CVE-2018-5332
- EPSS 0.03%
- Veröffentlicht 11.01.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:35
In the Linux kernel through 3.2, the rds_message_alloc_sgs() function does not validate a value that is used during DMA page allocation, leading to a heap-based out-of-bounds write (related to the rds_rdma_extra_size function in net/rds/rdma.c).
CVE-2018-5333
- EPSS 1.29%
- Veröffentlicht 11.01.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:36
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is supplied, leading to an rds_atomic_free_op NULL pointer dereference.
CVE-2017-17485
- EPSS 79.79%
- Veröffentlicht 10.01.2018 18:29:01
- Zuletzt bearbeitet 27.08.2025 21:15:33
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to t...
CVE-2017-18026
- EPSS 0.75%
- Veröffentlicht 10.01.2018 09:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:11
Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors inv...
CVE-2015-2318
- EPSS 1.29%
- Veröffentlicht 08.01.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 02:27:12
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.
CVE-2015-2320
- EPSS 4.83%
- Veröffentlicht 08.01.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 02:27:12
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
CVE-2018-5294
- EPSS 0.62%
- Veröffentlicht 08.01.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:31
In libming 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the readUInt32 function (util/read.c). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted swf file.
CVE-2018-5268
- EPSS 0.34%
- Veröffentlicht 08.01.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:27
In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file.
CVE-2018-5269
- EPSS 0.5%
- Veröffentlicht 08.01.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:27
In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.
CVE-2018-5205
- EPSS 0.59%
- Veröffentlicht 06.01.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:19
When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string.