CVE-2018-11780
- EPSS 6.77%
- Veröffentlicht 17.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:01
A potential Remote Code Execution bug exists with the PDFInfo plugin in Apache SpamAssassin before 3.4.2.
CVE-2018-11781
- EPSS 0.25%
- Veröffentlicht 17.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:01
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.
CVE-2018-17100
- EPSS 0.3%
- Veröffentlicht 16.09.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 03:53:52
An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause a denial of service (crash) or possibly have unspecified other impact via a crafted image file.
CVE-2018-17101
- EPSS 0.54%
- Veröffentlicht 16.09.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 03:53:52
An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.
CVE-2018-17082
- EPSS 4.44%
- Veröffentlicht 16.09.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:50
The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in s...
CVE-2018-12086
- EPSS 25.73%
- Veröffentlicht 14.09.2018 21:29:03
- Zuletzt bearbeitet 21.11.2024 03:44:33
Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.
CVE-2018-17000
- EPSS 1.21%
- Veröffentlicht 13.09.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:53:40
A NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9 allows an attacker to cause a denial-of-service through a crafted tiff file. This vulnerability can be triggered...
CVE-2018-16741
- EPSS 0.65%
- Veröffentlicht 13.09.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:16
An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanitize shell metacharacters to prevent command injection. It is possible to use the ||, &&, or > characters within a file created by ...
CVE-2018-16981
- EPSS 0.36%
- Veröffentlicht 12.09.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:38
stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.
CVE-2018-16947
- EPSS 1.49%
- Veröffentlicht 12.09.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:33
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not require (or allow for) authentication of those RPCs. Handling those RPCs results in operations being...