CVE-2018-18751
- EPSS 0.6%
- Veröffentlicht 29.10.2018 12:29:09
- Zuletzt bearbeitet 21.11.2024 03:56:31
An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt.
CVE-2016-10729
- EPSS 0.21%
- Veröffentlicht 24.10.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 02:44:36
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate comma...
CVE-2016-10730
- EPSS 0.1%
- Veröffentlicht 24.10.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 02:44:36
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to backup and restore data. It run...
CVE-2018-18584
- EPSS 6.37%
- Veröffentlicht 23.10.2018 02:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:12
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
CVE-2018-18438
- EPSS 0.09%
- Veröffentlicht 19.10.2018 22:29:02
- Zuletzt bearbeitet 21.11.2024 03:55:56
Qemu has integer overflows because IOReadHandler and its associated functions use a signed integer data type for a size value.
CVE-2018-12373
- EPSS 1.1%
- Veröffentlicht 18.10.2018 13:29:04
- Zuletzt bearbeitet 21.11.2024 03:45:05
dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderbird < 52.9.
CVE-2018-12374
- EPSS 0.76%
- Veröffentlicht 18.10.2018 13:29:04
- Zuletzt bearbeitet 21.11.2024 03:45:05
Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects Thunderbird < 52.9.
CVE-2018-12372
- EPSS 0.79%
- Veröffentlicht 18.10.2018 13:29:03
- Zuletzt bearbeitet 21.11.2024 03:45:04
Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 52.9.
CVE-2018-10933
- EPSS 78.63%
- Veröffentlicht 17.10.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:20
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
CVE-2018-17456
- EPSS 66.23%
- Veröffentlicht 06.10.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:27
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has ...