CVE-2018-19490
- EPSS 0.17%
- Veröffentlicht 23.11.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:00
An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an o...
CVE-2018-19491
- EPSS 0.17%
- Veröffentlicht 23.11.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:00
An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of an argument passed to the "se...
CVE-2018-19492
- EPSS 0.17%
- Veröffentlicht 23.11.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:01
An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to ...
CVE-2018-19475
- EPSS 63.59%
- Veröffentlicht 23.11.2018 05:29:03
- Zuletzt bearbeitet 21.11.2024 03:57:59
psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.
CVE-2018-19476
- EPSS 0.82%
- Veröffentlicht 23.11.2018 05:29:03
- Zuletzt bearbeitet 21.11.2024 03:57:59
psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.
CVE-2018-19477
- EPSS 0.82%
- Veröffentlicht 23.11.2018 05:29:03
- Zuletzt bearbeitet 21.11.2024 03:57:59
psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.
CVE-2018-19432
- EPSS 0.97%
- Veröffentlicht 22.11.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:54
An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfile.c, which will lead to a denial of service.
CVE-2018-19409
- EPSS 10.2%
- Veröffentlicht 21.11.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:52
An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.
CVE-2018-19274
- EPSS 14.46%
- Veröffentlicht 17.11.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:39
Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.
CVE-2018-16396
- EPSS 3.29%
- Veröffentlicht 16.11.2018 18:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:40
An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.