CVE-2018-1086
- EPSS 0.2%
- Veröffentlicht 12.04.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:09
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote att...
CVE-2018-10001
- EPSS 0.98%
- Veröffentlicht 11.04.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:40
The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via an AVI file.
CVE-2018-3837
- EPSS 0.35%
- Veröffentlicht 10.04.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:08
An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted PCX image can cause an out-of-bounds read on the heap, resulting in information disc...
CVE-2018-3838
- EPSS 0.42%
- Veröffentlicht 10.04.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:08
An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds read on the heap, resulting in information disclosure. An ...
CVE-2018-3839
- EPSS 1.16%
- Veröffentlicht 10.04.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:08
An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds write on the heap, resulting in code execution. An atta...
CVE-2018-9988
- EPSS 0.65%
- Veröffentlicht 10.04.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:59
ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input.
CVE-2018-9989
- EPSS 0.4%
- Veröffentlicht 10.04.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:59
ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.
CVE-2017-2826
- EPSS 0.26%
- Veröffentlicht 09.04.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:24:13
An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in informat...
CVE-2018-1308
- EPSS 5.78%
- Veröffentlicht 09.04.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:35
This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order t...
CVE-2018-9846
- EPSS 1.01%
- Veröffentlicht 07.04.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:47
In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to pe...