CVE-2018-14645
- EPSS 0.23%
- Published 21.09.2018 13:29:00
- Last modified 21.11.2024 03:49:29
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
CVE-2016-7056
- EPSS 0.33%
- Published 10.09.2018 16:29:00
- Last modified 21.11.2024 02:57:22
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
- EPSS 0.37%
- Published 05.09.2018 19:29:00
- Last modified 21.11.2024 03:49:26
curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocat...
CVE-2018-16540
- EPSS 0.28%
- Published 05.09.2018 18:29:00
- Last modified 21.11.2024 03:52:56
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.
CVE-2018-16542
- EPSS 0.43%
- Published 05.09.2018 18:29:00
- Last modified 21.11.2024 03:52:56
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter.
CVE-2018-10930
- EPSS 0.63%
- Published 04.09.2018 16:29:00
- Last modified 21.11.2024 03:42:19
A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.
CVE-2018-10926
- EPSS 0.79%
- Published 04.09.2018 15:29:00
- Last modified 21.11.2024 03:42:19
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execute arbitrary code on a glusterfs server node.
CVE-2018-10928
- EPSS 0.85%
- Published 04.09.2018 15:29:00
- Last modified 21.11.2024 03:42:19
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing any...
CVE-2018-10936
- EPSS 1.35%
- Published 30.08.2018 13:29:00
- Last modified 21.11.2024 03:42:20
A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle atta...
CVE-2018-14622
- EPSS 2.34%
- Published 30.08.2018 13:29:00
- Last modified 21.11.2024 03:49:26
A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file de...