CVE-2018-1061
- EPSS 1.65%
- Veröffentlicht 19.06.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:05
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.
CVE-2018-12564
- EPSS 0.31%
- Veröffentlicht 19.06.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:26
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and vali...
CVE-2018-12565
- EPSS 2.5%
- Veröffentlicht 19.06.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:27
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execution can occur.
CVE-2018-1060
- EPSS 0.96%
- Veröffentlicht 18.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:05
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.
CVE-2018-1152
- EPSS 0.97%
- Veröffentlicht 18.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:17
libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image.
- EPSS 0.1%
- Veröffentlicht 17.06.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:27
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file wi...
CVE-2018-11218
- EPSS 80.3%
- Veröffentlicht 17.06.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:55
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.
CVE-2018-11219
- EPSS 2.59%
- Veröffentlicht 17.06.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:55
An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking.
CVE-2018-12495
- EPSS 0.54%
- Veröffentlicht 15.06.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:20
The quoteblock function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
CVE-2018-12458
- EPSS 0.96%
- Veröffentlicht 15.06.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:15
An improper integer type in the mpeg4_encode_gop_header function in libavcodec/mpeg4videoenc.c in FFmpeg 2.8 and 4.0 may trigger an assertion violation while converting a crafted AVI file to MPEG4, leading to a denial of service.