CVE-2018-4117
- EPSS 1%
- Veröffentlicht 03.04.2018 06:29:04
- Zuletzt bearbeitet 21.11.2024 04:06:47
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves ...
CVE-2017-7000
- EPSS 0.62%
- Veröffentlicht 03.04.2018 06:29:01
- Zuletzt bearbeitet 21.11.2024 03:30:56
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c...
CVE-2018-1094
- EPSS 0.27%
- Veröffentlicht 02.04.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:10
The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.15.15 does not always initialize the crc32c checksum driver, which allows attackers to cause a denial of service (ext4_xattr_inode_hash NULL pointer dereference and system ...
CVE-2018-7566
- EPSS 0.13%
- Veröffentlicht 30.03.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 04:12:22
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
CVE-2018-1083
- EPSS 0.12%
- Veröffentlicht 28.03.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:08
Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to ...
CVE-2018-1312
- EPSS 8.66%
- Veröffentlicht 26.03.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:36
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication con...
CVE-2018-8976
- EPSS 0.3%
- Veröffentlicht 25.03.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:43
In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds read) via a crafted file.
CVE-2018-1000140
- EPSS 42.51%
- Veröffentlicht 23.03.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:46
rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to ...
CVE-2018-8945
- EPSS 0.17%
- Veröffentlicht 22.03.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:39
The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (segmentation fault) via a large attribute section.
CVE-2018-8905
- EPSS 1.14%
- Veröffentlicht 22.03.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:34
In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as demonstrated by tiff2ps.