CVE-2018-10733
- EPSS 0.8%
- Veröffentlicht 04.05.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:56
There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.
CVE-2018-10675
- EPSS 0.04%
- Veröffentlicht 02.05.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:49
The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.
CVE-2018-10583
- EPSS 72.65%
- Veröffentlicht 01.05.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:36
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg with...
CVE-2018-10534
- EPSS 0.19%
- Veröffentlicht 29.04.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:30
The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, processes a negative Data Directory size with an unbounded loop that increases the valu...
CVE-2018-10535
- EPSS 0.12%
- Veröffentlicht 29.04.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:30
The ignore_section_sym function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, does not validate the output_section pointer in the case of a symtab entry with a "SECTION" type that has a "0" va...
CVE-2018-10372
- EPSS 0.33%
- Veröffentlicht 25.04.2018 09:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:17
process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted binary file, as demonstrated by readelf.
CVE-2018-10373
- EPSS 0.83%
- Veröffentlicht 25.04.2018 09:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:17
concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file...
CVE-2017-2885
- EPSS 13.79%
- Veröffentlicht 24.04.2018 19:29:02
- Zuletzt bearbeitet 21.11.2024 03:24:23
An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code execution. An attacker can send a special HTTP request to the vulnerable s...
CVE-2018-10322
- EPSS 0.05%
- Veröffentlicht 24.04.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:13
The xfs_dinode_verify function in fs/xfs/libxfs/xfs_inode_buf.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_ilock_attr_map_shared invalid pointer dereference) via a crafted xfs image.
CVE-2018-1106
- EPSS 0.03%
- Veröffentlicht 23.04.2018 20:29:14
- Zuletzt bearbeitet 21.11.2024 03:59:11
An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a...