CVE-2018-10540
- EPSS 0.38%
- Veröffentlicht 29.04.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:31
An issue was discovered in WavPack 5.1.0 and earlier for W64 input. Out-of-bounds writes can occur because ParseWave64HeaderConfig in wave64.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of int...
CVE-2018-10471
- EPSS 0.06%
- Veröffentlicht 27.04.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:22
An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor crash) via unexpected INT 80 processing, because of an incorrect fix for CVE-2017-5754.
CVE-2018-10472
- EPSS 0.09%
- Veröffentlicht 27.04.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:22
An issue was discovered in Xen through 4.10.x allowing x86 HVM guest OS users (in certain configurations) to read arbitrary dom0 files via QMP live insertion of a CDROM, in conjunction with specifying the target file as the backing file of a snapshot...
- EPSS 1.3%
- Veröffentlicht 26.04.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:29
Qemu before version 2.9 is vulnerable to an improper link following when built with the VirtFS. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a ho...
CVE-2018-10392
- EPSS 1.32%
- Veröffentlicht 26.04.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:19
mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a ...
CVE-2018-10393
- EPSS 0.27%
- Veröffentlicht 26.04.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:19
bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.
CVE-2017-6888
- EPSS 0.45%
- Veröffentlicht 25.04.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:30:43
An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file.
CVE-2017-7652
- EPSS 1.04%
- Veröffentlicht 25.04.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:22
In Eclipse Mosquitto 1.4.14, if a Mosquitto instance is set running with a configuration file, then sending a HUP signal to server triggers the configuration to be reloaded from disk. If there are lots of clients connected so that there are no more f...
CVE-2017-2901
- EPSS 1.06%
- Veröffentlicht 24.04.2018 19:29:03
- Zuletzt bearbeitet 21.11.2024 03:24:25
An exploitable integer overflow exists in the IRIS loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.iris' file can cause an integer overflow resulting in a buffer overflow which can allow for cod...
CVE-2017-2902
- EPSS 1.06%
- Veröffentlicht 24.04.2018 19:29:03
- Zuletzt bearbeitet 21.11.2024 03:24:25
An exploitable integer overflow exists in the DPX loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.cin' file can cause an integer overflow resulting in a buffer overflow which can allow for code ...