CVE-2018-19052
- EPSS 37.42%
- Veröffentlicht 07.11.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:14
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a...
CVE-2018-18544
- EPSS 0.15%
- Veröffentlicht 21.10.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:07
There is a memory leak in the function WriteMSLImage of coders/msl.c in ImageMagick 7.0.8-13 Q16, and the function ProcessMSLScript of coders/msl.c in GraphicsMagick before 1.3.31.
CVE-2018-18520
- EPSS 1.16%
- Veröffentlicht 19.10.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:05
An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar files inside ar files, handle_ar in size.c closes the outer ar file before handling all inner entrie...
CVE-2018-18521
- EPSS 0.11%
- Veröffentlicht 19.10.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:05
Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize i...
CVE-2017-5934
- EPSS 0.65%
- Veröffentlicht 15.10.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:28:42
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-18310
- EPSS 0.09%
- Veröffentlicht 15.10.2018 02:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:40
An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated b...
CVE-2018-18225
- EPSS 1.18%
- Veröffentlicht 12.10.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:33
In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed.
CVE-2018-18074
- EPSS 0.18%
- Veröffentlicht 09.10.2018 17:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:26
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
CVE-2018-12477
- EPSS 0.32%
- Veröffentlicht 09.10.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:17
A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote attackers to cause deletion of directories by tricking obs-service-refresh_patches to delete them. Affected releases are openSUSE Open Build Service: versio...
CVE-2018-14647
- EPSS 1.9%
- Veröffentlicht 25.09.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:30
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions ...