
The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYPTO_USER_API_SKCIPHER) to cause a denial of service (uninitialized-memory free and kernel crash) or have unspecified other impact by executing a crafted sequence of system calls that use the blkcipher_walk API. Both the generic implementation (crypto/salsa20_generic.c) and x86 implementation (arch/x86/crypto/salsa20_glue.c) of Salsa20 were vulnerable.
0
Attacker Value
Unknown
CVE-2017-17806
Disclosure Date: December 20, 2017 (last updated November 26, 2024)
The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interface (CONFIG_CRYPTO_USER_API_HASH) and the SHA-3 hash algorithm (CONFIG_CRYPTO_SHA3) to cause a kernel stack buffer overflow by executing a crafted sequence of system calls that encounter a missing SHA-3 initialization.
0
Attacker Value
Unknown
CVE-2016-1254
Disclosure Date: December 05, 2017 (last updated November 08, 2023)
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
0
Attacker Value
Unknown
CVE-2015-3138
Disclosure Date: September 28, 2017 (last updated November 26, 2024)
print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).
0
Attacker Value
Unknown
CVE-2017-6594
Disclosure Date: August 28, 2017 (last updated November 26, 2024)
The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure to add the previous hop realm to the transit path of issued tickets.
0
Attacker Value
Unknown
CVE-2014-4616
Disclosure Date: August 24, 2017 (last updated November 26, 2024)
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.
0