- EPSS 0.08%
- Veröffentlicht 09.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:04
In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under umask which was in effect when t...
CVE-2018-6869
- EPSS 1.07%
- Veröffentlicht 09.02.2018 06:29:00
- Zuletzt bearbeitet 10.07.2025 15:44:54
In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
CVE-2018-6871
- EPSS 30.06%
- Veröffentlicht 09.02.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:20
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
CVE-2018-6789
- EPSS 86.59%
- Veröffentlicht 08.02.2018 23:29:01
- Zuletzt bearbeitet 07.11.2025 19:04:28
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.
CVE-2017-5125
- EPSS 1.59%
- Veröffentlicht 07.02.2018 23:29:01
- Zuletzt bearbeitet 21.11.2024 03:27:06
Heap buffer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2017-5126
- EPSS 1.48%
- Veröffentlicht 07.02.2018 23:29:01
- Zuletzt bearbeitet 21.11.2024 03:27:06
A use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVE-2017-5127
- EPSS 1.48%
- Veröffentlicht 07.02.2018 23:29:01
- Zuletzt bearbeitet 21.11.2024 03:27:06
Use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
CVE-2017-5128
- EPSS 1.46%
- Veröffentlicht 07.02.2018 23:29:01
- Zuletzt bearbeitet 21.11.2024 03:27:06
Heap buffer overflow in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, related to WebGL.
CVE-2017-5129
- EPSS 1.01%
- Veröffentlicht 07.02.2018 23:29:01
- Zuletzt bearbeitet 21.11.2024 03:27:07
A use after free in WebAudio in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVE-2017-5130
- EPSS 1.17%
- Veröffentlicht 07.02.2018 23:29:01
- Zuletzt bearbeitet 03.12.2025 22:15:48
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.