CVE-2017-14450
- EPSS 0.95%
- Veröffentlicht 24.04.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:12:49
A buffer overflow vulnerability exists in the GIF image parsing functionality of SDL2_image-2.0.2. A specially crafted GIF image can lead to a buffer overflow on a global section. An attacker can display an image to trigger this vulnerability.
CVE-2017-12081
- EPSS 0.79%
- Veröffentlicht 24.04.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:08:47
An exploitable integer overflow exists in the upgrade of a legacy Mesh attribute of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for cod...
CVE-2017-12082
- EPSS 0.79%
- Veröffentlicht 24.04.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:08:47
An exploitable integer overflow exists in the 'CustomData' Mesh loading functionality of the Blender open-source 3d creation suite. A .blend file with a specially crafted external data file can cause an integer overflow resulting in a buffer overflow...
CVE-2017-12086
- EPSS 0.79%
- Veröffentlicht 24.04.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:08:48
An exploitable integer overflow exists in the 'BKE_mesh_calc_normals_tessface' functionality of the Blender open-source 3d creation suite. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow fo...
CVE-2017-7651
- EPSS 23.23%
- Veröffentlicht 24.04.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:22
In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. This can be done without authentications if occur in connection phase of MQTT protocol.
CVE-2018-10323
- EPSS 0.08%
- Veröffentlicht 24.04.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:13
The xfs_bmap_extents_to_btree function in fs/xfs/libxfs/xfs_bmap.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_bmapi_write NULL pointer dereference) via a crafted xfs image.
CVE-2016-9601
- EPSS 0.45%
- Veröffentlicht 24.04.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:29
ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image function which is used to decode halftone segments in a JBIG2 image. A document (PostScript or PDF) with an ...
CVE-2018-1106
- EPSS 0.03%
- Veröffentlicht 23.04.2018 20:29:14
- Zuletzt bearbeitet 21.11.2024 03:59:11
An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a...
CVE-2018-8781
- EPSS 0.1%
- Veröffentlicht 23.04.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:18
The udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c at the Linux kernel version 3.4 and up to and including 4.15 has an integer-overflow vulnerability allowing local users with access to the udldrmfb driver to obtain full read and write permissi...
CVE-2017-17833
- EPSS 0.84%
- Veröffentlicht 23.04.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:18:46
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.