CVE-2018-7731
- EPSS 0.37%
- Veröffentlicht 06.03.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:37
An issue was discovered in Exempi through 2.4.4. XMPFiles/source/FormatSupport/WEBP_Support.cpp does not check whether a bitstream has a NULL value, leading to a NULL pointer dereference in the WEBP::VP8XChunk class.
CVE-2018-1000100
- EPSS 0.21%
- Veröffentlicht 06.03.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:38
GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap chunks being modified, this could lead to RCE. This attack appear to be exploitable via an attacker su...
CVE-2018-7725
- EPSS 0.5%
- Veröffentlicht 06.03.2018 17:29:00
- Zuletzt bearbeitet 10.07.2025 15:44:54
An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in zzip_disk_fread in mmapped.c. The vulnerability causes an application crash, which leads to denial of service.
CVE-2018-7726
- EPSS 0.5%
- Veröffentlicht 06.03.2018 17:29:00
- Zuletzt bearbeitet 10.07.2025 15:44:54
An issue was discovered in ZZIPlib 0.13.68. There is a bus error caused by the __zzip_parse_root_directory function of zip.c. Attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
CVE-2018-1000115
- EPSS 82.53%
- Veröffentlicht 05.03.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:40
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification...
CVE-2017-15130
- EPSS 2.38%
- Veröffentlicht 02.03.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:07
A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and the process to restart.
CVE-2018-1058
- EPSS 82.69%
- Veröffentlicht 02.03.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:05
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 ar...
CVE-2018-1066
- EPSS 5.04%
- Veröffentlicht 02.03.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:06
The Linux kernel before version 4.11 is vulnerable to a NULL pointer dereference in fs/cifs/cifsencrypt.c:setup_ntlmv2_rsp() that allows an attacker controlling a CIFS server to kernel panic a client that has this server mounted, because an empty Tar...
CVE-2017-18209
- EPSS 0.56%
- Veröffentlicht 01.03.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:34
In the GetOpenCLCachedFilesDirectory function in magick/opencl.c in ImageMagick 7.0.7, a NULL pointer dereference vulnerability occurs because a memory allocation result is not checked, related to GetOpenCLCacheDirectory.
CVE-2017-18211
- EPSS 0.56%
- Veröffentlicht 01.03.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:34
In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/opencl.c because a program-lookup result is not checked, related to CacheOpenCLKernel.