漏洞类别:Web Application 漏洞等级: 漏洞信息 Apache Struts is a framework for building web applications. Apache Struts on the target web application was found to be vulnerable to a remote code execution vulnerabili …
月度归档: 2018年3月
CVE-2018-1000024 SUSE Enterprise Linux Security Update for squid3 (SUSE-SU-2018:0752-1)
漏洞类别:SUSE 漏洞等级: 漏洞信息 SUSE has released security update for squid3 to fix the vulnerabilities. Affected Products: SUSE Linux Enterprise Server 11-SP4 漏洞危害 This vulnerability can be …
Information gathering Oracle Java SE/JRE/JDK 8/1.8 Detected
漏洞类别:Information gathering 漏洞等级: 漏洞信息 Java Platform, Standard Edition (Java SE) lets you develop and deploy Java applications on desktops, servers, and embedded environments, while offering user interface …
CVE-2018-1068 Amazon Linux Security Advisory for kernel: ALAS2-2018-971
漏洞类别:Amazon Linux 漏洞等级: 漏洞信息 Out-of-bounds write via userland offsets in ebt_entry struct in netfilter/ebtables.c:A flaw was found in the Linux kernel’s implementation of 32-bit syscall interface for br …
Amazon Linux Amazon Linux Security Advisory for memcached: ALAS2-2018-964
漏洞类别:Amazon Linux 漏洞等级: 漏洞信息 It was discovered that the memcached daemon listened on UDP port 11211 by default. An attacker could use memcached for UDP amplification denial-of-service attacks. The UDP por …
CVE-2018-7750 Ubuntu Security Notification for Paramiko Vulnerability (USN-3603-1)
漏洞类别:Ubuntu 漏洞等级: 漏洞信息 It was discovered that Paramiko’s SSH server implementation did not properly require authentication before processing requests. 漏洞危害 An unauthenticated rem …
CVE-2016-10266 Ubuntu Security Notification for Tiff Vulnerabilities (USN-3602-1)
漏洞类别:Ubuntu 漏洞等级: 漏洞信息 It was discovered that LibTIFF incorrectly handled certain malformed images. 漏洞危害 If a user or automated system were tricked into opening a specially craft …
CVE-2018-1049 Amazon Linux Security Advisory for systemd: ALAS2-2018-961
漏洞类别:Amazon Linux 漏洞等级: 漏洞信息 Access to automounted volumes can lock upA race condition was found in systemd. This could result in automount requests not being serviced and processes using them could hang, …
CVE-2017-3144 Amazon Linux Security Advisory for dhcp: ALAS2-2018-963
漏洞类别:Amazon Linux 漏洞等级: 漏洞信息 Omapi code doesn’t free socket descriptors when empty message is received allowing denial-of-serviceIt was found that the DHCP daemon did not properly clean up closed OMAPI co …
CVE-2017-5715 Amazon Linux Security Advisory for linux-firmware: ALAS2-2018-962
漏洞类别:Amazon Linux 漏洞等级: 漏洞信息 Speculative execution branch target injectionAn industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructi …
CVE-2017-14604 Amazon Linux Security Advisory for nautilus: ALAS2-2018-960
漏洞类别:Amazon Linux 漏洞等级: 漏洞信息 Insufficient validation of trust of .desktop files with execute permissionAn untrusted .desktop file with executable permission set could choose its displayed name and icon, a …
CVE-2018-5750 Amazon Linux Security Advisory for kernel: ALAS2-2018-956
漏洞类别:Amazon Linux 漏洞等级: 漏洞信息 Stack-based out-of-bounds read via vmcall instructionLinux kernel compiled with the KVM virtualization (CONFIG_KVM) support is vulnerable to an out-of-bounds read access issue …
CVE-2017-15134 Amazon Linux Security Advisory for 389-ds-base: ALAS2-2018-955
漏洞类别:Amazon Linux 漏洞等级: 漏洞信息 Remote DoS via search filters in slapi_filter_sprintf in slapd/util.cA stack buffer overflow flaw was found in the way 389-ds-base handled certain LDAP search filters. A remot …
CVE-2017-3145 Amazon Linux Security Advisory for bind: ALAS2-2018-954
漏洞类别:Amazon Linux 漏洞等级: 漏洞信息 Improper fetch cleanup sequencing in the resolver can cause named to crashA use-after-free flaw leading to denial of service was found in the way BIND internally handled clean …
CVE-2017-15119 SUSE Enterprise Linux Security Update for qemu (SUSE-SU-2018:0762-1)
漏洞类别:SUSE 漏洞等级: 漏洞信息 SUSE has released security update for qemu to fix the vulnerabilities. Affected Products: SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Desktop 12-SP3 漏洞危 …
CVE-2017-5715 SUSE Enterprise Linux Security Update for crash (SUSE-SU-2018:0757-1)
漏洞类别:SUSE 漏洞等级: 漏洞信息 SUSE has released security update for crash to fix the vulnerabilities. Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP2 SUSE Linux Enterprise Server 12-SP2 …
CVE-2018-1058 SUSE Enterprise Linux Security Update for postgresql94 (SUSE-SU-2018:0755-1)
漏洞类别:SUSE 漏洞等级: 漏洞信息 SUSE has released security update for postgresql94 to fix the vulnerabilities. Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server …
CVE-2018-1050 SUSE Enterprise Linux Security Update for samba, talloc, tevent (SUSE-SU-2018:0754-1)
漏洞类别:SUSE 漏洞等级: 漏洞信息 SUSE has released security update for samba, talloc, tevent to fix the vulnerabilities. Affected Products: SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterpri …
CVE-2017-5715 Amazon Linux Security Advisory for microcode_ctl: ALAS2-2018-953
漏洞类别:Amazon Linux 漏洞等级: 漏洞信息 <DIV> Issue Overview: An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of instructions (a commonly u …
CVE-2018-2579 Debian Security Update for openjdk-8 (DSA 4144-1)
漏洞类别:Debian 漏洞等级: 漏洞信息 Debian has released security update for openjdk-8 to fix the vulnerabilities. 漏洞危害 This vulnerability could be exploited to gain partial access to sensitive in …