CVE-2018-7284
- EPSS 65.24%
- Veröffentlicht 22.02.2018 00:29:01
- Zuletzt bearbeitet 21.11.2024 04:11:56
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. When processing a SUBSCRIBE request, the res_pjsip_pubsub module stores the accepted formats...
CVE-2018-7286
- EPSS 54.63%
- Veröffentlicht 22.02.2018 00:29:01
- Zuletzt bearbeitet 21.11.2024 04:11:56
An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.18-cert2. res_pjsip allows remote authenticated users to crash Asterisk (segmentation fault) by sending a number of S...
CVE-2015-5314
- EPSS 1.15%
- Veröffentlicht 21.02.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 02:32:46
The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when used with (1) an internal EAP server or (2) a RADIUS server and EAP-pwd is ...
CVE-2015-5315
- EPSS 1.15%
- Veröffentlicht 21.02.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 02:32:46
The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when EAP-pwd is enabled in a network configuration profile, which allows remote at...
CVE-2015-5316
- EPSS 1.52%
- Veröffentlicht 21.02.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 02:32:46
The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configuration profile, allows remote attackers to cause a denial of service (NULL pointer dereference and daemo...
CVE-2018-7253
- EPSS 0.88%
- Veröffentlicht 19.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:53
The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buffer over-read) or possibly overwrite the heap via a maliciously crafted DSDIFF file.
CVE-2018-7254
- EPSS 21.31%
- Veröffentlicht 19.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:53
The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-read), or possibly trigger a buffer overflow or incorrect memory allocation, via a maliciously crafte...
CVE-2017-7375
- EPSS 0.26%
- Veröffentlicht 19.02.2018 19:29:00
- Zuletzt bearbeitet 03.12.2025 22:15:49
A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may exp...
- EPSS 38.43%
- Veröffentlicht 19.02.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:31:45
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.
CVE-2018-7225
- EPSS 4.26%
- Veröffentlicht 19.02.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:49
An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an ...