CVE-2018-0735
- EPSS 4.76%
- Veröffentlicht 29.10.2018 13:29:00
- Zuletzt bearbeitet 08.10.2026 22:16:43
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in Ope...
CVE-2018-18065
- EPSS 17.19%
- Veröffentlicht 08.10.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:25
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
CVE-2018-18066
- EPSS 4.3%
- Veröffentlicht 08.10.2018 18:29:00
- Zuletzt bearbeitet 06.05.2025 15:15:54
snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
CVE-2018-15919
- EPSS 3.56%
- Veröffentlicht 28.08.2018 08:29:00
- Zuletzt bearbeitet 18.12.2025 12:15:53
Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not w...
CVE-2018-15473
- EPSS 98.63%
- Veröffentlicht 17.08.2018 19:29:00
- Zuletzt bearbeitet 17.12.2025 22:15:54
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-...
CVE-2018-8011
- EPSS 56.04%
- Veröffentlicht 18.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:05
By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33).
CVE-2018-2964
- EPSS 2.77%
- Veröffentlicht 18.07.2018 13:29:03
- Zuletzt bearbeitet 21.11.2024 04:04:51
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u172 and 10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multip...
CVE-2018-2973
- EPSS 4.68%
- Veröffentlicht 18.07.2018 13:29:03
- Zuletzt bearbeitet 21.11.2024 04:04:52
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Difficult to exploit vulnerability allows unau...
- EPSS 1.94%
- Veröffentlicht 18.07.2018 13:29:02
- Zuletzt bearbeitet 21.11.2024 04:04:47
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE: 6u191, 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via mul...
CVE-2018-2940
- EPSS 3.15%
- Veröffentlicht 18.07.2018 13:29:02
- Zuletzt bearbeitet 21.11.2024 04:04:47
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Easily exploitable vulnerability allows u...