CVE-2018-20181
- EPSS 10.07%
- Veröffentlicht 15.03.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:02
rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamless_process() and results in memory corruption and probably even a remote code execution.
CVE-2018-20182
- EPSS 10.07%
- Veröffentlicht 15.03.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:02
rdesktop versions up to and including v1.8.3 contain a Buffer Overflow over the global variables in the function seamless_process_line() that results in memory corruption and probably even a remote code execution.
CVE-2018-17937
- EPSS 4.11%
- Veröffentlicht 13.03.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:14
gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow remote attackers to execute arbitrary code on embedded platforms via traffic on Port 2947/TCP or crafted JSON i...
CVE-2019-9741
- EPSS 3.53%
- Veröffentlicht 13.03.2019 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:12
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.
CVE-2019-9735
- EPSS 2%
- Veröffentlicht 13.03.2019 02:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:12
An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't supp...
CVE-2019-9718
- EPSS 1.69%
- Veröffentlicht 12.03.2019 09:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:10
In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, because ff_htmlmarkup_to_ass in libavcodec/htmlsubtitles.c has a complex format argument to sscanf.
CVE-2019-9704
- EPSS 0.17%
- Veröffentlicht 12.03.2019 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:08
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.
CVE-2019-9705
- EPSS 0.17%
- Veröffentlicht 12.03.2019 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:08
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines is accepted.
CVE-2019-9706
- EPSS 0.06%
- Veröffentlicht 12.03.2019 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:08
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (use-after-free and daemon crash) because of a force_rescan_user error.
CVE-2019-9656
- EPSS 0.94%
- Veröffentlicht 11.03.2019 05:29:00
- Zuletzt bearbeitet 21.11.2024 04:52:03
An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump.