CVE-2018-14362
- EPSS 2.09%
- Veröffentlicht 17.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:48:55
An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. pop.c does not forbid characters that may have unsafe interaction with message-cache pathnames, as demonstrated by a '/' character.
CVE-2018-10840
- EPSS 0.1%
- Veröffentlicht 16.07.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:07
Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by operating on a mounted crafted ext4 image.
CVE-2018-0360
- EPSS 1.09%
- Veröffentlicht 16.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:03
ClamAV before 0.100.1 has an HWP integer overflow with a resultant infinite loop via a crafted Hangul Word Processor file. This is in parsehwp3_paragraph() in libclamav/hwp.c.
CVE-2018-10875
- EPSS 0.04%
- Veröffentlicht 13.07.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:11
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.
CVE-2018-0500
- EPSS 1.15%
- Veröffentlicht 11.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:21
Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attacker who can control the data that curl transmits over SMTP with certain settings (i.e., use of a nons...
CVE-2018-1116
- EPSS 0.07%
- Veröffentlicht 10.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:12
A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other...
CVE-2018-13785
- EPSS 2.92%
- Veröffentlicht 09.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:47:58
In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.
CVE-2018-13440
- EPSS 6.02%
- Veröffentlicht 08.07.2018 16:29:00
- Zuletzt bearbeitet 13.08.2025 20:48:07
The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert.
CVE-2018-13405
- EPSS 0.17%
- Veröffentlicht 06.07.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:47:02
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a memb...
CVE-2018-13406
- EPSS 0.04%
- Veröffentlicht 06.07.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:47:02
An integer overflow in the uvesafb_setcmap function in drivers/video/fbdev/uvesafb.c in the Linux kernel before 4.17.4 could result in local attackers being able to crash the kernel or potentially elevate privileges because kmalloc_array is not used.