CVE-2018-1000027
- EPSS 66%
- Veröffentlicht 09.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:27
The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can result in Denial of Service to all clients of the pro...
- EPSS 0.07%
- Veröffentlicht 09.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:04
In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under umask which was in effect when t...
CVE-2018-6869
- EPSS 1.07%
- Veröffentlicht 09.02.2018 06:29:00
- Zuletzt bearbeitet 10.07.2025 15:44:54
In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
CVE-2018-6871
- EPSS 42.68%
- Veröffentlicht 09.02.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:20
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
CVE-2018-6789
- EPSS 86.44%
- Veröffentlicht 08.02.2018 23:29:01
- Zuletzt bearbeitet 07.11.2025 19:04:28
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.
CVE-2017-5125
- EPSS 1.59%
- Veröffentlicht 07.02.2018 23:29:01
- Zuletzt bearbeitet 21.11.2024 03:27:06
Heap buffer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2017-5126
- EPSS 1.48%
- Veröffentlicht 07.02.2018 23:29:01
- Zuletzt bearbeitet 21.11.2024 03:27:06
A use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVE-2017-5127
- EPSS 1.48%
- Veröffentlicht 07.02.2018 23:29:01
- Zuletzt bearbeitet 21.11.2024 03:27:06
Use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVE-2017-5128
- EPSS 1.46%
- Veröffentlicht 07.02.2018 23:29:01
- Zuletzt bearbeitet 21.11.2024 03:27:06
Heap buffer overflow in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, related to WebGL.
CVE-2017-5129
- EPSS 1.01%
- Veröffentlicht 07.02.2018 23:29:01
- Zuletzt bearbeitet 21.11.2024 03:27:07
A use after free in WebAudio in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.