CVE-2018-12020
- EPSS 1.56%
- Veröffentlicht 08.06.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:25
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" optio...
CVE-2018-1000199
- EPSS 0.17%
- Veröffentlicht 24.05.2018 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:39:55
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptra...
CVE-2018-1126
- EPSS 0.3%
- Veröffentlicht 23.05.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:14
procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124.
CVE-2018-3639
- EPSS 44.99%
- Veröffentlicht 22.05.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 04:05:48
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access vi...
CVE-2018-1087
- EPSS 0.04%
- Veröffentlicht 15.05.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:09
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS ...
CVE-2018-10675
- EPSS 0.04%
- Veröffentlicht 02.05.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:49
The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.
CVE-2018-10392
- EPSS 1.36%
- Veröffentlicht 26.04.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:19
mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a ...
CVE-2018-10393
- EPSS 0.35%
- Veröffentlicht 26.04.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:19
bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.
CVE-2017-2885
- EPSS 13.79%
- Veröffentlicht 24.04.2018 19:29:02
- Zuletzt bearbeitet 21.11.2024 03:24:23
An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code execution. An attacker can send a special HTTP request to the vulnerable s...
CVE-2018-1106
- EPSS 0.03%
- Veröffentlicht 23.04.2018 20:29:14
- Zuletzt bearbeitet 21.11.2024 03:59:11
An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a...