Show filters
120 Total Results
Displaying 31-40 of 120
Sort by:
Attacker Value
Unknown

CVE-2018-14660

Disclosure Date: November 01, 2018 (last updated November 27, 2024)
A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitively resulting in memory exhaustion of glusterfs server node.
Attacker Value
Unknown

CVE-2018-14661

Disclosure Date: October 31, 2018 (last updated November 27, 2024)
It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vulnerable to a format string attack. A remote, authenticated attacker could use this flaw to cause remote denial of service.
Attacker Value
Unknown

CVE-2018-14653

Disclosure Date: October 31, 2018 (last updated November 27, 2024)
The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_getspec_req' RPC message. A remote authenticated attacker could exploit this to cause a denial of service or other potential unspecified impact.
Attacker Value
Unknown

CVE-2018-14652

Disclosure Date: October 31, 2018 (last updated November 27, 2024)
The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling the 'GF_XATTR_CLRLK_CMD' xattr in the 'pl_getxattr' function. A remote authenticated attacker could exploit this on a mounted volume to cause a denial of service.
Attacker Value
Unknown

CVE-2018-14659

Disclosure Date: October 31, 2018 (last updated November 27, 2024)
The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr. A remote, authenticated attacker could exploit this by mounting a Gluster volume and repeatedly calling 'setxattr(2)' to trigger a state dump and create an arbitrary number of files in the server's runtime directory.
Attacker Value
Unknown

CVE-2018-14654

Disclosure Date: October 31, 2018 (last updated November 27, 2024)
The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could exploit this via the 'GF_XATTROP_ENTRY_IN_KEY' xattrop to create arbitrary, empty files on the target server.
Attacker Value
Unknown

CVE-2018-1000805

Disclosure Date: October 08, 2018 (last updated November 27, 2024)
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
Attacker Value
Unknown

CVE-2018-0462

Disclosure Date: September 05, 2018 (last updated November 27, 2024)
A vulnerability in the user management functionality of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a denial of service (DoS) attack against an affected system. The vulnerability is due to insufficient validation of user-provided input. An attacker could exploit this vulnerability by logging in with a highly privileged user account and performing a sequence of specific user management operations that interfere with the underlying operating system. A successful exploit could allow the attacker to permanently degrade the functionality of the affected system.
0
Attacker Value
Unknown

CVE-2018-10930

Disclosure Date: September 04, 2018 (last updated November 27, 2024)
A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.
Attacker Value
Unknown

CVE-2018-10929

Disclosure Date: September 04, 2018 (last updated November 27, 2024)
A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw to create arbitrary files and execute arbitrary code on glusterfs server nodes.