CVE-2018-10938
- EPSS 4.37%
- Veröffentlicht 27.08.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:21
A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading...
- EPSS 3.63%
- Veröffentlicht 26.08.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 01:28:55
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control ...
CVE-2018-14598
- EPSS 3.14%
- Veröffentlicht 24.08.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:49:22
An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that will be freed later on, leading to DoS (segmentation f...
CVE-2018-14599
- EPSS 2.46%
- Veröffentlicht 24.08.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:49:23
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact.
CVE-2018-14600
- EPSS 9.37%
- Veröffentlicht 24.08.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:49:23
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resulting in an out-of-bounds write (of up to 128 bytes), leading to DoS or remote code execution.
CVE-2018-15822
- EPSS 1.53%
- Veröffentlicht 23.08.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:31
The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an empty audio packet, leading to an assertion failure.
CVE-2018-10858
- EPSS 5.7%
- Veröffentlicht 22.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:09
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and ...
CVE-2018-10919
- EPSS 1.73%
- Veröffentlicht 22.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:18
The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Sa...
CVE-2018-10844
- EPSS 0.19%
- Veröffentlicht 22.08.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:07
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data...
CVE-2018-10845
- EPSS 1.09%
- Veröffentlicht 22.08.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:07
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing dat...