CVE-2018-17477
- EPSS 0.8%
- Veröffentlicht 14.11.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:30
Incorrect dialog placement in Extensions in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of extension popups via a crafted HTML page.
CVE-2018-6057
- EPSS 0.55%
- Veröffentlicht 14.11.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:58
Lack of special casing of Android ashmem in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process to bypass inter-process read only guarantees via a crafted HTML page.
CVE-2018-19115
- EPSS 6.96%
- Veröffentlicht 08.11.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:21
keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code and instead writes an unlimi...
CVE-2018-19107
- EPSS 0.3%
- Veröffentlicht 08.11.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:20
In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-based buffer over-read) caused by an integer overflow via a crafted PSD image file.
CVE-2018-19108
- EPSS 0.41%
- Veröffentlicht 08.11.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:20
In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file.
CVE-2018-19058
- EPSS 0.28%
- Veröffentlicht 07.11.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:14
An issue was discovered in Poppler 0.71.0. There is a reachable abort in Object.h, will lead to denial of service because EmbFile::save2 in FileSpec.cc lacks a stream check before saving an embedded file.
CVE-2018-18897
- EPSS 0.2%
- Veröffentlicht 02.11.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:50
An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo.
CVE-2018-14660
- EPSS 1.66%
- Veröffentlicht 01.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:32
A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitivel...
CVE-2016-2125
- EPSS 12.78%
- Veröffentlicht 31.10.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 02:47:52
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to othe...
CVE-2018-14661
- EPSS 3.1%
- Veröffentlicht 31.10.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:32
It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vulnerable to a format string attack. A remote, authenticated attacker could use this flaw to cause remot...