CVE-2018-16866
- EPSS 0.1%
- Veröffentlicht 11.01.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:28
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.
CVE-2018-4180
- EPSS 0.2%
- Veröffentlicht 11.01.2019 18:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:55
In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.
CVE-2018-4181
- EPSS 0.19%
- Veröffentlicht 11.01.2019 18:29:01
- Zuletzt bearbeitet 21.11.2024 04:06:55
In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.
CVE-2019-6133
- EPSS 0.02%
- Veröffentlicht 11.01.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:00
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendin...
CVE-2019-6128
- EPSS 1.24%
- Veröffentlicht 11.01.2019 05:29:01
- Zuletzt bearbeitet 21.11.2024 04:45:59
The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb.
CVE-2018-20685
- EPSS 3.38%
- Veröffentlicht 10.01.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:59
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
CVE-2019-3498
- EPSS 2.02%
- Veröffentlicht 09.01.2019 23:29:05
- Zuletzt bearbeitet 21.11.2024 04:42:08
In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defaults.page_not_found(), leading to content spoofing ...
CVE-2018-6174
- EPSS 1.98%
- Veröffentlicht 09.01.2019 19:29:11
- Zuletzt bearbeitet 21.11.2024 04:10:13
Integer overflows in Swiftshader in Google Chrome prior to 68.0.3440.75 potentially allowed a remote attacker to execute arbitrary code via a crafted HTML page.
CVE-2018-6175
- EPSS 0.95%
- Veröffentlicht 09.01.2019 19:29:11
- Zuletzt bearbeitet 21.11.2024 04:10:13
Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
CVE-2018-6178
- EPSS 0.49%
- Veröffentlicht 09.01.2019 19:29:11
- Zuletzt bearbeitet 21.11.2024 04:10:13
Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to Hide Chrome Security UI via a crafted Chrome Extension.