CVE-2018-16873
- EPSS 63.39%
- Published 14.12.2018 14:29:00
- Last modified 21.11.2024 03:53:29
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directly or indirectly. Specifically,...
CVE-2018-16874
- EPSS 12.67%
- Published 14.12.2018 14:29:00
- Last modified 21.11.2024 03:53:30
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters). Specifically, it is only v...
CVE-2018-19539
- EPSS 1.01%
- Published 26.11.2018 03:29:00
- Last modified 21.11.2024 03:58:07
An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service.
CVE-2018-19540
- EPSS 0.77%
- Published 26.11.2018 03:29:00
- Last modified 21.11.2024 03:58:07
An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29...
CVE-2018-19541
- EPSS 1.23%
- Published 26.11.2018 03:29:00
- Last modified 21.11.2024 03:58:07
An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29...
CVE-2018-19542
- EPSS 1.01%
- Published 26.11.2018 03:29:00
- Last modified 21.11.2024 03:58:07
An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.
CVE-2018-19543
- EPSS 0.36%
- Published 26.11.2018 03:29:00
- Last modified 21.11.2024 03:58:07
An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.
CVE-2018-18873
- EPSS 0.47%
- Published 31.10.2018 16:29:00
- Last modified 21.11.2024 03:56:47
An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.
CVE-2018-18584
- EPSS 2.79%
- Published 23.10.2018 02:29:00
- Last modified 21.11.2024 03:56:12
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
CVE-2018-18585
- EPSS 0.48%
- Published 23.10.2018 02:29:00
- Last modified 21.11.2024 03:56:12
chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).