CVE-2018-17407
- EPSS 1.36%
- Veröffentlicht 23.09.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:20
An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font is loaded by one of the vulnera...
CVE-2018-17141
- EPSS 5.87%
- Veröffentlicht 21.09.2018 17:29:07
- Zuletzt bearbeitet 21.11.2024 03:53:56
HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit enabled, which is mishandled in FaxModem::writeECMData() in the faxd/CopyQuality.c++ file.
CVE-2018-17206
- EPSS 2.08%
- Veröffentlicht 19.09.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:54:05
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
CVE-2018-17204
- EPSS 1.13%
- Veröffentlicht 19.09.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:05
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The O...
CVE-2018-17183
- EPSS 0.35%
- Veröffentlicht 19.09.2018 15:29:19
- Zuletzt bearbeitet 21.11.2024 03:54:02
Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code.
CVE-2018-17182
- EPSS 8.51%
- Veröffentlicht 19.09.2018 09:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:02
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) via certain thread creation, ma...
CVE-2018-16515
- EPSS 0.44%
- Veröffentlicht 18.09.2018 21:29:03
- Zuletzt bearbeitet 21.11.2024 03:52:53
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
CVE-2018-13982
- EPSS 2.33%
- Veröffentlicht 18.09.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:48:22
Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory se...
CVE-2018-1000802
- EPSS 26.49%
- Veröffentlicht 18.09.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:23
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service...
CVE-2017-15705
- EPSS 1.77%
- Veröffentlicht 17.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:15:02
A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to be handled incorrectly leading to scan timeouts. In Apache SpamAssass...