ALAS-2018-982
ALAS-2018-982: php71 (important)
CVEs:CVE-2018-7584
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| php71 | affected | Amazon | php71 | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.
ALAS-2018-982: php71 (important)
CVEs:CVE-2018-7584
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| php71 | affected | Amazon | php71 | — |
ALAS-2018-978: ruby24, ruby22, ruby23 (medium)
CVEs:CVE-2017-0903
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ruby24, ruby22, ruby23 | affected | Amazon | ruby24, ruby22, ruby23 | — |
ALAS-2018-977: python-crypto (medium)
CVEs:CVE-2018-6594
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| python-crypto | affected | Amazon | python-crypto | — |
ALAS-2018-976: clamav (medium)
CVEs:CVE-2012-6706CVE-2017-11423CVE-2017-6419CVE-2018-0202CVE-2018-1000085
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| clamav | affected | Amazon | clamav | — |
ALAS-2018-975: golang (medium)
CVEs:CVE-2018-6574CVE-2018-7187
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| golang | affected | Amazon | golang | — |
ALAS-2018-974: java-1.7.0-openjdk (important)
CVEs:CVE-2018-2579CVE-2018-2588CVE-2018-2599CVE-2018-2602CVE-2018-2603CVE-2018-2618CVE-2018-2629CVE-2018-2633CVE-2018-2634CVE-2018-2637CVE-2018-2641CVE-2018-2663CVE-2018-2677CVE-2018-2678
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| java-1.7.0-openjdk | affected | Amazon | java-1.7.0-openjdk | — |
ALAS-2018-973: tomcat80 (medium)
CVEs:CVE-2017-15706CVE-2018-1304CVE-2018-1305
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tomcat80 | affected | Amazon | tomcat80 | — |
ALAS-2018-972: tomcat7, tomcat8 (medium)
CVEs:CVE-2018-1304CVE-2018-1305
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tomcat7, tomcat8 | affected | Amazon | tomcat7, tomcat8 | — |
ALAS-2018-971: kernel (important)
CVEs:CVE-2018-1068
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| kernel | affected | Amazon | kernel | — |
ALAS-2018-970: exim (critical)
CVEs:CVE-2018-6789
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| exim | affected | Amazon | exim | — |
ALAS-2018-969: mysql55, mysql56, mysql57 (important)
CVEs:CVE-2018-2565CVE-2018-2573CVE-2018-2576CVE-2018-2583CVE-2018-2586CVE-2018-2590CVE-2018-2600CVE-2018-2612CVE-2018-2622CVE-2018-2640CVE-2018-2645CVE-2018-2646CVE-2018-2647CVE-2018-2665CVE-2018-2667CVE-2018-2668CVE-2018-2696CVE-2018-2703
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mysql55, mysql56, mysql57 | affected | Amazon | mysql55, mysql56, mysql57 | — |
ALAS-2018-968: mod_auth_mellon, mod24_auth_mellon (medium)
CVEs:CVE-2017-6807
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| mod_auth_mellon, mod24_auth_mellon | affected | Amazon | mod_auth_mellon, mod24_auth_mellon | — |
ALAS-2018-967: libvpx (low)
CVEs:CVE-2017-13194
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| libvpx | affected | Amazon | libvpx | — |
ALAS-2018-966: GraphicsMagick (important)
CVEs:CVE-2017-11102CVE-2017-11139CVE-2017-11140CVE-2017-11636CVE-2017-11637CVE-2017-11641CVE-2017-11643CVE-2017-13147CVE-2017-16353CVE-2017-16669CVE-2017-17782CVE-2017-17783CVE-2017-17912CVE-2017-17913CVE-2017-17915CVE-2018-5685
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| GraphicsMagick | affected | Amazon | GraphicsMagick | — |
ALAS-2018-965: tomcat-native (medium)
CVEs:CVE-2017-15698
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tomcat-native | affected | Amazon | tomcat-native | — |
ALAS-2018-964: memcached (medium)
CVEs:CVE-2018-1000115
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| memcached | affected | Amazon | memcached | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.