CVE-2017-3144
- EPSS 18.41%
- Published 16.01.2019 20:29:00
- Last modified 21.11.2024 03:24:55
A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older ve...
CVE-2017-3145
- EPSS 5.77%
- Published 16.01.2019 20:29:00
- Last modified 21.11.2024 03:24:55
BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to ...
CVE-2018-5733
- EPSS 29.51%
- Published 16.01.2019 20:29:00
- Last modified 25.04.2025 23:15:15
A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash. Affects ISC DHCP 4.1.0 -> 4.1-ESV-R15, 4.2.0 -> 4...
CVE-2019-2422
- EPSS 0.24%
- Published 16.01.2019 19:30:31
- Last modified 21.11.2024 04:40:50
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker...
CVE-2018-16865
- EPSS 2.07%
- Published 11.01.2019 21:29:00
- Last modified 21.11.2024 03:53:28
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remo...
CVE-2018-16864
- EPSS 0.15%
- Published 11.01.2019 20:29:00
- Last modified 21.11.2024 03:53:28
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash s...
CVE-2019-6133
- EPSS 0.01%
- Published 11.01.2019 14:29:00
- Last modified 21.11.2024 04:46:00
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendin...
CVE-2018-19134
- EPSS 1.36%
- Published 20.12.2018 23:29:00
- Last modified 21.11.2024 03:57:23
In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscri...
CVE-2018-15127
- EPSS 15.62%
- Published 19.12.2018 16:29:00
- Last modified 21.11.2024 03:50:21
LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution
CVE-2018-18397
- EPSS 0.07%
- Published 12.12.2018 10:29:00
- Last modified 21.11.2024 03:55:52
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that fil...