CVE-2018-1000888
- EPSS 29.48%
- Veröffentlicht 28.12.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:40:35
PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When extract is ca...
CVE-2018-20511
- EPSS 0.07%
- Veröffentlicht 27.12.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:38
An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route dev and next f...
CVE-2018-19870
- EPSS 1.69%
- Veröffentlicht 26.12.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:58:43
An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault.
CVE-2018-19873
- EPSS 4.65%
- Veröffentlicht 26.12.2018 21:29:02
- Zuletzt bearbeitet 11.02.2025 20:11:38
An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.
CVE-2018-20217
- EPSS 2.38%
- Veröffentlicht 26.12.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 04:01:06
A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17. If an attacker can obtain a krbtgt ticket using an older encryption type (single-DES, triple-DES, or RC4), the attacker can crash the KDC by making an S4U...
CVE-2018-15518
- EPSS 2.31%
- Veröffentlicht 26.12.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:50:59
QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.
CVE-2018-20482
- EPSS 0.02%
- Veröffentlicht 26.12.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:34
GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c) by modifying a file that is supposed to be archive...
CVE-2018-20481
- EPSS 1.19%
- Veröffentlicht 26.12.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:34
XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when XRefEntry::setFlag in XRef.h is called from Parser...
CVE-2018-20467
- EPSS 0.37%
- Veröffentlicht 26.12.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:32
In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.
CVE-2018-20433
- EPSS 2.4%
- Veröffentlicht 24.12.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:28
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.