CVE-2018-14938
- EPSS 0.49%
- Veröffentlicht 05.08.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 03:50:07
An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the function handle_prism during caplen processing. If the caplen is less than 144, one can cause an integer overflow in the function han...
CVE-2018-14574
- EPSS 9.75%
- Veröffentlicht 03.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:20
django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
CVE-2018-14883
- EPSS 20.29%
- Veröffentlicht 03.08.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:50:00
An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c.
CVE-2018-14851
- EPSS 0.41%
- Veröffentlicht 02.08.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:55
exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG...
CVE-2018-1336
- EPSS 15.01%
- Veröffentlicht 02.08.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:38
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and ...
CVE-2015-9262
- EPSS 3.21%
- Veröffentlicht 01.08.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 02:40:11
_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow.
CVE-2018-8034
- EPSS 20.79%
- Veröffentlicht 01.08.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:08
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.
CVE-2018-10916
- EPSS 0.7%
- Veröffentlicht 01.08.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:17
It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirr...
CVE-2018-10883
- EPSS 0.05%
- Veröffentlicht 30.07.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:13
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_dirty_metadata(), a denial of service, and a system crash by mounting and operating on a crafted ext4 filesystem image.
CVE-2018-10903
- EPSS 0.22%
- Veröffentlicht 30.07.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:16
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an...