CVE-2018-1000180
- EPSS 0.24%
- Published 05.06.2018 13:29:00
- Last modified 12.05.2025 17:37:16
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. T...
CVE-2018-11212
- EPSS 0.73%
- Published 16.05.2018 17:29:00
- Last modified 21.11.2024 03:42:54
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
CVE-2018-8014
- EPSS 53.05%
- Published 16.05.2018 16:29:00
- Last modified 21.11.2024 04:13:05
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter ...
CVE-2018-1258
- EPSS 0.16%
- Published 11.05.2018 20:29:00
- Last modified 21.11.2024 03:59:28
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted...
CVE-2018-2846
- EPSS 0.38%
- Published 19.04.2018 02:29:06
- Last modified 21.11.2024 04:04:36
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Performance Schema). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access vi...
CVE-2018-2825
- EPSS 1.13%
- Published 19.04.2018 02:29:05
- Last modified 06.05.2025 15:15:56
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols t...
CVE-2018-2826
- EPSS 2.92%
- Published 19.04.2018 02:29:05
- Last modified 06.05.2025 15:15:56
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols t...
CVE-2018-2839
- EPSS 0.38%
- Published 19.04.2018 02:29:05
- Last modified 21.11.2024 04:04:35
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple prot...
CVE-2018-2810
- EPSS 0.1%
- Published 19.04.2018 02:29:04
- Last modified 21.11.2024 04:04:30
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols...
CVE-2018-2812
- EPSS 0.4%
- Published 19.04.2018 02:29:04
- Last modified 21.11.2024 04:04:31
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multipl...