CVE-2018-12617
- EPSS 10.99%
- Veröffentlicht 21.06.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:33
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to allocate a large memory chunk. Th...
CVE-2017-2669
- EPSS 6.87%
- Veröffentlicht 21.06.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:56
Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending speci...
CVE-2018-10841
- EPSS 0.68%
- Veröffentlicht 20.06.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:07
glusterfs is vulnerable to privilege escalation on gluster server nodes. An authenticated gluster client via TLS could use gluster cli with --remote-host command to add it self to trusted storage pool and perform privileged gluster operations like ad...
CVE-2018-12599
- EPSS 0.33%
- Veröffentlicht 20.06.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:30
In ImageMagick 7.0.8-3 Q16, ReadBMPImage and WriteBMPImage in coders/bmp.c allow attackers to cause an out of bounds write via a crafted file.
CVE-2018-12600
- EPSS 0.33%
- Veröffentlicht 20.06.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:30
In ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow attackers to cause an out of bounds write via a crafted file.
CVE-2018-12601
- EPSS 0.5%
- Veröffentlicht 20.06.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:30
There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact.
CVE-2018-1120
- EPSS 1.34%
- Veröffentlicht 20.06.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:13
A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containing command line arguments (or environment strings), an attacker can cause utilities from psutils or procps (such as ps, w...
CVE-2018-10811
- EPSS 5.17%
- Veröffentlicht 19.06.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:04
strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.
CVE-2018-1061
- EPSS 1.48%
- Veröffentlicht 19.06.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:05
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.
CVE-2018-12564
- EPSS 0.31%
- Veröffentlicht 19.06.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:26
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and vali...