CVE-2019-3862
- EPSS 5.73%
- Veröffentlicht 21.03.2019 16:01:04
- Zuletzt bearbeitet 21.11.2024 04:42:44
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Servic...
CVE-2018-20340
- EPSS 0.13%
- Veröffentlicht 21.03.2019 16:00:35
- Zuletzt bearbeitet 21.11.2024 04:01:16
Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device masquerading as a security to...
CVE-2018-19985
- EPSS 0.04%
- Veröffentlicht 21.03.2019 16:00:33
- Zuletzt bearbeitet 21.11.2024 03:58:56
The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses it to index a small array, resulting in an object out-of-bounds (OOB) read that potentially allows arbitr...
CVE-2018-18898
- EPSS 1.47%
- Veröffentlicht 21.03.2019 16:00:29
- Zuletzt bearbeitet 21.11.2024 03:56:50
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.
CVE-2018-12022
- EPSS 2.93%
- Veröffentlicht 21.03.2019 16:00:12
- Zuletzt bearbeitet 21.11.2024 03:44:25
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in ...
CVE-2018-12023
- EPSS 4.66%
- Veröffentlicht 21.03.2019 16:00:12
- Zuletzt bearbeitet 21.11.2024 03:44:26
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provid...
CVE-2018-20175
- EPSS 0.59%
- Veröffentlicht 15.03.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:00
rdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to Out-Of-Bounds Reads in the file mcs.c and result in a Denial of Service (segfault).
CVE-2018-20177
- EPSS 5.12%
- Veröffentlicht 15.03.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:01
rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in the function rdp_in_unistr() and results in memory corruption and possibly even a remote code execution.
CVE-2018-20178
- EPSS 0.59%
- Veröffentlicht 15.03.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:01
rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function process_demand_active() that results in a Denial of Service (segfault).
CVE-2018-20180
- EPSS 15.35%
- Veröffentlicht 15.03.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:01
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_process() and results in memory corruption and probably even a remote code execution.