CVE-2018-18227
- EPSS 1.84%
- Veröffentlicht 12.10.2018 06:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:34
In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector could crash. This was addressed in epan/dissectors/packet-mswsp.c by properly handling NULL return values.
CVE-2018-18225
- EPSS 1.18%
- Veröffentlicht 12.10.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:33
In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed.
CVE-2018-16758
- EPSS 0.16%
- Veröffentlicht 10.10.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:53:17
Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.
CVE-2018-16738
- EPSS 0.32%
- Veröffentlicht 10.10.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 03:53:15
tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed in 1.1.
CVE-2018-17963
- EPSS 1.53%
- Veröffentlicht 09.10.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 03:55:17
qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.
CVE-2018-17958
- EPSS 0.89%
- Veröffentlicht 09.10.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:16
Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used.
CVE-2018-17962
- EPSS 0.26%
- Veröffentlicht 09.10.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:17
Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.
CVE-2018-18088
- EPSS 0.88%
- Veröffentlicht 09.10.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:27
OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c
CVE-2018-18065
- EPSS 11.46%
- Veröffentlicht 08.10.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:25
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
CVE-2018-1000805
- EPSS 0.42%
- Veröffentlicht 08.10.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:23
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.