CVE-2017-18267
- EPSS 0.27%
- Veröffentlicht 10.05.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:43
The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.
CVE-2017-18266
- EPSS 1%
- Veröffentlicht 10.05.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:43
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafte...
CVE-2018-1130
- EPSS 0.05%
- Veröffentlicht 10.05.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:15
Linux kernel before version 4.16-rc7 is vulnerable to a null pointer dereference in dccp_write_xmit() function in net/dccp/output.c in that allows a local user to cause a denial of service by a number of certain crafted system calls.
CVE-2018-10958
- EPSS 1.62%
- Veröffentlicht 10.05.2018 02:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:23
In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory allocation for an Exiv2::Internal::PngChunk::zlibUncompress call.
CVE-2018-10963
- EPSS 0.39%
- Veröffentlicht 10.05.2018 02:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:24
The TIFFWriteDirectorySec() function in tif_dirwrite.c in LibTIFF through 4.0.9 allows remote attackers to cause a denial of service (assertion failure and application crash) via a crafted file, a different vulnerability than CVE-2017-13726.
CVE-2017-18265
- EPSS 1.06%
- Veröffentlicht 09.05.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:43
Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain versions of the LuaSocket library, such as the lua-socket package from Debian stretch. The attacker needs to tr...
CVE-2018-10940
- EPSS 0.06%
- Veröffentlicht 09.05.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:21
The cdrom_ioctl_media_changed function in drivers/cdrom/cdrom.c in the Linux kernel before 4.16.6 allows local attackers to use a incorrect bounds check in the CDROM driver CDROM_MEDIA_CHANGED ioctl to read out kernel memory.
CVE-2018-1089
- EPSS 14.57%
- Veröffentlicht 09.05.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:09
389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could potentially use this flaw to make ns-sl...
CVE-2018-8897
- EPSS 24.8%
- Veröffentlicht 08.05.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:33
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that ...
CVE-2018-1000168
- EPSS 3.36%
- Veröffentlicht 08.05.2018 15:29:00
- Zuletzt bearbeitet 09.06.2025 16:15:27
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network...