CVE-2018-11356
- EPSS 1.18%
- Veröffentlicht 22.05.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:12
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the DNS dissector could crash. This was addressed in epan/dissectors/packet-dns.c by avoiding a NULL pointer dereference for an empty name in an SRV record.
CVE-2018-11357
- EPSS 1.18%
- Veröffentlicht 22.05.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:12
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LTP dissector and other dissectors could consume excessive memory. This was addressed in epan/tvbuff.c by rejecting negative lengths.
CVE-2018-11358
- EPSS 1.59%
- Veröffentlicht 22.05.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:12
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the Q.931 dissector could crash. This was addressed in epan/dissectors/packet-q931.c by avoiding a use-after-free after a malformed packet prevented certain cleanup.
CVE-2018-11359
- EPSS 1.19%
- Veröffentlicht 22.05.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:12
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the RRC dissector and other dissectors could crash. This was addressed in epan/proto.c by avoiding a NULL pointer dereference.
CVE-2018-11360
- EPSS 1.09%
- Veröffentlicht 22.05.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:13
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the GSM A DTAP dissector could crash. This was addressed in epan/dissectors/packet-gsm_a_dtap.c by fixing an off-by-one error that caused a buffer overflow.
CVE-2018-11362
- EPSS 1.59%
- Veröffentlicht 22.05.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:13
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by avoiding a buffer over-read upon encountering a missing '\0' character.
CVE-2018-3639
- EPSS 39.09%
- Veröffentlicht 22.05.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 04:05:48
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access vi...
CVE-2018-1108
- EPSS 0.46%
- Veröffentlicht 21.05.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:11
kernel drivers before version 4.17-rc1 are vulnerable to a weakness in the Linux kernel's implementation of random seed data. Programs, early in the boot sequence, could use the data allocated for the seed before it was sufficiently generated.
CVE-2018-8012
- EPSS 1.37%
- Veröffentlicht 21.05.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:05
No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit cha...
CVE-2018-11319
- EPSS 0.84%
- Veröffentlicht 20.05.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:07
Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrary code execution via a malicio...