CVE-2015-9268
- EPSS 0.57%
- Veröffentlicht 01.10.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 02:40:12
Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime.
CVE-2018-14648
- EPSS 4.25%
- Veröffentlicht 28.09.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:30
A flaw was found in 389 Directory Server. A specially crafted search query could lead to excessive CPU consumption in the do_search() function. An unauthenticated attacker could use this flaw to provoke a denial of service.
CVE-2018-17581
- EPSS 0.23%
- Veröffentlicht 28.09.2018 09:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:38
CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service.
CVE-2018-16587
- EPSS 0.49%
- Veröffentlicht 28.09.2018 00:29:02
- Zuletzt bearbeitet 21.11.2024 03:53:00
In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that...
CVE-2018-16586
- EPSS 0.58%
- Veröffentlicht 28.09.2018 00:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:59
In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a logged in user opens it, the email could cause the browser to load external image...
CVE-2018-16151
- EPSS 1.69%
- Veröffentlicht 26.09.2018 21:29:01
- Zuletzt bearbeitet 03.12.2025 21:15:50
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded algorithm OID during PKCS#1 v1.5 signature verificati...
CVE-2018-16152
- EPSS 1.69%
- Veröffentlicht 26.09.2018 21:29:01
- Zuletzt bearbeitet 03.12.2025 21:15:50
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 signature ve...
CVE-2018-6054
- EPSS 1.44%
- Veröffentlicht 25.09.2018 14:29:04
- Zuletzt bearbeitet 21.11.2024 04:09:58
Use after free in WebUI in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension.
CVE-2018-6049
- EPSS 0.69%
- Veröffentlicht 25.09.2018 14:29:03
- Zuletzt bearbeitet 21.11.2024 04:09:57
Incorrect security UI in permissions prompt in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the origin to which permission is granted via a crafted HTML page.
CVE-2018-6050
- EPSS 0.91%
- Veröffentlicht 25.09.2018 14:29:03
- Zuletzt bearbeitet 21.11.2024 04:09:57
Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.