Show filters
128 Total Results
Displaying 71-80 of 128
Sort by:
Attacker Value
Unknown
CVE-2018-10855
Disclosure Date: July 03, 2018 (last updated November 26, 2024)
Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.
0
Attacker Value
Unknown
CVE-2017-2615
Disclosure Date: July 03, 2018 (last updated November 26, 2024)
Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host.
0
Attacker Value
Unknown
CVE-2018-10874
Disclosure Date: July 02, 2018 (last updated November 26, 2024)
In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.
0
Attacker Value
Unknown
CVE-2017-7466
Disclosure Date: June 22, 2018 (last updated November 26, 2024)
Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.
0
Attacker Value
Unknown
CVE-2018-11218
Disclosure Date: June 17, 2018 (last updated November 26, 2024)
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.
0
Attacker Value
Unknown
CVE-2018-11219
Disclosure Date: June 17, 2018 (last updated November 26, 2024)
An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking.
0
Attacker Value
Unknown
CVE-2018-11806
Disclosure Date: June 13, 2018 (last updated November 26, 2024)
m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.
0
Attacker Value
Unknown
CVE-2018-3639
Disclosure Date: May 22, 2018 (last updated November 26, 2024)
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
0
Attacker Value
Unknown
CVE-2016-9590
Disclosure Date: April 26, 2018 (last updated November 26, 2024)
puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.
0
Attacker Value
Unknown
CVE-2018-1059
Disclosure Date: April 24, 2018 (last updated November 26, 2024)
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.
0