CVE-2018-8777
- EPSS 1.86%
- Veröffentlicht 03.04.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:17
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with a crafted header to WEBrick server or a crafted body to WEBrick server/handler and cause a denial of...
CVE-2018-8778
- EPSS 0.54%
- Veröffentlicht 03.04.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:17
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-read in the String#unpack method...
CVE-2018-8779
- EPSS 1.28%
- Veröffentlicht 03.04.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:17
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open methods are not checked for null characters. It may be connected to an unintended socket.
CVE-2018-8780
- EPSS 1.34%
- Veröffentlicht 03.04.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:17
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional director...
- EPSS 2.09%
- Veröffentlicht 03.04.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:20
Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.
CVE-2018-0493
- EPSS 0.96%
- Veröffentlicht 03.04.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:20
remctld in remctl before 3.14, when an attacker is authorized to execute a command that uses the sudo option, has a use-after-free that leads to a daemon crash, memory corruption, or arbitrary command execution.
CVE-2018-4117
- EPSS 0.95%
- Veröffentlicht 03.04.2018 06:29:04
- Zuletzt bearbeitet 21.11.2024 04:06:47
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves ...
CVE-2017-7000
- EPSS 0.59%
- Veröffentlicht 03.04.2018 06:29:01
- Zuletzt bearbeitet 21.11.2024 03:30:56
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory c...
CVE-2018-7566
- EPSS 0.05%
- Veröffentlicht 30.03.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 04:12:22
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
CVE-2018-9132
- EPSS 0.53%
- Veröffentlicht 30.03.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:02
libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.