-
CVE-2017-8291 ghostscript corruption of operand stack
CVE ID CVE-2017-8291 DESCRIPTION It was found that ghostscript did not properly validate the parameters passed to the .rsdparams and .eqproc functions. During its execution, a specially crafted PostScript document could execute code in the context of the ghostscript process, bypassing the -dSAFER protection. CVSS3 Base…
-
CVE-2018-10858 samba: insufficient input validation in libsmbclient
SUMMARY Not exposed CVE ID CVE-2018-10858 DESCRIPTION A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. CVSS3 Base Score 4.3 Public Date: 2018-08-16 RESOLUTION…
-
CVE-2017-5753 kernel: speculative execution bounds-check bypass (meltdown/spectre)
SUMMARY requires a kernel update for compliance CVE ID CVE-2017-5753 DESCRIPTION An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions (a commonly used performance optimization). There are three primary variants of the issue which differ in the…
-
CVE-2016-8858 openssh: Memory exhaustion due to unregistered KEXINIT handler
CVE ID CVE-2016-8858 DESCRIPTION ** DISPUTED ** The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party reports that "OpenSSH upstream does not consider this as a…
-
CVE-2017-7280: Unitrends RCE in systems.php password
CVE ID CVE-2017-7280 DESCRIPTION An RCE issue in Unitrends api/includes/systems.php could allow a remote command execution to be injected when changing the system password. RESOLUTION Unitrends Risk Assessment: None. Resolved with latest security update Resolved with latest security update as of 04/14/2017. LINK TO…
-
CVE-2014-3139: snmpd.php bypass authentication
SUMMARY To fix vulnerability in Unitrends snmpd.php allowing an authentication exploit CVE ID CVE-2014-3139 DESCRIPTION recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth parameter to a certain string. RESOLUTION Resolved in the latest…
-
CVE-2018-1111 dhcp: Command injection vulnerability in the DHCP client NetworkManager integration script
SUMMARY Update dhclient package CVE ID CVE-2018-1111 DESCRIPTION A command injection flaw was found in the NetworkManager integration script included in the DHCP client packages in Red Hat Enterprise Linux. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to…
-
CVE-2016-2107: OpenSSL oracle padding vulnerability
CVE ID CVE-2016-2107 DESCRIPTION The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session, NOTE: this…
-
CVE-2014-3008: snmpd.php remote execution
SUMMARY To fix a Unitrends snmpd.php vulnerability allowing a remote execution exploit CVE ID CVE-2014-3008 DESCRIPTION Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm parameter to recoveryconsole/bpl/snmpd.php. RESOLUTION Resolved in…
-
CVE-2017-7541 kernel: Possible heap buffer overflow in brcmf_cfg80211_mgmt_tx
CVE ID CVE-2017-7541 DESCRIPTION Kernel memory corruption due to a buffer overflow was found in brcmf_cfg80211_mgmt_tx() function in Linux kernels from v3.9-rc1 to v4.13-rc1. The vulnerability can be triggered by sending a crafted NL80211_CMD_FRAME packet via netlink. This flaw is unlikely to be triggered remotely as…