CVE-2018-17847
- EPSS 0.91%
- Veröffentlicht 01.10.2018 08:29:02
- Zuletzt bearbeitet 21.11.2024 03:55:02
The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a "panic: runtime error" (index out of range) in (*nodeStack).pop in node.go, called from (*parser).clearActiveFormattingElemen...
CVE-2018-17848
- EPSS 1.03%
- Veröffentlicht 01.10.2018 08:29:02
- Zuletzt bearbeitet 21.11.2024 03:55:03
The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "panic: runtime error" (index out of range) in (*insertionModeStack).pop in node.go, called from inHeadIM, during an html.Parse cal...
CVE-2018-17825
- EPSS 0.48%
- Veröffentlicht 01.10.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:00
An issue was discovered in AdPlug 2.3.1. There are several double-free vulnerabilities in the CEmuopl class in emuopl.cpp because of a destructor's two OPLDestroy calls, each of which frees TL_TABLE, SIN_TABLE, AMS_TABLE, and VIB_TABLE.
CVE-2018-14647
- EPSS 1.95%
- Veröffentlicht 25.09.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:30
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions ...
CVE-2018-17142
- EPSS 0.75%
- Veröffentlicht 17.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:56
The html package (aka x/net/html) through 2018-09-17 in Go mishandles <math><template><mo><template>, leading to a "panic: runtime error" in parseCurrentToken in parse.go during an html.Parse call.
CVE-2018-17143
- EPSS 0.65%
- Veröffentlicht 17.09.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:56
The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><tBody><isindex/action=0>, leading to a "panic: runtime error" in inBodyIM in parse.go during an html.Parse call.
CVE-2018-17075
- EPSS 0.72%
- Veröffentlicht 16.09.2018 02:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:50
The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse of <template><object>, <template><applet>, or <template><marquee>. This is related to HTMLTreeBuilde...
CVE-2018-14598
- EPSS 3.14%
- Veröffentlicht 24.08.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:49:22
An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that will be freed later on, leading to DoS (segmentation f...
CVE-2018-14599
- EPSS 2.46%
- Veröffentlicht 24.08.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:49:23
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact.
CVE-2018-10844
- EPSS 0.19%
- Veröffentlicht 22.08.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:07
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data...