Vulnerabilities > Redhat

DATE CVE VULNERABILITY TITLE RISK
2018-07-10 CVE-2018-1128 Improper Authentication vulnerability in multiple products
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack.
high complexity
redhat debian opensuse CWE-287
7.5
2018-07-10 CVE-2018-10861 Improper Authentication vulnerability in multiple products
A flaw was found in the way ceph mon handles user requests.
network
low complexity
ceph redhat opensuse debian CWE-287
8.1
2018-07-09 CVE-2018-5002 Out-of-bounds Write vulnerability in multiple products
Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability.
network
low complexity
adobe redhat CWE-787
critical
9.8
2018-07-09 CVE-2018-5001 Out-of-bounds Read vulnerability in multiple products
Adobe Flash Player versions 29.0.0.171 and earlier have an Out-of-bounds read vulnerability.
network
low complexity
adobe redhat CWE-125
6.5
2018-07-09 CVE-2018-5000 Integer Overflow or Wraparound vulnerability in multiple products
Adobe Flash Player versions 29.0.0.171 and earlier have an Integer Overflow vulnerability.
network
low complexity
adobe redhat CWE-190
6.5
2018-07-09 CVE-2018-4945 Incorrect Type Conversion or Cast vulnerability in multiple products
Adobe Flash Player versions 29.0.0.171 and earlier have a Type Confusion vulnerability.
network
low complexity
adobe redhat CWE-704
8.8
2018-07-09 CVE-2018-13785 Integer Overflow or Wraparound vulnerability in multiple products
In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.
network
low complexity
libpng canonical oracle redhat CWE-190
6.5
2018-07-06 CVE-2018-10892 The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames.
network
low complexity
docker mobyproject redhat opensuse
5.3
2018-07-06 CVE-2018-13405 Improper Privilege Management vulnerability in multiple products
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group.
7.8
2018-07-06 CVE-2017-2665 Insufficiently Protected Credentials vulnerability in multiple products
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user.
local
high complexity
mongodb redhat CWE-522
7.0