CVE-2018-16864
- EPSS 0.15%
- Veröffentlicht 11.01.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:28
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash s...
CVE-2018-11237
- EPSS 0.59%
- Veröffentlicht 18.05.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:58
An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupper.
CVE-2018-11236
- EPSS 0.89%
- Veröffentlicht 18.05.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:57
stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer over...
CVE-2018-6485
- EPSS 0.73%
- Veröffentlicht 01.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:10:45
An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to ...
- EPSS 0.2%
- Veröffentlicht 21.07.2016 10:13:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communications Applications before PCz 2.0.0m4p1 allows remote authenticated users to affect confidentiality via vectors related to GUI, a different vulnerab...
CVE-2016-3515
- EPSS 1.49%
- Veröffentlicht 21.07.2016 10:13:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communications Applications before PCz 2.0.0m4p1 allows remote attackers to affect confidentiality via unknown vectors.
CVE-2016-3514
- EPSS 0.63%
- Veröffentlicht 21.07.2016 10:13:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communications Applications before PCz 2.0.0m4p1 allows remote authenticated users to affect confidentiality via vectors related to GUI, a different vulnerab...
- EPSS 4.51%
- Veröffentlicht 31.03.2015 14:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".