CVE-2018-16845
- EPSS 6.33%
- Veröffentlicht 07.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:25
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using ...
CVE-2018-19052
- EPSS 49.52%
- Veröffentlicht 07.11.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:14
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a...
CVE-2018-16472
- EPSS 0.52%
- Veröffentlicht 06.11.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:49
A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.
CVE-2018-9516
- EPSS 0.04%
- Veröffentlicht 06.11.2018 17:29:01
- Zuletzt bearbeitet 21.11.2024 04:15:37
In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for e...
CVE-2018-9363
- EPSS 0.03%
- Veröffentlicht 06.11.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:24
In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kerne...
CVE-2018-9422
- EPSS 0.04%
- Veröffentlicht 06.11.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:26
In get_futex_key of futex.c, there is a use-after-free due to improper locking. This could lead to local escalation of privilege with no additional privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android...
CVE-2014-10077
- EPSS 1.31%
- Veröffentlicht 06.11.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 02:03:28
Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash.
CVE-2018-18820
- EPSS 63.68%
- Veröffentlicht 05.11.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:41
A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource including a crafted header, leading to denial of s...
CVE-2018-18897
- EPSS 0.2%
- Veröffentlicht 02.11.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:50
An issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by pdftocairo.
CVE-2018-14660
- EPSS 1.6%
- Veröffentlicht 01.11.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:32
A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitivel...