Vulnerabilities > Canonical > Ubuntu Linux > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-03-06 CVE-2018-7730 Out-of-bounds Read vulnerability in multiple products
An issue was discovered in Exempi through 2.4.4.
local
low complexity
exempi-project debian canonical CWE-125
5.5
2018-03-06 CVE-2018-7729 Out-of-bounds Read vulnerability in multiple products
An issue was discovered in Exempi through 2.4.4.
local
low complexity
exempi-project canonical CWE-125
5.5
2018-03-06 CVE-2018-7728 Out-of-bounds Read vulnerability in multiple products
An issue was discovered in Exempi through 2.4.4.
local
low complexity
exempi-project canonical debian CWE-125
5.5
2018-03-06 CVE-2018-7726 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
An issue was discovered in ZZIPlib 0.13.68.
network
low complexity
zziplib-project canonical redhat CWE-119
6.5
2018-03-06 CVE-2018-7725 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
An issue was discovered in ZZIPlib 0.13.68.
network
low complexity
zziplib-project canonical redhat CWE-119
6.5
2018-03-02 CVE-2017-15130 A denial of service flaw was found in dovecot before 2.2.34.
network
high complexity
dovecot debian canonical
5.9
2018-03-02 CVE-2018-1066 NULL Pointer Dereference vulnerability in multiple products
The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() that allows an attacker controlling a CIFS server to kernel panic a client that has this server mounted, because an empty TargetInfo field in an NTLMSSP setup negotiation response is mishandled during session recovery.
network
low complexity
linux debian canonical CWE-476
6.5
2018-02-28 CVE-2018-1304 The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition.
network
high complexity
apache redhat debian canonical oracle
5.9
2018-02-26 CVE-2018-7492 NULL Pointer Dereference vulnerability in multiple products
A NULL pointer dereference was found in the net/rds/rdma.c __rds_rdma_map() function in the Linux kernel before 4.14.7 allowing local attackers to cause a system panic and a denial-of-service, related to RDS_GET_MR and RDS_GET_MR_FOR_DEST.
local
low complexity
linux debian canonical CWE-476
5.5
2018-02-24 CVE-2018-7456 NULL Pointer Dereference vulnerability in multiple products
A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 when using the tiffinfo tool to print crafted TIFF information, a different vulnerability than CVE-2017-18013.
network
low complexity
libtiff debian canonical CWE-476
6.5