CVE-2018-11235
- EPSS 41.72%
- Veröffentlicht 30.05.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:57
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that ...
CVE-2018-11531
- EPSS 1.44%
- Veröffentlicht 29.05.2018 07:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:33
Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.
CVE-2018-11508
- EPSS 1.54%
- Veröffentlicht 28.05.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:30
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.
CVE-2018-11506
- EPSS 0.08%
- Veröffentlicht 28.05.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:30
The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact because sense buffers have different sizes...
CVE-2018-11490
- EPSS 0.21%
- Veröffentlicht 26.05.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:28
The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is not checked. This will lead to ...
CVE-2018-11469
- EPSS 0.03%
- Veröffentlicht 25.05.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:25
Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, related to the proto_http.c check...
CVE-2018-11440
- EPSS 0.29%
- Veröffentlicht 25.05.2018 11:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:22
Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c.
CVE-2018-11412
- EPSS 11.2%
- Veröffentlicht 24.05.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:18
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a d...
CVE-2018-8013
- EPSS 1.33%
- Veröffentlicht 24.05.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:13:05
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before ...
CVE-2018-1000199
- EPSS 0.48%
- Veröffentlicht 24.05.2018 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:39:55
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptra...