CVE-2018-16839
- EPSS 0.29%
- Veröffentlicht 31.10.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:25
Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to denial of service.
CVE-2018-18873
- EPSS 0.45%
- Veröffentlicht 31.10.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:47
An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.
CVE-2018-16468
- EPSS 0.31%
- Veröffentlicht 30.10.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:48
In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
CVE-2018-18281
- EPSS 0.42%
- Veröffentlicht 30.10.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:38
Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(), a stale TLB entry can remain f...
CVE-2018-0734
- EPSS 6.05%
- Veröffentlicht 30.10.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:50
The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1....
CVE-2018-0735
- EPSS 7.04%
- Veröffentlicht 29.10.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:50
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in Ope...
CVE-2018-18718
- EPSS 0.13%
- Veröffentlicht 29.10.2018 12:29:06
- Zuletzt bearbeitet 21.11.2024 03:56:26
An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the add_themes_from_dir method in dlg-contact-sheet.c because of two successive calls of g_free, each of which frees the same buffer.
CVE-2018-18710
- EPSS 0.04%
- Veröffentlicht 29.10.2018 12:29:05
- Zuletzt bearbeitet 21.11.2024 03:56:25
An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_disc in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds c...
CVE-2018-18690
- EPSS 0.06%
- Veröffentlicht 26.10.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:22
In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could make this filesystem non-operational until the next mount by triggering an unchecked error condition during an xfs attribute change, because xfs_attr_...
CVE-2018-15686
- EPSS 1.13%
- Veröffentlicht 26.10.2018 14:29:00
- Zuletzt bearbeitet 09.06.2025 16:15:28
A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affec...