CVE-2018-1258
- EPSS 0.16%
- Published 11.05.2018 20:29:00
- Last modified 21.11.2024 03:59:28
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted...
CVE-2018-10545
- EPSS 0.07%
- Published 29.04.2018 21:29:00
- Last modified 21.11.2024 03:41:32
An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPABLE prctl call, allowing one u...
CVE-2018-10546
- EPSS 58.92%
- Published 29.04.2018 21:29:00
- Last modified 21.11.2024 03:41:32
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not reject invalid multibyte sequences.
CVE-2018-10547
- EPSS 29.43%
- Published 29.04.2018 21:29:00
- Last modified 21.11.2024 03:41:32
An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. There is Reflected XSS on the PHAR 403 and 404 error pages via request data of a request for a .phar file. NOTE:...
CVE-2018-10548
- EPSS 65.47%
- Published 29.04.2018 21:29:00
- Last modified 21.11.2024 03:41:32
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. ext/ldap/ldap.c allows remote LDAP servers to cause a denial of service (NULL pointer dereference and application crash) because of mishan...
CVE-2018-10549
- EPSS 4.54%
- Published 29.04.2018 21:29:00
- Last modified 21.11.2024 03:41:32
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. exif_read_data in ext/exif/exif.c has an out-of-bounds read for crafted JPEG data because exif_iif_add_value mishandles the case of a Make...
CVE-2018-2846
- EPSS 0.38%
- Published 19.04.2018 02:29:06
- Last modified 21.11.2024 04:04:36
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Performance Schema). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access vi...
CVE-2018-2839
- EPSS 0.38%
- Published 19.04.2018 02:29:05
- Last modified 21.11.2024 04:04:35
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple prot...
CVE-2018-2812
- EPSS 0.4%
- Published 19.04.2018 02:29:04
- Last modified 21.11.2024 04:04:31
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multipl...
CVE-2018-2813
- EPSS 0.27%
- Published 19.04.2018 02:29:04
- Last modified 21.11.2024 04:04:31
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows low privileged attacker...