CVE-2018-6198
- EPSS 0.18%
- Veröffentlicht 25.01.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 04:10:16
w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.
CVE-2018-1000005
- EPSS 0.47%
- Veröffentlicht 24.01.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:24
libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pull/2231) that reading an HTTP/2 trailer could mess up future trailers since the stored size was one b...
CVE-2018-1000007
- EPSS 3.88%
- Veröffentlicht 24.01.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:24
libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the host in the initial URL but also, if asked to follow r...
CVE-2017-18075
- EPSS 0.07%
- Veröffentlicht 24.01.2018 10:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:18
crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access the AF_ALG-based AEAD interface (CONFIG_CRYPTO_USER_API_AEAD) and pcrypt (CONFIG_CRYPTO_PCRYPT) to cause a denial of service (kfree ...
- EPSS 0.03%
- Veröffentlicht 23.01.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:09
The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging improper memory address validation.
CVE-2018-5950
- EPSS 6.86%
- Veröffentlicht 23.01.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 04:09:44
Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL.
CVE-2017-15105
- EPSS 0.69%
- Veröffentlicht 23.01.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:05
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound int...
CVE-2016-10708
- EPSS 3.75%
- Veröffentlicht 21.01.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 02:44:33
sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.
CVE-2018-5784
- EPSS 0.29%
- Veröffentlicht 19.01.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:23
In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared nu...
CVE-2018-5785
- EPSS 0.68%
- Veröffentlicht 19.01.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:09:23
In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.