CVE-2017-6928
- EPSS 0.28%
- Veröffentlicht 01.03.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:30:49
Drupal core 7.x versions before 7.57 when using Drupal's private file system, Drupal will check to make sure a user has access to a file before allowing the user to view or download it. This check fails under certain conditions in which one module is...
CVE-2017-6929
- EPSS 0.6%
- Veröffentlicht 01.03.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:30:49
A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domains. This vulnerability is mitigated by the fact that it requires contributed or custom modules in order to exploit. For Drupal 8, this vulnerability wa...
CVE-2017-6932
- EPSS 0.38%
- Veröffentlicht 01.03.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:30:50
Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick ...
CVE-2018-7584
- EPSS 83.07%
- Veröffentlicht 01.03.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:25
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper.c. This ...
CVE-2018-7550
- EPSS 0.08%
- Veröffentlicht 01.03.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:20
The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which triggers an out-of-bounds read or ...
CVE-2018-1304
- EPSS 2.08%
- Veröffentlicht 28.02.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:35
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definiti...
CVE-2018-7556
- EPSS 0.29%
- Veröffentlicht 28.02.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:21
LimeSurvey 2.6.x before 2.6.7, 2.7x.x before 2.73.1, and 3.x before 3.4.2 mishandles application/controller/InstallerController.php after installation, which allows remote attackers to access the configuration file.
CVE-2018-7557
- EPSS 1.07%
- Veröffentlicht 28.02.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:21
The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 allows remote attackers to cause a denial of service (Out of array read) via an AVI file with crafted dimensions within chroma subsampling data.
CVE-2018-7551
- EPSS 0.57%
- Veröffentlicht 28.02.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:21
There is an invalid free in MiniPS::delete0 in minips.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
CVE-2018-7552
- EPSS 0.57%
- Veröffentlicht 28.02.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:21
There is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.