CVE-2018-15688
- EPSS 0.73%
- Veröffentlicht 26.10.2018 14:29:00
- Zuletzt bearbeitet 09.06.2025 16:15:28
A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.
CVE-2018-14665
- EPSS 14.46%
- Veröffentlicht 25.10.2018 20:29:00
- Zuletzt bearbeitet 29.08.2025 13:42:30
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate the...
CVE-2016-10729
- EPSS 0.21%
- Veröffentlicht 24.10.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 02:44:36
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate comma...
CVE-2018-18605
- EPSS 0.42%
- Veröffentlicht 23.10.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:14
A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, because _bfd_add_merge_section mishandles section merge...
CVE-2018-18606
- EPSS 0.68%
- Veröffentlicht 23.10.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:14
An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in _bfd_add_merge_section when attempting to merge sec...
CVE-2018-18607
- EPSS 0.37%
- Veröffentlicht 23.10.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:14
An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in elf_link_input_bfd when used for finding STT_TLS symbols ...
CVE-2018-16837
- EPSS 0.04%
- Veröffentlicht 23.10.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:24
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear te...
CVE-2018-18584
- EPSS 6.37%
- Veröffentlicht 23.10.2018 02:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:12
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
CVE-2018-18585
- EPSS 1.46%
- Veröffentlicht 23.10.2018 02:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:12
chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).
CVE-2018-18557
- EPSS 32.24%
- Veröffentlicht 22.10.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:09
LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 (with JBIG enabled) decodes arbitrarily-sized JBIG into a buffer, ignorin...