CVE-2018-16402
- EPSS 1.52%
- Veröffentlicht 03.09.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:40
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
CVE-2018-16335
- EPSS 1.7%
- Veröffentlicht 02.09.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:32
newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIF...
CVE-2018-16336
- EPSS 1.06%
- Veröffentlicht 02.09.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:33
Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, a different vulnerability than CVE-2018-10999.
CVE-2018-16276
- EPSS 0.08%
- Veröffentlicht 31.08.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:26
An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate ...
CVE-2018-14622
- EPSS 2.34%
- Veröffentlicht 30.08.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:26
A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file de...
CVE-2018-16056
- EPSS 0.53%
- Veröffentlicht 30.08.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:00
In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth Attribute Protocol dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by verifying that a dissector for a specific UUID exists.
CVE-2018-16057
- EPSS 1.28%
- Veröffentlicht 30.08.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:00
In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Radiotap dissector could crash. This was addressed in epan/dissectors/packet-ieee80211-radiotap-iter.c by validating iterator operations.
CVE-2018-16058
- EPSS 1.05%
- Veröffentlicht 30.08.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:01
In Wireshark 2.6.0 to 2.6.2, 2.4.0 to 2.4.8, and 2.2.0 to 2.2.16, the Bluetooth AVDTP dissector could crash. This was addressed in epan/dissectors/packet-btavdtp.c by properly initializing a data structure.
CVE-2018-8040
- EPSS 7.83%
- Veröffentlicht 29.08.2018 13:29:02
- Zuletzt bearbeitet 21.11.2024 04:13:09
Pages that are rendered using the ESI plugin can have access to the cookie header when the plugin is configured not to allow access. This affects Apache Traffic Server (ATS) versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users runn...
CVE-2018-1318
- EPSS 14.59%
- Veröffentlicht 29.08.2018 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:59:36
Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server (ATS) 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6....