CVE-2018-5685
- EPSS 0.57%
- Veröffentlicht 14.01.2018 02:29:05
- Zuletzt bearbeitet 21.11.2024 04:09:09
In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Remote attackers could leverage this vulnerability to cause a denial of service via an image file with a crafted bit-field mask valu...
CVE-2018-5686
- EPSS 0.13%
- Veröffentlicht 14.01.2018 02:29:05
- Zuletzt bearbeitet 21.11.2024 04:09:10
In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered. Remote attackers could leverage this vulnerability to cause a denial of service via a craft...
CVE-2018-0486
- EPSS 0.78%
- Veröffentlicht 13.01.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:19
Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct im...
CVE-2017-13194
- EPSS 1.25%
- Veröffentlicht 12.01.2018 23:29:01
- Zuletzt bearbeitet 21.11.2024 03:11:08
A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64710201.
CVE-2018-5345
- EPSS 0.86%
- Veröffentlicht 12.01.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:37
A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file.
CVE-2018-5334
- EPSS 0.87%
- Veröffentlicht 11.01.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:36
In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks.
CVE-2018-5335
- EPSS 0.87%
- Veröffentlicht 11.01.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:36
In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the WCP dissector could crash. This was addressed in epan/dissectors/packet-wcp.c by validating the available buffer length.
CVE-2018-5336
- EPSS 1.01%
- Veröffentlicht 11.01.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:36
In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the JSON, XML, NTP, XMPP, and GDB dissectors could crash. This was addressed in epan/tvbparse.c by limiting the recursion depth.
CVE-2018-5332
- EPSS 0.03%
- Veröffentlicht 11.01.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:35
In the Linux kernel through 3.2, the rds_message_alloc_sgs() function does not validate a value that is used during DMA page allocation, leading to a heap-based out-of-bounds write (related to the rds_rdma_extra_size function in net/rds/rdma.c).
CVE-2018-5333
- EPSS 1.29%
- Veröffentlicht 11.01.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:36
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is supplied, leading to an rds_atomic_free_op NULL pointer dereference.