CVE-2018-8897
- EPSS 24.8%
- Veröffentlicht 08.05.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:33
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that ...
CVE-2018-1000168
- EPSS 3.61%
- Veröffentlicht 08.05.2018 15:29:00
- Zuletzt bearbeitet 09.06.2025 16:15:27
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network...
CVE-2018-1000178
- EPSS 1.08%
- Veröffentlicht 08.05.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:51
A heap corruption of type CWE-120 exists in quassel version 0.12.4 in quasselcore in void DataStreamPeer::processMessage(const QByteArray &msg) datastreampeer.cpp line 62 that allows an attacker to execute code remotely.
CVE-2018-1000179
- EPSS 0.57%
- Veröffentlicht 08.05.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:51
A NULL Pointer Dereference of CWE-476 exists in quassel version 0.12.4 in the quasselcore void CoreAuthHandler::handle(const Login &msg) coreauthhandler.cpp line 235 that allows an attacker to cause a denial of service.
CVE-2018-10380
- EPSS 0.09%
- Veröffentlicht 08.05.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:18
kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.
CVE-2018-10771
- EPSS 0.91%
- Veröffentlicht 07.05.2018 02:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:00
Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
CVE-2018-10768
- EPSS 1.85%
- Veröffentlicht 06.05.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:00
There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are no...
CVE-2018-0494
- EPSS 72.58%
- Veröffentlicht 06.05.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:21
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequence in a continuation line.
CVE-2018-10753
- EPSS 0.91%
- Veröffentlicht 05.05.2018 02:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:59
Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
CVE-2017-18264
- EPSS 0.31%
- Veröffentlicht 01.05.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:43
An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions (e.g., vers...