CVE-2018-5206
- EPSS 0.58%
- Veröffentlicht 06.01.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:20
When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer.
CVE-2018-5207
- EPSS 0.53%
- Veröffentlicht 06.01.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:20
When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the string.
CVE-2018-5208
- EPSS 0.92%
- Veröffentlicht 06.01.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:20
In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings.
CVE-2018-5251
- EPSS 0.56%
- Veröffentlicht 05.01.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:25
In libming 0.4.8, there is an integer signedness error vulnerability (left shift of a negative value) in the readSBits function (util/read.c). Remote attackers can leverage this vulnerability to cause a denial of service via a crafted swf file.
CVE-2018-5248
- EPSS 0.66%
- Veröffentlicht 05.01.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:25
In ImageMagick 7.0.7-17 Q16, there is a heap-based buffer over-read in coders/sixel.c in the ReadSIXELImage function, related to the sixel_decode function.
CVE-2017-1665
- EPSS 0.14%
- Veröffentlicht 04.01.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:22:11
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133559.
CVE-2017-5715
- EPSS 88.95%
- Veröffentlicht 04.01.2018 13:29:00
- Zuletzt bearbeitet 06.05.2025 15:15:51
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
CVE-2017-5753
- EPSS 94.33%
- Veröffentlicht 04.01.2018 13:29:00
- Zuletzt bearbeitet 14.01.2025 19:29:55
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
CVE-2017-1000472
- EPSS 0.47%
- Veröffentlicht 03.01.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:48
The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the ZIP header, which allows attackers to conduct absolute path traversal attacks during the ZIP decompre...
CVE-2017-1000487
- EPSS 7.8%
- Veröffentlicht 03.01.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:50
Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.