CVE-2018-19052
- EPSS 37.42%
- Published 07.11.2018 05:29:00
- Last modified 21.11.2024 03:57:14
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a...
CVE-2018-18544
- EPSS 0.15%
- Published 21.10.2018 01:29:00
- Last modified 21.11.2024 03:56:07
There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsMagick before 1.3.31.
CVE-2018-18520
- EPSS 1.16%
- Published 19.10.2018 17:29:00
- Last modified 21.11.2024 03:56:05
An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar files inside ar files, handle_ar in size.c closes the outer ar file before handling all inner entrie...
CVE-2018-18521
- EPSS 0.11%
- Published 19.10.2018 17:29:00
- Last modified 21.11.2024 03:56:05
Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize i...
CVE-2017-5934
- EPSS 0.65%
- Published 15.10.2018 19:29:00
- Last modified 21.11.2024 03:28:42
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-18310
- EPSS 0.09%
- Published 15.10.2018 02:29:00
- Last modified 21.11.2024 03:55:40
An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated b...
CVE-2018-18225
- EPSS 1.18%
- Published 12.10.2018 06:29:00
- Last modified 21.11.2024 03:55:33
In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed.
CVE-2018-18074
- EPSS 0.18%
- Published 09.10.2018 17:29:01
- Last modified 21.11.2024 03:55:26
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
CVE-2018-12477
- EPSS 0.32%
- Published 09.10.2018 13:29:00
- Last modified 21.11.2024 03:45:17
A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote attackers to cause deletion of directories by tricking obs-service-refresh_patches to delete them. Affected releases are openSUSE Open Build Service: versio...
CVE-2018-14647
- EPSS 1.9%
- Published 25.09.2018 00:29:00
- Last modified 21.11.2024 03:49:30
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions ...