Show filters
158 Total Results
Displaying 141-150 of 158
Sort by:
Attacker Value
Unknown

CVE-2017-18267

Disclosure Date: May 10, 2018 (last updated November 26, 2024)
The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.
0
Attacker Value
Unknown

CVE-2018-10768

Disclosure Date: May 06, 2018 (last updated November 26, 2024)
There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected.
0
Attacker Value
Unknown

CVE-2018-10767

Disclosure Date: May 06, 2018 (last updated November 26, 2024)
There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack.
0
Attacker Value
Unknown

CVE-2013-2233

Disclosure Date: May 04, 2018 (last updated November 26, 2024)
Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.
0
Attacker Value
Unknown

CVE-2018-10733

Disclosure Date: May 04, 2018 (last updated November 26, 2024)
There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.
0
Attacker Value
Unknown

CVE-2018-1104

Disclosure Date: May 02, 2018 (last updated November 26, 2024)
Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server.
0
Attacker Value
Unknown

CVE-2018-1101

Disclosure Date: May 02, 2018 (last updated November 26, 2024)
Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.
0
Attacker Value
Unknown

CVE-2016-9587

Disclosure Date: April 24, 2018 (last updated November 08, 2023)
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.
Attacker Value
Unknown

CVE-2018-1000149

Disclosure Date: April 05, 2018 (last updated November 26, 2024)
A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in AbstractAnsibleInvocation.java, AnsibleAdHocCommandBuilder.java, AnsibleAdHocCommandInvocationTest.java, AnsibleContext.java, AnsibleJobDslExtension.java, AnsiblePlaybookBuilder.java, AnsiblePlaybookStep.java that disables host key verification by default.
0
Attacker Value
Unknown

CVE-2018-7750

Disclosure Date: March 13, 2018 (last updated November 26, 2024)
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.