CVE-2018-14681
- EPSS 4.21%
- Veröffentlicht 28.07.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:34
An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.
CVE-2018-14682
- EPSS 3.14%
- Veröffentlicht 28.07.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:34
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.
CVE-2018-14678
- EPSS 0.09%
- Veröffentlicht 28.07.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:34
An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which allows local users to cause a denial of service (unin...
CVE-2018-0497
- EPSS 0.33%
- Veröffentlicht 28.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:21
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vulnerability exists because of an incorrect fix (wit...
CVE-2018-0498
- EPSS 0.21%
- Veröffentlicht 28.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:21
ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack.
CVE-2016-9578
- EPSS 3.34%
- Veröffentlicht 27.07.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:25
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
CVE-2016-9603
- EPSS 1.59%
- Veröffentlicht 27.07.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:29
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged...
CVE-2016-9577
- EPSS 3.67%
- Veröffentlicht 27.07.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:25
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
CVE-2017-2616
- EPSS 0.06%
- Veröffentlicht 27.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:50
A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
CVE-2017-2618
- EPSS 0.05%
- Veröffentlicht 27.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:50
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.