CVE-2018-10191
- EPSS 1.29%
- Veröffentlicht 17.04.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:59
In versions of mruby up to and including 1.4.0, an integer overflow exists in src/vm.c::mrb_vm_exec() when handling OP_GETUPVAR in the presence of deep scope nesting, resulting in a use-after-free. An attacker that can cause Ruby code to be run can u...
CVE-2018-6797
- EPSS 1.48%
- Veröffentlicht 17.04.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:13
An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.
CVE-2018-6798
- EPSS 1.49%
- Veröffentlicht 17.04.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:13
An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.
CVE-2018-6913
- EPSS 3.9%
- Veröffentlicht 17.04.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:24
Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item count.
CVE-2018-10124
- EPSS 0.04%
- Veröffentlicht 16.04.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:52
The kill_something_info function in kernel/signal.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service via an INT_MIN argument.
CVE-2018-10119
- EPSS 0.55%
- Veröffentlicht 16.04.2018 09:58:10
- Zuletzt bearbeitet 21.11.2024 03:40:52
sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-free with write access) or possib...
CVE-2018-10120
- EPSS 0.5%
- Veröffentlicht 16.04.2018 09:58:10
- Zuletzt bearbeitet 21.11.2024 03:40:52
The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 and 6.x before 6.0.2.1 does not validate a customizations index, which allows remote attackers to cause a denial of service (heap-based buffer overfl...
CVE-2018-10100
- EPSS 6.6%
- Veröffentlicht 16.04.2018 09:58:09
- Zuletzt bearbeitet 21.11.2024 03:40:49
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
CVE-2018-10101
- EPSS 9.39%
- Veröffentlicht 16.04.2018 09:58:09
- Zuletzt bearbeitet 21.11.2024 03:40:49
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
CVE-2018-10102
- EPSS 5.17%
- Veröffentlicht 16.04.2018 09:58:09
- Zuletzt bearbeitet 21.11.2024 03:40:49
Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.