Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 479

Количество 55 479

redhat логотип

CVE-2018-9268

больше 8 лет назад

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-smb2.c has a memory leak.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-9267

больше 8 лет назад

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-lapd.c has a memory leak.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-9266

больше 8 лет назад

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-isup.c has a memory leak.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-9265

больше 8 лет назад

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-tn3270.c has a memory leak.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-9264

больше 8 лет назад

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the ADB dissector could crash with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-adb.c by checking for a length inconsistency.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-9263

больше 8 лет назад

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the Kerberos dissector could crash. This was addressed in epan/dissectors/packet-kerberos.c by ensuring a nonzero key length.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-9262

больше 8 лет назад

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the VLAN dissector could crash. This was addressed in epan/dissectors/packet-vlan.c by limiting VLAN tag nesting to restrict the recursion depth.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-9261

больше 8 лет назад

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-nbap.c by prohibiting the self-linking of DCH-IDs.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-9260

больше 8 лет назад

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the IEEE 802.15.4 dissector could crash. This was addressed in epan/dissectors/packet-ieee802154.c by ensuring that an allocation step occurs.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-9259

около 9 лет назад

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. This was addressed in epan/dissectors/file-mp4.c by restricting the box recursion depth.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-9258

больше 8 лет назад

In Wireshark 2.4.0 to 2.4.5, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by preserving valid data sources.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-9257

больше 8 лет назад

In Wireshark 2.4.0 to 2.4.5, the CQL dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-cql.c by checking for a nonzero number of columns.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2018-9256

больше 8 лет назад

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the LWAPP dissector could crash. This was addressed in epan/dissectors/packet-lwapp.c by limiting the encapsulation levels to restrict the recursion depth.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-9252

больше 8 лет назад

JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2018-9251

больше 8 лет назад

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.

CVSS3: 3.5
EPSS: Низкий
redhat логотип

CVE-2018-9234

больше 8 лет назад

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

CVSS3: 2.2
EPSS: Низкий
redhat логотип

CVE-2018-9159

больше 8 лет назад

In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. NOTE: this product is unrelated to Ignite Realtime Spark.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-9154

больше 8 лет назад

There is a reachable abort in the function jpc_dec_process_sot in libjasper/jpc/jpc_dec.c of JasPer 2.0.14 that will lead to a remote denial of service attack by triggering an unexpected jas_alloc2 return value, a different vulnerability than CVE-2017-13745.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-9145

больше 8 лет назад

In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size. A large size value may lead to a SIGABRT during an attempt at memory allocation. NOTE: some third parties have been unable to reproduce the SIGABRT when using the 4-DataBuf-abort-1 PoC file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-9144

больше 8 лет назад

In Exiv2 0.26, there is an out-of-bounds read in Exiv2::Internal::binaryToString in image.cpp. It could result in denial of service or information disclosure.

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-9268

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-smb2.c has a memory leak.

CVSS3: 5.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9267

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-lapd.c has a memory leak.

CVSS3: 5.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9266

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-isup.c has a memory leak.

CVSS3: 5.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9265

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, epan/dissectors/packet-tn3270.c has a memory leak.

CVSS3: 5.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9264

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the ADB dissector could crash with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-adb.c by checking for a length inconsistency.

CVSS3: 5.3
3%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9263

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the Kerberos dissector could crash. This was addressed in epan/dissectors/packet-kerberos.c by ensuring a nonzero key length.

CVSS3: 5.3
3%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9262

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the VLAN dissector could crash. This was addressed in epan/dissectors/packet-vlan.c by limiting VLAN tag nesting to restrict the recursion depth.

CVSS3: 5.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9261

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-nbap.c by prohibiting the self-linking of DCH-IDs.

CVSS3: 5.3
3%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9260

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the IEEE 802.15.4 dissector could crash. This was addressed in epan/dissectors/packet-ieee802154.c by ensuring that an allocation step occurs.

CVSS3: 5.3
3%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9259

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. This was addressed in epan/dissectors/file-mp4.c by restricting the box recursion depth.

CVSS3: 5.3
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2018-9258

In Wireshark 2.4.0 to 2.4.5, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by preserving valid data sources.

CVSS3: 5.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9257

In Wireshark 2.4.0 to 2.4.5, the CQL dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-cql.c by checking for a nonzero number of columns.

CVSS3: 4.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9256

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the LWAPP dissector could crash. This was addressed in epan/dissectors/packet-lwapp.c by limiting the encapsulation levels to restrict the recursion depth.

CVSS3: 5.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9252

JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c.

CVSS3: 6.5
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9251

The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.

CVSS3: 3.5
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9234

GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

CVSS3: 2.2
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9159

In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. NOTE: this product is unrelated to Ignite Realtime Spark.

CVSS3: 5.3
5%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9154

There is a reachable abort in the function jpc_dec_process_sot in libjasper/jpc/jpc_dec.c of JasPer 2.0.14 that will lead to a remote denial of service attack by triggering an unexpected jas_alloc2 return value, a different vulnerability than CVE-2017-13745.

CVSS3: 3.3
4%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9145

In the DataBuf class in include/exiv2/types.hpp in Exiv2 0.26, an issue exists in the constructor with an initial buffer size. A large size value may lead to a SIGABRT during an attempt at memory allocation. NOTE: some third parties have been unable to reproduce the SIGABRT when using the 4-DataBuf-abort-1 PoC file.

CVSS3: 3.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-9144

In Exiv2 0.26, there is an out-of-bounds read in Exiv2::Internal::binaryToString in image.cpp. It could result in denial of service or information disclosure.

CVSS3: 3.3
2%
Низкий
больше 8 лет назад

Уязвимостей на страницу