CVE-2017-17485
- EPSS 79.79%
- Veröffentlicht 10.01.2018 18:29:01
- Zuletzt bearbeitet 27.08.2025 21:15:33
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to t...
CVE-2017-18026
- EPSS 0.75%
- Veröffentlicht 10.01.2018 09:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:11
Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary commands (through the Mercurial adapter) via vectors inv...
CVE-2015-2318
- EPSS 1.29%
- Veröffentlicht 08.01.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 02:27:12
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.
CVE-2015-2320
- EPSS 4.83%
- Veröffentlicht 08.01.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 02:27:12
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
CVE-2018-5294
- EPSS 0.62%
- Veröffentlicht 08.01.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:31
In libming 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the readUInt32 function (util/read.c). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted swf file.
CVE-2018-5268
- EPSS 0.32%
- Veröffentlicht 08.01.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:27
In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing a crafted image file.
CVE-2018-5269
- EPSS 0.48%
- Veröffentlicht 08.01.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:27
In OpenCV 3.3.1, an assertion failure happens in cv::RBaseStream::setPos in modules/imgcodecs/src/bitstrm.cpp because of an incorrect integer cast.
CVE-2018-5205
- EPSS 0.59%
- Veröffentlicht 06.01.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:19
When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string.
CVE-2018-5206
- EPSS 0.58%
- Veröffentlicht 06.01.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:20
When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer.
CVE-2018-5207
- EPSS 0.53%
- Veröffentlicht 06.01.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:20
When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the string.