CVE-2018-15857
- EPSS 0.06%
- Veröffentlicht 25.08.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 03:51:35
An invalid free in ExprAppendMultiKeysymList in xkbcomp/ast-build.c in xkbcommon before 0.8.1 could be used by local attackers to crash xkbcommon keymap parsers or possibly have unspecified other impact by supplying a crafted keymap file.
CVE-2018-14598
- EPSS 3.14%
- Veröffentlicht 24.08.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:49:22
An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that will be freed later on, leading to DoS (segmentation f...
CVE-2018-14599
- EPSS 2.46%
- Veröffentlicht 24.08.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:49:23
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact.
CVE-2018-14600
- EPSS 9.37%
- Veröffentlicht 24.08.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:49:23
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resulting in an out-of-bounds write (of up to 128 bytes), leading to DoS or remote code execution.
CVE-2018-15120
- EPSS 8.02%
- Veröffentlicht 24.08.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:50:20
libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.
CVE-2018-15822
- EPSS 1.53%
- Veröffentlicht 23.08.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:31
The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an empty audio packet, leading to an assertion failure.
CVE-2018-10858
- EPSS 5.7%
- Veröffentlicht 22.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:09
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and ...
CVE-2018-10918
- EPSS 4.35%
- Veröffentlicht 22.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:18
A null pointer dereference flaw was found in the way samba checked database outputs from the LDB database layer. An authenticated attacker could use this flaw to crash a samba server in an Active Directory Domain Controller configuration. Samba versi...
CVE-2018-10919
- EPSS 1.73%
- Veröffentlicht 22.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:18
The Samba Active Directory LDAP server was vulnerable to an information disclosure flaw because of missing access control checks. An authenticated attacker could use this flaw to extract confidential attribute values using LDAP search expressions. Sa...
CVE-2018-1139
- EPSS 1.53%
- Veröffentlicht 22.08.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:16
A flaw was found in the way samba before 4.7.9 and 4.8.4 allowed the use of weak NTLMv1 authentication even when NTLMv1 was explicitly disabled. A man-in-the-middle attacker could use this flaw to read the credential and other details passed between ...