CVE-2018-20749
- EPSS 10.91%
- Published 30.01.2019 18:29:00
- Last modified 21.11.2024 04:02:05
LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.
CVE-2018-20750
- EPSS 10.91%
- Published 30.01.2019 18:29:00
- Last modified 21.11.2024 04:02:05
LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.
CVE-2019-7149
- EPSS 0.34%
- Published 29.01.2019 00:29:00
- Last modified 21.11.2024 04:47:39
A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by eu-nm.
CVE-2019-7150
- EPSS 0.1%
- Published 29.01.2019 00:29:00
- Last modified 21.11.2024 04:47:40
An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted inp...
CVE-2019-3462
- EPSS 7.37%
- Published 28.01.2019 21:29:00
- Last modified 21.11.2024 04:42:05
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.
CVE-2019-3815
- EPSS 0.14%
- Published 28.01.2019 15:29:00
- Last modified 21.11.2024 04:42:35
A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A...
CVE-2019-6978
- EPSS 3.68%
- Published 28.01.2019 08:29:00
- Last modified 21.11.2024 04:47:21
The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected.
CVE-2019-6977
- EPSS 89.15%
- Published 27.01.2019 02:29:00
- Last modified 21.11.2024 04:47:20
gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This c...
CVE-2019-6799
- EPSS 70.65%
- Published 26.01.2019 17:29:00
- Last modified 21.11.2024 04:47:10
An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is r...
CVE-2018-16881
- EPSS 2.77%
- Published 25.01.2019 18:29:00
- Last modified 21.11.2024 03:53:31
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.