CVE-2018-16152
- EPSS 1.69%
- Veröffentlicht 26.09.2018 21:29:01
- Zuletzt bearbeitet 03.12.2025 21:15:50
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 signature ve...
CVE-2018-11763
- EPSS 17.4%
- Veröffentlicht 25.09.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:58
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitiga...
CVE-2018-14634
- EPSS 11.53%
- Veröffentlicht 25.09.2018 21:29:00
- Zuletzt bearbeitet 27.01.2026 15:55:15
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6...
CVE-2018-14633
- EPSS 7.98%
- Veröffentlicht 25.09.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:28
A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a way an authentication request from an ISCSI initiator is processed. An unauthenticated remote attacker can cause a stack buffer over...
CVE-2018-14647
- EPSS 1.9%
- Veröffentlicht 25.09.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:30
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions ...
CVE-2018-17407
- EPSS 1.36%
- Veröffentlicht 23.09.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:20
An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font is loaded by one of the vulnera...
CVE-2018-17336
- EPSS 0.34%
- Veröffentlicht 22.09.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:14
UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspecified other impact via a malfo...
CVE-2018-14645
- EPSS 0.23%
- Veröffentlicht 21.09.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:29
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
CVE-2018-17294
- EPSS 0.51%
- Veröffentlicht 21.09.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:11
The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's length, allowing attackers to cause a denial of service (application crash via out-of-bounds read) by crafting an input file with c...
CVE-2018-17205
- EPSS 0.77%
- Veröffentlicht 19.09.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 03:54:05
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofproto in order. If a flow cannot be added (e.g., the flow...