CVE-2018-5390
- EPSS 11.42%
- Veröffentlicht 06.08.2018 20:29:01
- Zuletzt bearbeitet 21.11.2024 04:08:43
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
CVE-2018-14938
- EPSS 0.46%
- Veröffentlicht 05.08.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 03:50:07
An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the function handle_prism during caplen processing. If the caplen is less than 144, one can cause an integer overflow in the function han...
CVE-2018-14574
- EPSS 7.48%
- Veröffentlicht 03.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:20
django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
CVE-2018-14883
- EPSS 20.29%
- Veröffentlicht 03.08.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:50:00
An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c.
CVE-2018-14851
- EPSS 0.41%
- Veröffentlicht 02.08.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:55
exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG...
CVE-2018-1336
- EPSS 18.55%
- Veröffentlicht 02.08.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:38
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and ...
CVE-2015-9262
- EPSS 3.05%
- Veröffentlicht 01.08.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 02:40:11
_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow.
CVE-2018-8034
- EPSS 13.31%
- Veröffentlicht 01.08.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:08
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.
CVE-2018-10916
- EPSS 0.7%
- Veröffentlicht 01.08.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:17
It has been discovered that lftp up to and including version 4.8.3 does not properly sanitize remote file names, leading to a loss of integrity on the local system when reverse mirroring is used. A remote attacker may trick a user to use reverse mirr...
CVE-2018-10883
- EPSS 0.05%
- Veröffentlicht 30.07.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:13
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_dirty_metadata(), a denial of service, and a system crash by mounting and operating on a crafted ext4 filesystem image.