Show filters
1,398 Total Results
Displaying 71-80 of 1,398
Sort by:
Attacker Value
Unknown

CVE-2018-19208

Disclosure Date: November 12, 2018 (last updated November 27, 2024)
In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h.
Attacker Value
Unknown

CVE-2018-19052

Disclosure Date: November 07, 2018 (last updated November 27, 2024)
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.
Attacker Value
Unknown

The lxc-user-nic component of LXC allows unprivileged users to open arbitrary f…

Disclosure Date: August 10, 2018 (last updated November 27, 2024)
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.
0
Attacker Value
Unknown

Open Shortest Path First (OSPF) protocol implementations may improperly determi…

Disclosure Date: July 24, 2018 (last updated November 27, 2024)
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same LSA, recency is determined by first comparing sequence numbers, then checksums, and finally MaxAge. In a case where the sequence numbers are the same, the LSA with the larger checksum is considered more recent, and will not be flushed from the Link State Database (LSDB). Since the RFC does not explicitly state that the values of links carried by a LSA must be the same when prematurely aging a self-originating LSA with MaxSequenceNumber, it is possible in vulnerable OSPF implementations for an attacker to craft a LSA with MaxSequenceNumber and invalid links that will result in a larger checksum and thus a 'newer' LSA that will not be flushed from the LSDB. Propagation of the crafted LSA can result in the erasure or alteration of the routing tables of routers within the …
0
Attacker Value
Unknown

Missing verification of host key for kdump server

Disclosure Date: June 08, 2018 (last updated November 08, 2023)
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server could use this flaw to impersonate the correct kdump server to obtain security sensitive information (kdump core files).
0
Attacker Value
Unknown

unix2_chkpwd do not check for a valid account

Disclosure Date: June 08, 2018 (last updated November 08, 2023)
A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12.
0
Attacker Value
Unknown

CVE-2016-5314

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by overwriting the vgetparent function pointer with rgb2ycbcr.
0
Attacker Value
Unknown

local privilege escalation in SUSE postgresql init script

Disclosure Date: March 01, 2018 (last updated November 08, 2023)
A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.
0
Attacker Value
Unknown

CVE-2016-1254

Disclosure Date: December 05, 2017 (last updated November 08, 2023)
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
0
Attacker Value
Unknown

CVE-2016-5759

Disclosure Date: September 08, 2017 (last updated November 08, 2023)
The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.
0