CVE-2018-8976
- EPSS 0.56%
- Veröffentlicht 25.03.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:43
In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds read) via a crafted file.
CVE-2018-8971
- EPSS 0.18%
- Veröffentlicht 24.03.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:42
The Auth0 integration in GitLab before 10.3.9, 10.4.x before 10.4.6, and 10.5.x before 10.5.6 has an incorrect omniauth-auth0 configuration, leading to signing in unintended users.
CVE-2018-1000140
- EPSS 27.16%
- Veröffentlicht 23.03.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:46
rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to ...
CVE-2018-8905
- EPSS 0.64%
- Veröffentlicht 22.03.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:34
In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as demonstrated by tiff2ps.
CVE-2018-3710
- EPSS 5.24%
- Veröffentlicht 21.03.2018 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:05:55
Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.
CVE-2017-0915
- EPSS 1.16%
- Veröffentlicht 21.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:03:53
Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.
CVE-2017-0916
- EPSS 0.43%
- Veröffentlicht 21.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:03:53
Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.
CVE-2017-0917
- EPSS 0.08%
- Veröffentlicht 21.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:03:53
Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.
CVE-2017-0918
- EPSS 6.16%
- Veröffentlicht 21.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:03:53
Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution.
CVE-2017-0925
- EPSS 0.11%
- Veröffentlicht 21.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:03:54
Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration API endpoint resulting in an information disclosure of plaintext password.