Количество 18 824
Количество 18 824
CVE-2018-15687
CVE-2018-15686
CVE-2018-15664
Docker Elevation of Privilege Vulnerability
CVE-2018-14628
An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.
CVE-2018-14348
CVE-2018-14042
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
CVE-2018-14040
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attributeIn Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute
CVE-2018-13420
Google gperftools 2.7 has a memory leak in malloc_extension.cc related to MallocExtension::Register and InitModule. NOTE: the software maintainer indicates that this is not a bug; it is only a false-positive report from the LeakSanitizer program
CVE-2018-13419
CVE-2018-13410
CVE-2018-13139
CVE-2018-1311
CVE-2018-12207
Windows Denial of Service Vulnerability
CVE-2018-12123
Node.js: All versions prior to Node.js 6.15.0 8.14.0 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname that hostname can be spoofed by using a mixed case "javascript:" (e.g. "javAscript:") protocol (other protocols are not affected). If security decisions are made about the URL based on the hostname they may be incorrect.
CVE-2018-12122
Node.js: All versions prior to Node.js 6.15.0 8.14.0 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time.
CVE-2018-12121
Node.js: All versions prior to Node.js 6.15.0 8.14.0 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection) and carefully timed completion of the headers it is possible to cause the HTTP server to abort from heap allocation failure. Attack potential is mitigated by the use of a load balancer or other proxy layer.
CVE-2018-12116
Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request then data can be provided which will trigger a second unexpected and user-defined HTTP request to made to the same server.
CVE-2018-11694
CVE-2018-11439
The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted audio file.
CVE-2018-1129
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVSS3: 7 | 0% Низкий | больше 5 лет назад | ||
CVSS3: 7.8 | 1% Низкий | больше 5 лет назад | ||
CVE-2018-15664 Docker Elevation of Privilege Vulnerability | 6% Низкий | больше 6 лет назад | ||
CVE-2018-14628 An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store. | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
CVSS3: 8.1 | 0% Низкий | больше 5 лет назад | ||
CVE-2018-14042 In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip. | 2% Низкий | 5 месяцев назад | ||
CVE-2018-14040 In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attributeIn Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute | CVSS3: 6.1 | 2% Низкий | 5 месяцев назад | |
CVE-2018-13420 Google gperftools 2.7 has a memory leak in malloc_extension.cc related to MallocExtension::Register and InitModule. NOTE: the software maintainer indicates that this is not a bug; it is only a false-positive report from the LeakSanitizer program | CVSS3: 7.5 | 0% Низкий | больше 5 лет назад | |
CVSS3: 6.5 | 0% Низкий | около 5 лет назад | ||
CVSS3: 9.8 | 8% Низкий | больше 5 лет назад | ||
CVSS3: 8.8 | 2% Низкий | около 5 лет назад | ||
CVSS3: 8.1 | 4% Низкий | почти 4 года назад | ||
CVE-2018-12207 Windows Denial of Service Vulnerability | CVSS3: 4.7 | 0% Низкий | больше 6 лет назад | |
CVE-2018-12123 Node.js: All versions prior to Node.js 6.15.0 8.14.0 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname that hostname can be spoofed by using a mixed case "javascript:" (e.g. "javAscript:") protocol (other protocols are not affected). If security decisions are made about the URL based on the hostname they may be incorrect. | CVSS3: 4.3 | 5% Низкий | больше 4 лет назад | |
CVE-2018-12122 Node.js: All versions prior to Node.js 6.15.0 8.14.0 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time. | CVSS3: 7.5 | 4% Низкий | больше 4 лет назад | |
CVE-2018-12121 Node.js: All versions prior to Node.js 6.15.0 8.14.0 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection) and carefully timed completion of the headers it is possible to cause the HTTP server to abort from heap allocation failure. Attack potential is mitigated by the use of a load balancer or other proxy layer. | CVSS3: 7.5 | 6% Низкий | больше 4 лет назад | |
CVE-2018-12116 Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request then data can be provided which will trigger a second unexpected and user-defined HTTP request to made to the same server. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
CVSS3: 8.8 | 0% Низкий | больше 2 лет назад | ||
CVE-2018-11439 The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted audio file. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
CVSS3: 6.5 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу