CVE-2018-20662
- EPSS 0.59%
- Veröffentlicht 03.01.2019 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:57
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is m...
CVE-2018-20650
- EPSS 0.36%
- Veröffentlicht 01.01.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:56
A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach.
CVE-2018-19134
- EPSS 1.31%
- Veröffentlicht 20.12.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:23
In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscri...
CVE-2018-1000876
- EPSS 0.13%
- Veröffentlicht 20.12.2018 17:29:01
- Zuletzt bearbeitet 21.11.2024 03:40:33
binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows executi...
CVE-2018-1000877
- EPSS 1.78%
- Veröffentlicht 20.12.2018 17:29:01
- Zuletzt bearbeitet 21.11.2024 03:40:33
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lzss.window, ...
CVE-2018-1000878
- EPSS 1.71%
- Veröffentlicht 20.12.2018 17:29:01
- Zuletzt bearbeitet 21.11.2024 03:40:33
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is un...
CVE-2018-15127
- EPSS 15.14%
- Veröffentlicht 19.12.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:50:21
LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution
CVE-2018-19039
- EPSS 9.22%
- Veröffentlicht 13.12.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:12
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
CVE-2018-18397
- EPSS 0.07%
- Veröffentlicht 12.12.2018 10:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:52
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that fil...
CVE-2018-20097
- EPSS 0.64%
- Veröffentlicht 12.12.2018 10:29:00
- Zuletzt bearbeitet 21.11.2024 04:00:52
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.