CVE-2018-16845
- EPSS 6.33%
- Veröffentlicht 07.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:25
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using ...
CVE-2018-19052
- EPSS 58.17%
- Veröffentlicht 07.11.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:14
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a...
CVE-2018-18544
- EPSS 0.15%
- Veröffentlicht 21.10.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:07
There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsMagick before 1.3.31.
CVE-2018-18520
- EPSS 0.89%
- Veröffentlicht 19.10.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:05
An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar files inside ar files, handle_ar in size.c closes the outer ar file before handling all inner entrie...
CVE-2018-18521
- EPSS 0.11%
- Veröffentlicht 19.10.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:05
Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize i...
CVE-2017-5934
- EPSS 0.65%
- Veröffentlicht 15.10.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:28:42
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-18310
- EPSS 0.09%
- Veröffentlicht 15.10.2018 02:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:40
An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated b...
CVE-2018-18225
- EPSS 1.18%
- Veröffentlicht 12.10.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:33
In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed.
CVE-2018-18074
- EPSS 0.18%
- Veröffentlicht 09.10.2018 17:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:26
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
CVE-2018-12477
- EPSS 0.32%
- Veröffentlicht 09.10.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:17
A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote attackers to cause deletion of directories by tricking obs-service-refresh_patches to delete them. Affected releases are openSUSE Open Build Service: versio...