CVE-2018-7490
- EPSS 93.3%
- Veröffentlicht 26.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:13
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.
CVE-2018-7492
- EPSS 0.07%
- Veröffentlicht 26.02.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:14
A NULL pointer dereference was found in the net/rds/rdma.c __rds_rdma_map() function in the Linux kernel before 4.14.7 allowing local attackers to cause a system panic and a denial-of-service, related to RDS_GET_MR and RDS_GET_MR_FOR_DEST.
CVE-2018-7487
- EPSS 0.2%
- Veröffentlicht 26.02.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:13
There is a heap-based buffer overflow in the LoadPCX function of in_pcx.cpp in sam2p 0.49.4. A Crafted input will lead to a denial of service or possibly unspecified other impact.
CVE-2018-7489
- EPSS 36.21%
- Veröffentlicht 26.02.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:13
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously c...
CVE-2018-7480
- EPSS 0.07%
- Veröffentlicht 25.02.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:12
The blkcg_init_queue function in block/blk-cgroup.c in the Linux kernel before 4.11 allows local users to cause a denial of service (double free) or possibly have unspecified other impact by triggering a creation failure.
CVE-2018-7456
- EPSS 0.66%
- Veröffentlicht 24.02.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:10
A NULL Pointer Dereference occurs in the function TIFFPrintDirectory in tif_print.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4....
CVE-2018-1305
- EPSS 19.27%
- Veröffentlicht 23.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:35
Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way ap...
CVE-2018-7331
- EPSS 1.3%
- Veröffentlicht 23.02.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 04:12:02
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-ber.c had an infinite loop that was addressed by validating a length.
CVE-2018-7332
- EPSS 0.37%
- Veröffentlicht 23.02.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 04:12:02
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, epan/dissectors/packet-reload.c had an infinite loop that was addressed by validating a length.
CVE-2018-7334
- EPSS 1.01%
- Veröffentlicht 23.02.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 04:12:02
In Wireshark 2.4.0 to 2.4.4 and 2.2.0 to 2.2.12, the UMTS MAC dissector could crash. This was addressed in epan/dissectors/packet-umts_mac.c by rejecting a certain reserved value.