CVE-2018-11040
- EPSS 7.32%
- Veröffentlicht 25.06.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:32
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controlle...
CVE-2018-3665
- EPSS 1.26%
- Veröffentlicht 21.06.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:05:51
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
CVE-2018-12617
- EPSS 10.99%
- Veröffentlicht 21.06.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:33
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to allocate a large memory chunk. Th...
CVE-2017-2669
- EPSS 6.87%
- Veröffentlicht 21.06.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:56
Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending speci...
CVE-2018-10841
- EPSS 0.69%
- Veröffentlicht 20.06.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:07
glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like ad...
CVE-2018-12599
- EPSS 0.33%
- Veröffentlicht 20.06.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:30
In ImageMagick 7.0.8-3 Q16, ReadBMPImage and WriteBMPImage in coders/bmp.c allow attackers to cause an out of bounds write via a crafted file.
CVE-2018-12600
- EPSS 0.33%
- Veröffentlicht 20.06.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:30
In ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow attackers to cause an out of bounds write via a crafted file.
CVE-2018-12601
- EPSS 0.5%
- Veröffentlicht 20.06.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:30
There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact.
CVE-2018-1120
- EPSS 0.99%
- Veröffentlicht 20.06.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:13
A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containing command line arguments (or environment strings), an attacker can cause utilities from psutils or procps (such as ps, w...
CVE-2018-10811
- EPSS 16.95%
- Veröffentlicht 19.06.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:04
strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.