CVE-2018-17281
- EPSS 80.26%
- Veröffentlicht 24.09.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 03:54:10
There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a speci...
CVE-2018-17407
- EPSS 1.36%
- Veröffentlicht 23.09.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:20
An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font is loaded by one of the vulnera...
CVE-2018-17141
- EPSS 6.17%
- Veröffentlicht 21.09.2018 17:29:07
- Zuletzt bearbeitet 21.11.2024 03:53:56
HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit enabled, which is mishandled in FaxModem::writeECMData() in the faxd/CopyQuality.c++ file.
CVE-2018-17206
- EPSS 2.08%
- Veröffentlicht 19.09.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:54:05
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
CVE-2018-17204
- EPSS 1.13%
- Veröffentlicht 19.09.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:05
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The O...
CVE-2018-17183
- EPSS 0.77%
- Veröffentlicht 19.09.2018 15:29:19
- Zuletzt bearbeitet 21.11.2024 03:54:02
Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code.
CVE-2018-17182
- EPSS 6.47%
- Veröffentlicht 19.09.2018 09:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:02
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) via certain thread creation, ma...
CVE-2018-16515
- EPSS 0.57%
- Veröffentlicht 18.09.2018 21:29:03
- Zuletzt bearbeitet 21.11.2024 03:52:53
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
CVE-2018-13982
- EPSS 2.45%
- Veröffentlicht 18.09.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:48:22
Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory se...
CVE-2018-1000802
- EPSS 23.2%
- Veröffentlicht 18.09.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:23
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service...