CVE-2019-2434
- EPSS 3.26%
- Veröffentlicht 16.01.2019 19:30:31
- Zuletzt bearbeitet 21.11.2024 04:40:51
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network a...
CVE-2018-20685
- EPSS 3.68%
- Veröffentlicht 10.01.2019 21:29:00
- Zuletzt bearbeitet 17.12.2025 22:15:55
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
CVE-2018-20662
- EPSS 2.26%
- Veröffentlicht 03.01.2019 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:57
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is m...
CVE-2018-20650
- EPSS 2.68%
- Veröffentlicht 01.01.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:56
A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.
CVE-2018-18311
- EPSS 11.68%
- Veröffentlicht 07.12.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:40
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
CVE-2018-8787
- EPSS 8.36%
- Veröffentlicht 29.11.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:18
FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdi_Bitmap_Decompress() and results in a memory corruption and probably even a remote code execution.
CVE-2018-12121
- EPSS 10.21%
- Veröffentlicht 28.11.2018 17:29:00
- Zuletzt bearbeitet 08.10.2026 22:16:44
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and carefully timed completion of ...
CVE-2018-18897
- EPSS 1.96%
- Veröffentlicht 02.11.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:50
An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo.
CVE-2018-3214
- EPSS 7%
- Veröffentlicht 17.10.2018 01:31:23
- Zuletzt bearbeitet 21.11.2024 04:05:27
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Sound). Supported versions that are affected are Java SE: 6u201, 7u191 and 8u182; Java SE Embedded: 8u181; JRockit: R28.3.19. Easily exploitable vulner...
CVE-2018-3180
- EPSS 3.39%
- Veröffentlicht 17.10.2018 01:31:20
- Zuletzt bearbeitet 21.11.2024 04:05:21
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181; JRockit: R28.3.19. Difficult to exploit v...