CVE-2018-0735
- EPSS 9.26%
- Veröffentlicht 29.10.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:50
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in Ope...
CVE-2018-15756
- EPSS 13.38%
- Veröffentlicht 18.10.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:24
Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler,...
CVE-2018-11763
- EPSS 17.4%
- Veröffentlicht 25.09.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:58
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitiga...
CVE-2018-11058
- EPSS 1.73%
- Veröffentlicht 14.09.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:35
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior to 4.0.5.3 (in 4.0.x) contain a Buffer Over-Read vulnerability when parsing ASN.1 data. A remote att...
CVE-2018-11054
- EPSS 2.35%
- Veröffentlicht 31.08.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:34
RSA BSAFE Micro Edition Suite, version 4.1.6, contains an integer overflow vulnerability. A remote attacker could use maliciously constructed ASN.1 data to potentially cause a Denial Of Service.
CVE-2018-11055
- EPSS 0.09%
- Veröffentlicht 31.08.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:34
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release ('Heap Inspection') vulnerability. Decoded PKCS #12 data in heap memory is not zeroized by...
CVE-2018-11056
- EPSS 1.96%
- Veröffentlicht 31.08.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:35
RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.3 (in 4.0.x) contain an Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerability when parsing ASN.1 data. A remote...
CVE-2018-11057
- EPSS 0.62%
- Veröffentlicht 31.08.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:35
RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be...
CVE-2018-2976
- EPSS 1.78%
- Veröffentlicht 18.07.2018 13:29:03
- Zuletzt bearbeitet 21.11.2024 04:04:52
Vulnerability in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Products Suite (subcomponent: Networking). The supported version that is affected is 12.2.2. Easily exploitable vulnerability allows unauthenticated attacker wi...
CVE-2018-11039
- EPSS 2.92%
- Veröffentlicht 25.06.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:32
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring ...