CVE-2018-16509
- EPSS 91.74%
- Veröffentlicht 05.09.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:52
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instr...
CVE-2018-16511
- EPSS 0.37%
- Veröffentlicht 05.09.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:52
An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact.
CVE-2018-10911
- EPSS 4.26%
- Veröffentlicht 04.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:17
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
CVE-2018-16435
- EPSS 0.43%
- Veröffentlicht 04.09.2018 00:29:02
- Zuletzt bearbeitet 21.11.2024 03:52:44
Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile...
CVE-2018-16402
- EPSS 1.52%
- Veröffentlicht 03.09.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:40
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
CVE-2018-14622
- EPSS 2.34%
- Veröffentlicht 30.08.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:26
A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file de...
CVE-2018-12825
- EPSS 1.35%
- Veröffentlicht 29.08.2018 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:45:53
Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitation could lead to security mitigation bypass.
CVE-2018-12826
- EPSS 2.08%
- Veröffentlicht 29.08.2018 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:45:53
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
CVE-2018-12827
- EPSS 8.65%
- Veröffentlicht 29.08.2018 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:45:54
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
CVE-2018-12828
- EPSS 1.55%
- Veröffentlicht 29.08.2018 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:45:54
Adobe Flash Player 30.0.0.134 and earlier have a "use of a component with a known vulnerability" vulnerability. Successful exploitation could lead to privilege escalation.