CVE-2018-2755
- EPSS 0.19%
- Published 19.04.2018 02:29:01
- Last modified 21.11.2024 04:04:22
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticat...
CVE-2018-2761
- EPSS 0.25%
- Published 19.04.2018 02:29:01
- Last modified 21.11.2024 04:04:23
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated a...
CVE-2018-10194
- EPSS 0.65%
- Published 18.04.2018 21:29:00
- Last modified 21.11.2024 03:40:59
The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause a denial of service (applicat...
CVE-2018-1000156
- EPSS 35.17%
- Published 06.04.2018 13:29:00
- Last modified 14.04.2025 20:15:16
GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via th...
CVE-2018-7566
- EPSS 0.13%
- Published 30.03.2018 21:29:02
- Last modified 21.11.2024 04:12:22
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
CVE-2018-1312
- EPSS 9.08%
- Published 26.03.2018 15:29:00
- Last modified 21.11.2024 03:59:36
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication con...
CVE-2018-1000140
- EPSS 42.51%
- Published 23.03.2018 21:29:00
- Last modified 21.11.2024 03:39:46
rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to ...
CVE-2018-8088
- EPSS 0.84%
- Published 20.03.2018 16:29:00
- Last modified 21.11.2024 04:13:14
org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1....
CVE-2018-1068
- EPSS 0.04%
- Published 16.03.2018 16:29:00
- Last modified 21.11.2024 03:59:06
A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privileged user to arbitrarily write to a limited range of kernel memory.
CVE-2018-7750
- EPSS 16.05%
- Published 13.03.2018 18:29:00
- Last modified 21.11.2024 04:12:39
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is co...