CVE-2018-16873
- EPSS 63.39%
- Veröffentlicht 14.12.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:29
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directly or indirectly. Specifically,...
CVE-2018-16874
- EPSS 12.67%
- Veröffentlicht 14.12.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:30
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters). Specifically, it is only v...
CVE-2018-16875
- EPSS 0.96%
- Veröffentlicht 14.12.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:30
The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers ...
CVE-2018-16872
- EPSS 0.27%
- Veröffentlicht 13.12.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:29
A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_partial_object and directories in usb_mtp_object_readdir doesn't consider that the underlying filesystem may have changed since the t...
CVE-2018-19364
- EPSS 0.05%
- Veröffentlicht 13.12.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:48
hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading to (for example) a use-after-free outcome.
CVE-2018-19489
- EPSS 0.04%
- Veröffentlicht 13.12.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:00
v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race condition during file renaming.
CVE-2018-18356
- EPSS 2.61%
- Veröffentlicht 11.12.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:46
An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2018-18335
- EPSS 1.8%
- Veröffentlicht 11.12.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:44
Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2018-19665
- EPSS 1.17%
- Veröffentlicht 06.12.2018 23:29:01
- Zuletzt bearbeitet 21.11.2024 03:58:23
The Bluetooth subsystem in QEMU mishandles negative values for length variables, leading to memory corruption.
CVE-2018-19865
- EPSS 0.8%
- Veröffentlicht 05.12.2018 11:29:06
- Zuletzt bearbeitet 21.11.2024 03:58:43
A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.