CVE-2018-17466
- EPSS 1.05%
- Published 14.11.2018 15:29:00
- Last modified 21.11.2024 03:54:28
Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVE-2018-19115
- EPSS 6.96%
- Published 08.11.2018 20:29:00
- Last modified 21.11.2024 03:57:21
keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code and instead writes an unlimi...
CVE-2016-2125
- EPSS 12.78%
- Published 31.10.2018 20:29:00
- Last modified 21.11.2024 02:47:52
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to othe...
CVE-2018-15688
- EPSS 0.73%
- Published 26.10.2018 14:29:00
- Last modified 09.06.2025 16:15:28
A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.
CVE-2018-14665
- EPSS 3.8%
- Published 25.10.2018 20:29:00
- Last modified 29.08.2025 13:42:30
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate the...
CVE-2018-18559
- EPSS 1.14%
- Published 22.10.2018 16:29:00
- Last modified 21.11.2024 03:56:09
In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt and bind on an AF_PACKET socket. This issue exists because of the 15fe076edea787807a7cdc168df832544b58eba6 incomplete fix for a ra...
CVE-2018-18284
- EPSS 0.22%
- Published 19.10.2018 22:29:01
- Last modified 21.11.2024 03:55:38
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.
CVE-2018-5188
- EPSS 1.34%
- Published 18.10.2018 13:29:07
- Last modified 21.11.2024 04:08:18
Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerabi...
- EPSS 0.06%
- Published 18.10.2018 13:29:06
- Last modified 21.11.2024 03:45:06
A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to w...
CVE-2018-12386
- EPSS 39.1%
- Published 18.10.2018 13:29:06
- Last modified 21.11.2024 03:45:06
A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. This vulnerability affects Firefox ESR...