CVE-2017-15108
- EPSS 0.14%
- Veröffentlicht 20.01.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:05
spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.
CVE-2018-5784
- EPSS 0.29%
- Veröffentlicht 19.01.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:23
In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared nu...
CVE-2018-5785
- EPSS 0.68%
- Veröffentlicht 19.01.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:23
In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
CVE-2018-5786
- EPSS 0.84%
- Veröffentlicht 19.01.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:23
In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.
CVE-2017-12197
- EPSS 0.43%
- Veröffentlicht 18.01.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:09:02
It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security restrictions and possibly access sensitive informatio...
CVE-2018-2663
- EPSS 0.11%
- Veröffentlicht 18.01.2018 02:29:22
- Zuletzt bearbeitet 21.11.2024 04:04:11
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploit...
CVE-2018-2665
- EPSS 0.44%
- Veröffentlicht 18.01.2018 02:29:22
- Zuletzt bearbeitet 21.11.2024 04:04:11
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged at...
CVE-2018-2668
- EPSS 0.36%
- Veröffentlicht 18.01.2018 02:29:22
- Zuletzt bearbeitet 21.11.2024 04:04:11
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged at...
CVE-2018-2677
- EPSS 0.11%
- Veröffentlicht 18.01.2018 02:29:22
- Zuletzt bearbeitet 21.11.2024 04:04:13
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthen...
CVE-2018-2678
- EPSS 0.11%
- Veröffentlicht 18.01.2018 02:29:22
- Zuletzt bearbeitet 21.11.2024 04:04:13
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable ...