CVE-2018-2761
- EPSS 0.25%
- Veröffentlicht 19.04.2018 02:29:01
- Zuletzt bearbeitet 21.11.2024 04:04:23
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated a...
CVE-2018-10194
- EPSS 0.65%
- Veröffentlicht 18.04.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:59
The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause a denial of service (applicat...
CVE-2018-1088
- EPSS 5.68%
- Veröffentlicht 18.04.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:09
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.
CVE-2018-6797
- EPSS 1.55%
- Veröffentlicht 17.04.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:13
An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.
CVE-2018-6798
- EPSS 1.02%
- Veröffentlicht 17.04.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:13
An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.
CVE-2018-10119
- EPSS 0.16%
- Veröffentlicht 16.04.2018 09:58:10
- Zuletzt bearbeitet 21.11.2024 03:40:52
sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-free with write access) or possib...
CVE-2018-10120
- EPSS 0.15%
- Veröffentlicht 16.04.2018 09:58:10
- Zuletzt bearbeitet 21.11.2024 03:40:52
The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 and 6.x before 6.0.2.1 does not validate a customizations index, which allows remote attackers to cause a denial of service (heap-based buffer overfl...
CVE-2018-1084
- EPSS 0.8%
- Veröffentlicht 12.04.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:08
corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.
CVE-2018-1100
- EPSS 0.05%
- Veröffentlicht 11.04.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:59:10
zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the utils.c:checkmailpath function. A local attacker could exploit this to execute arbitrary code in the context of another user.
CVE-2018-1000156
- EPSS 35.17%
- Veröffentlicht 06.04.2018 13:29:00
- Zuletzt bearbeitet 14.04.2025 20:15:16
GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via th...