Show filters
488 Total Results
Displaying 251-260 of 488
Sort by:
Attacker Value
Unknown
CVE-2018-10914
Disclosure Date: September 04, 2018 (last updated November 27, 2024)
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.
0
Attacker Value
Unknown
CVE-2018-10923
Disclosure Date: September 04, 2018 (last updated November 27, 2024)
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs server node.
0
Attacker Value
Unknown
CVE-2018-10907
Disclosure Date: September 04, 2018 (last updated November 27, 2024)
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume and sending a string longer that the fixed buffer size to cause crash or potential code execution.
0
Attacker Value
Unknown
CVE-2018-10904
Disclosure Date: September 04, 2018 (last updated November 27, 2024)
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would require sufficient access to modify the extended attributes of files on a gluster volume.
0
Attacker Value
Unknown
CVE-2018-16402
Disclosure Date: September 03, 2018 (last updated November 08, 2023)
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
0
Attacker Value
Unknown
CVE-2018-16062
Disclosure Date: August 29, 2018 (last updated November 08, 2023)
dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
0
Attacker Value
Unknown
The lxc-user-nic component of LXC allows unprivileged users to open arbitrary f…
Disclosure Date: August 10, 2018 (last updated November 27, 2024)
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.
0
Attacker Value
Unknown
CVE-2018-8032
Disclosure Date: August 02, 2018 (last updated November 08, 2023)
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
0
Attacker Value
Unknown
CVE-2018-3693
Disclosure Date: July 10, 2018 (last updated November 27, 2024)
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.
0
Attacker Value
Unknown
CVE-2018-10861
Disclosure Date: July 10, 2018 (last updated November 27, 2024)
A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.
0