CVE-2018-16874
- EPSS 10.79%
- Published 14.12.2018 14:29:00
- Last modified 21.11.2024 03:53:30
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters). Specifically, it is only v...
CVE-2018-16872
- EPSS 0.27%
- Published 13.12.2018 21:29:00
- Last modified 21.11.2024 03:53:29
A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_partial_object and directories in usb_mtp_object_readdir doesn't consider that the underlying filesystem may have changed since the t...
CVE-2018-19364
- EPSS 0.08%
- Published 13.12.2018 19:29:00
- Last modified 21.11.2024 03:57:48
hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading to (for example) a use-after-free outcome.
CVE-2018-19489
- EPSS 0.06%
- Published 13.12.2018 19:29:00
- Last modified 21.11.2024 03:58:00
v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race condition during file renaming.
CVE-2018-20097
- EPSS 0.63%
- Published 12.12.2018 10:29:00
- Last modified 21.11.2024 04:00:52
There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
CVE-2018-19968
- EPSS 2.64%
- Published 11.12.2018 17:29:00
- Last modified 21.11.2024 03:58:54
An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created...
CVE-2018-19970
- EPSS 1.56%
- Published 11.12.2018 17:29:00
- Last modified 21.11.2024 03:58:54
In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.
CVE-2018-18357
- EPSS 0.95%
- Published 11.12.2018 16:29:02
- Last modified 21.11.2024 03:55:47
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.
CVE-2018-18358
- EPSS 0.12%
- Published 11.12.2018 16:29:02
- Last modified 21.11.2024 03:55:47
Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.
CVE-2018-18359
- EPSS 1.2%
- Published 11.12.2018 16:29:02
- Last modified 21.11.2024 03:55:47
Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.