CVE-2018-20024
- EPSS 3.79%
- Veröffentlicht 19.12.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:00:46
LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS.
CVE-2018-6307
- EPSS 9.8%
- Veröffentlicht 19.12.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:10:27
LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution.
CVE-2018-19790
- EPSS 0.47%
- Veröffentlicht 18.12.2018 22:29:05
- Zuletzt bearbeitet 21.11.2024 03:58:33
An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacke...
- EPSS 0.13%
- Veröffentlicht 18.12.2018 22:29:04
- Zuletzt bearbeitet 21.11.2024 03:53:31
A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container ...
CVE-2018-19789
- EPSS 0.9%
- Veröffentlicht 18.12.2018 22:29:04
- Zuletzt bearbeitet 21.11.2024 03:58:33
An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x before 4.2.1. When using the scalar type hint `string` in a setter method (e.g. `setName(string $name)`...
CVE-2018-20196
- EPSS 0.38%
- Veröffentlicht 18.12.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:04
There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. A crafted input will lead to a denial of service or possibly unspecified other impa...
CVE-2018-20199
- EPSS 0.5%
- Veröffentlicht 18.12.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:05
A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service because adding t...
CVE-2018-20189
- EPSS 0.63%
- Veröffentlicht 17.12.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:03
In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is crafted to appear with direct pixel values and also colormapping (which is not available beyond 8-bi...
CVE-2018-20184
- EPSS 0.27%
- Veröffentlicht 17.12.2018 19:29:03
- Zuletzt bearbeitet 21.11.2024 04:01:02
In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to cause a denial of service via a crafted image file, because the number of rows or columns can exceed t...
CVE-2018-20185
- EPSS 0.88%
- Veröffentlicht 17.12.2018 19:29:03
- Zuletzt bearbeitet 21.11.2024 04:01:02
In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage function of bmp.c, which allows attackers to cause a denial of service via a crafted bmp image file. This only affects Graphics...