CVE-2018-18506
- EPSS 2.44%
- Published 05.02.2019 21:29:00
- Last modified 21.11.2024 03:56:04
When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This b...
CVE-2019-1000019
- EPSS 1.91%
- Published 04.02.2019 21:29:01
- Last modified 21.11.2024 04:17:41
libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_format_7zip.c, header_bytes() that can result in a cr...
CVE-2019-1000020
- EPSS 1.09%
- Published 04.02.2019 21:29:01
- Last modified 21.11.2024 04:17:41
libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ISO9660 parser, archive_read_support_format_iso9660.c, rea...
CVE-2019-3813
- EPSS 0.26%
- Published 04.02.2019 18:29:00
- Last modified 21.11.2024 04:42:35
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
CVE-2019-7317
- EPSS 0.99%
- Published 04.02.2019 08:29:00
- Last modified 21.11.2024 04:48:00
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
CVE-2019-7310
- EPSS 0.31%
- Published 03.02.2019 03:29:00
- Last modified 21.11.2024 04:47:58
In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a c...
CVE-2019-7150
- EPSS 0.1%
- Published 29.01.2019 00:29:00
- Last modified 21.11.2024 04:47:40
An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted inp...
CVE-2019-3815
- EPSS 0.14%
- Published 28.01.2019 15:29:00
- Last modified 21.11.2024 04:42:35
A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A...
CVE-2018-16881
- EPSS 2.77%
- Published 25.01.2019 18:29:00
- Last modified 21.11.2024 03:53:31
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
- EPSS 93.43%
- Published 18.01.2019 17:29:01
- Last modified 13.02.2025 17:40:13
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.