CVE-2018-19623
- EPSS 2.06%
- Veröffentlicht 29.11.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:18
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the LBMPDM dissector could crash. In addition, a remote attacker could write arbitrary data to any memory locations before the packet-scoped memory. This was addressed in epan/dissectors/packet-lbmpdm....
CVE-2018-19624
- EPSS 0.27%
- Veröffentlicht 29.11.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:18
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the PVFS dissector could crash. This was addressed in epan/dissectors/packet-pvfs2.c by preventing a NULL pointer dereference.
CVE-2018-19625
- EPSS 0.27%
- Veröffentlicht 29.11.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:18
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the dissection engine could crash. This was addressed in epan/tvbuff_composite.c by preventing a heap-based buffer over-read.
CVE-2018-19626
- EPSS 0.27%
- Veröffentlicht 29.11.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:18
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash. This was addressed in epan/dissectors/packet-dcom.c by adding '\0' termination.
CVE-2018-19627
- EPSS 18.64%
- Veröffentlicht 29.11.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:18
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer boundary.
CVE-2018-19628
- EPSS 0.92%
- Veröffentlicht 29.11.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:58:18
In Wireshark 2.6.0 to 2.6.4, the ZigBee ZCL dissector could crash. This was addressed in epan/dissectors/packet-zbee-zcl-lighting.c by preventing a divide-by-zero error.
CVE-2018-14629
- EPSS 9.24%
- Veröffentlicht 28.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:27
A denial of service vulnerability was discovered in Samba's LDAP server before versions 4.7.12, 4.8.7, and 4.9.3. A CNAME loop could lead to infinite recursion in the server. An unprivileged local attacker could create such an entry, leading to denia...
CVE-2018-16841
- EPSS 7.11%
- Veröffentlicht 28.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:25
Samba from version 4.3.0 and before versions 4.7.12, 4.8.7 and 4.9.3 are vulnerable to a denial of service. When configured to accept smart-card authentication, Samba's KDC will call talloc_free() twice on the same memory if the principal in a validl...
CVE-2018-16851
- EPSS 9.2%
- Veröffentlicht 28.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:26
Samba from version 4.0.0 and before versions 4.7.12, 4.8.7, 4.9.3 is vulnerable to a denial of service. During the processing of an LDAP search before Samba's AD DC returns the LDAP entries to the client, the entries are cached in a single memory obj...
CVE-2018-16862
- EPSS 0.03%
- Veröffentlicht 26.11.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:28
A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The new file created with the same inode may contain leftover pages from cleancache and the old file data ...