CVE-2018-7584
- EPSS 83.07%
- Veröffentlicht 01.03.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:25
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper.c. This ...
CVE-2018-7550
- EPSS 0.08%
- Veröffentlicht 01.03.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:20
The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which triggers an out-of-bounds read or ...
CVE-2018-1304
- EPSS 1.79%
- Veröffentlicht 28.02.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:35
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definiti...
CVE-2014-10071
- EPSS 0.48%
- Veröffentlicht 27.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 02:03:27
In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.
CVE-2016-10714
- EPSS 0.4%
- Veröffentlicht 27.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 02:44:34
In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.
CVE-2017-18206
- EPSS 0.4%
- Veröffentlicht 27.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:33
In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.
CVE-2018-7548
- EPSS 0.37%
- Veröffentlicht 27.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:20
In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.
CVE-2018-7549
- EPSS 0.32%
- Veröffentlicht 27.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:20
In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p.
CVE-2018-7492
- EPSS 0.07%
- Veröffentlicht 26.02.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:14
A NULL pointer dereference was found in the net/rds/rdma.c __rds_rdma_map() function in the Linux kernel before 4.14.7 allowing local attackers to cause a system panic and a denial-of-service, related to RDS_GET_MR and RDS_GET_MR_FOR_DEST.
CVE-2018-7480
- EPSS 0.07%
- Veröffentlicht 25.02.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:12
The blkcg_init_queue function in block/blk-cgroup.c in the Linux kernel before 4.11 allows local users to cause a denial of service (double free) or possibly have unspecified other impact by triggering a creation failure.