CVE-2018-7208
- EPSS 0.19%
- Published 18.02.2018 04:29:00
- Last modified 21.11.2024 04:11:47
In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, an index is not validated, which allows remote attackers to cause a denial of service (segmentation fault)...
CVE-2018-1049
- EPSS 0.76%
- Published 16.02.2018 21:29:00
- Last modified 21.11.2024 03:59:04
In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will h...
CVE-2018-6927
- EPSS 0.06%
- Published 12.02.2018 19:29:01
- Last modified 21.11.2024 04:11:26
The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact by triggering a negative wake or requeue value.
CVE-2018-1000026
- EPSS 0.87%
- Published 09.02.2018 23:29:00
- Last modified 21.11.2024 03:39:27
Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear...
CVE-2018-6871
- EPSS 42.68%
- Published 09.02.2018 06:29:00
- Last modified 21.11.2024 04:11:20
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
CVE-2018-6574
- EPSS 31.64%
- Published 07.02.2018 21:29:00
- Last modified 21.11.2024 04:10:55
Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not bloc...
- EPSS 5.04%
- Published 06.02.2018 21:29:00
- Last modified 21.11.2024 04:07:37
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player's quality of service functionality. A successful attack can lead t...
CVE-2018-4878
- EPSS 93.16%
- Published 06.02.2018 21:29:00
- Last modified 13.02.2025 17:38:59
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbi...
CVE-2018-6560
- EPSS 0.09%
- Published 02.02.2018 14:29:01
- Last modified 21.11.2024 04:10:54
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in...
CVE-2018-6485
- EPSS 0.73%
- Published 01.02.2018 14:29:00
- Last modified 21.11.2024 04:10:45
An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to ...