CVE-2018-18954
- EPSS 0.12%
- Veröffentlicht 15.11.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:56
The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV memory.
CVE-2018-17466
- EPSS 1.11%
- Veröffentlicht 14.11.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:28
Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVE-2018-16850
- EPSS 1.32%
- Veröffentlicht 13.11.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:26
postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL statements to run, with superuser ...
CVE-2018-19210
- EPSS 4.91%
- Veröffentlicht 12.11.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:33
In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset.
CVE-2018-19149
- EPSS 0.26%
- Veröffentlicht 10.11.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:25
Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment.
CVE-2018-19107
- EPSS 0.3%
- Veröffentlicht 08.11.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:20
In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-based buffer over-read) caused by an integer overflow via a crafted PSD image file.
CVE-2018-19108
- EPSS 0.41%
- Veröffentlicht 08.11.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:20
In Exiv2 0.26, Exiv2::PsdImage::readMetadata in psdimage.cpp in the PSD image reader may suffer from a denial of service (infinite loop) caused by an integer overflow via a crafted PSD image file.
CVE-2018-19060
- EPSS 0.15%
- Veröffentlicht 07.11.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:57:14
An issue was discovered in Poppler 0.71.0. There is a NULL pointer dereference in goo/GooString.h, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating a filename of an embedded file before constructing a save path.
CVE-2018-19058
- EPSS 0.28%
- Veröffentlicht 07.11.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:14
An issue was discovered in Poppler 0.71.0. There is a reachable abort in Object.h, will lead to denial of service because EmbFile::save2 in FileSpec.cc lacks a stream check before saving an embedded file.
CVE-2018-19059
- EPSS 0.13%
- Veröffentlicht 07.11.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:14
An issue was discovered in Poppler 0.71.0. There is a out-of-bounds read in EmbFile::save2 in FileSpec.cc, will lead to denial of service, as demonstrated by utils/pdfdetach.cc not validating embedded files before save attempts.