Show filters
740 Total Results
Displaying 151-160 of 740
Sort by:
Attacker Value
Unknown

CVE-2018-2819

Disclosure Date: April 19, 2018 (last updated November 26, 2024)
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Attacker Value
Unknown

CVE-2018-1000156

Disclosure Date: April 06, 2018 (last updated November 26, 2024)
GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via the patch utility. This is similar to FreeBSD's CVE-2015-1418 however although they share a common ancestry the code bases have diverged over time.
0
Attacker Value
Unknown

CVE-2018-7566

Disclosure Date: March 30, 2018 (last updated November 26, 2024)
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
0
Attacker Value
Unknown

CVE-2018-1312

Disclosure Date: March 26, 2018 (last updated November 08, 2023)
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection.
Attacker Value
Unknown

CVE-2017-15710

Disclosure Date: March 26, 2018 (last updated November 08, 2023)
In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate it to a two characters value to allow a quick retry (for example, 'en-US' is truncated to 'en'). A header value of less than two characters forces an out of bound write of one NUL byte to a memory location that is not part of the string. In the worst case, quite unlikely, the process would crash which could be used as a Denial of Service attack. In the more likely case, this memory is already reserved for future use and the issue has no effect at all.
0
Attacker Value
Unknown

CVE-2018-1301

Disclosure Date: March 26, 2018 (last updated November 08, 2023)
A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server usage.
0
Attacker Value
Unknown

CVE-2018-1068

Disclosure Date: March 16, 2018 (last updated November 26, 2024)
A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privileged user to arbitrarily write to a limited range of kernel memory.
Attacker Value
Unknown

CVE-2018-1000120

Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse.
0
Attacker Value
Unknown

CVE-2018-1000121

Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service
0
Attacker Value
Unknown

CVE-2018-1000122

Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage
0