CVE-2018-1000030
- EPSS 1.58%
- Veröffentlicht 08.02.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:28
Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears that Python 2.7.17 and prior may also be vulnerable however this has not been confirmed. The...
CVE-2018-6767
- EPSS 0.88%
- Veröffentlicht 06.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:11:08
A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service attack or possibly have unspecified other impact via a maliciously crafted RF64 file.
CVE-2018-6188
- EPSS 0.7%
- Veröffentlicht 05.02.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 04:10:15
django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated b...
CVE-2018-6616
- EPSS 0.08%
- Veröffentlicht 04.02.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:10:59
In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.
CVE-2018-6594
- EPSS 0.8%
- Veröffentlicht 03.02.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:10:57
lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only ...
CVE-2017-14177
- EPSS 0.05%
- Veröffentlicht 02.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:12:18
Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileg...
CVE-2017-14179
- EPSS 0.03%
- Veröffentlicht 02.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:12:18
Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root priv...
CVE-2017-14180
- EPSS 0.05%
- Veröffentlicht 02.02.2018 14:29:00
- Zuletzt bearbeitet 03.11.2025 20:15:41
Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain...
CVE-2018-6540
- EPSS 0.42%
- Veröffentlicht 02.02.2018 09:29:00
- Zuletzt bearbeitet 10.07.2025 15:44:54
In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address in the zzip_disk_findfirst function of zzip/mmapped.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.
CVE-2018-6541
- EPSS 0.44%
- Veröffentlicht 02.02.2018 09:29:00
- Zuletzt bearbeitet 10.07.2025 15:44:54
In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address (when handling disk64_trailer local entries) in __zzip_fetch_disk_trailer (zzip/zip.c). Remote attackers could leverage this vulnerability to cause a denial of service...