CVE-2018-14358
- EPSS 1.38%
- Veröffentlicht 17.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:54
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response with a long RFC822.SIZE field.
CVE-2018-14359
- EPSS 4.1%
- Veröffentlicht 17.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:54
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They have a buffer overflow via base64 data.
CVE-2018-14360
- EPSS 0.32%
- Veröffentlicht 17.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:55
An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.
CVE-2018-14361
- EPSS 0.4%
- Veröffentlicht 17.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:55
An issue was discovered in NeoMutt before 2018-07-16. nntp.c proceeds even if memory allocation fails for messages data.
CVE-2018-14362
- EPSS 1.81%
- Veröffentlicht 17.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:55
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.
CVE-2018-14346
- EPSS 0.5%
- Veröffentlicht 17.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:52
GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).
CVE-2018-14347
- EPSS 0.57%
- Veröffentlicht 17.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:52
GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c).
CVE-2018-14337
- EPSS 0.36%
- Veröffentlicht 17.07.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:51
The CHECK macro in mrbgems/mruby-sprintf/src/sprintf.c in mruby 1.4.1 contains a signed integer overflow, possibly leading to out-of-bounds memory access because the mrb_str_resize function in string.c does not check for a negative length.
CVE-2018-10857
- EPSS 0.5%
- Veröffentlicht 16.07.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:09
git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.
CVE-2018-12584
- EPSS 25.19%
- Veröffentlicht 16.07.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:29
The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows remote attackers to cause a denial of service (buffer overflow) or possibly execute arbitrary code when TLS communication is enabled.