Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 250

Количество 55 250

redhat логотип

CVE-2018-20200

больше 7 лет назад

CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext and the boolean values while hooking the application. NOTE: This id is disputed because some parties don't consider this is a vulnerability. Their rationale can be found in https://github.com/square/okhttp/issues/4967

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-20191

больше 7 лет назад

hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which allows attackers to cause a denial of service (NULL pointer dereference).

CVSS3: 3.8
EPSS: Низкий
redhat логотип

CVE-2018-20182

больше 7 лет назад

rdesktop versions up to and including v1.8.3 contain a Buffer Overflow over the global variables in the function seamless_process_line() that results in memory corruption and probably even a remote code execution.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-20181

больше 7 лет назад

rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamless_process() and results in memory corruption and probably even a remote code execution.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-20180

больше 7 лет назад

rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_process() and results in memory corruption and probably even a remote code execution.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-20179

больше 7 лет назад

rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_process() and results in memory corruption and probably even a remote code execution.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-20178

больше 7 лет назад

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function process_demand_active() that results in a Denial of Service (segfault).

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-20177

больше 7 лет назад

rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in the function rdp_in_unistr() and results in memory corruption and possibly even a remote code execution.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-20176

больше 7 лет назад

rdesktop versions up to and including v1.8.3 contain several Out-Of- Bounds Reads in the file secure.c that result in a Denial of Service (segfault).

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-20175

больше 7 лет назад

rdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to Out-Of-Bounds Reads in the file mcs.c and result in a Denial of Service (segfault).

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-20174

больше 7 лет назад

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function ui_clip_handle_data() that results in an information leak.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-20169

больше 7 лет назад

An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2018-20126

больше 7 лет назад

hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.

CVSS3: 3.2
EPSS: Низкий
redhat логотип

CVE-2018-20125

больше 7 лет назад

hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in create_cq_ring or create_qp_rings.

CVSS3: 3.2
EPSS: Низкий
redhat логотип

CVE-2018-20124

больше 7 лет назад

hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge value.

CVSS3: 5
EPSS: Низкий
redhat логотип

CVE-2018-20123

больше 7 лет назад

pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error.

CVSS3: 3.2
EPSS: Низкий
redhat логотип

CVE-2018-20103

больше 7 лет назад

An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaustion.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-20102

больше 7 лет назад

An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-initialized part of the buffer, possibly accessing anything that was left on the stack, or even past the end of the 8193-byte buffer, depending on the value of accepted_payload_size.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2018-20099

больше 7 лет назад

There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-20098

больше 7 лет назад

There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-20200

CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext and the boolean values while hooking the application. NOTE: This id is disputed because some parties don't consider this is a vulnerability. Their rationale can be found in https://github.com/square/okhttp/issues/4967

CVSS3: 5.9
3%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20191

hw/rdma/vmw/pvrdma_main.c in QEMU does not implement a read operation (such as uar_read by analogy to uar_write), which allows attackers to cause a denial of service (NULL pointer dereference).

CVSS3: 3.8
4%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20182

rdesktop versions up to and including v1.8.3 contain a Buffer Overflow over the global variables in the function seamless_process_line() that results in memory corruption and probably even a remote code execution.

CVSS3: 7.5
7%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20181

rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamless_process() and results in memory corruption and probably even a remote code execution.

CVSS3: 7.5
7%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20180

rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function rdpsnddbg_process() and results in memory corruption and probably even a remote code execution.

CVSS3: 7.5
7%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20179

rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function lspci_process() and results in memory corruption and probably even a remote code execution.

CVSS3: 7.5
6%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20178

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function process_demand_active() that results in a Denial of Service (segfault).

CVSS3: 5.3
4%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20177

rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in the function rdp_in_unistr() and results in memory corruption and possibly even a remote code execution.

CVSS3: 5.3
8%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20176

rdesktop versions up to and including v1.8.3 contain several Out-Of- Bounds Reads in the file secure.c that result in a Denial of Service (segfault).

CVSS3: 5.3
3%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20175

rdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to Out-Of-Bounds Reads in the file mcs.c and result in a Denial of Service (segfault).

CVSS3: 5.3
4%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20174

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function ui_clip_handle_data() that results in an information leak.

CVSS3: 5.3
3%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20169

An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.

CVSS3: 6.4
1%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20126

hw/rdma/vmw/pvrdma_cmd.c in QEMU allows create_cq and create_qp memory leaks because errors are mishandled.

CVSS3: 3.2
0%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20125

hw/rdma/vmw/pvrdma_cmd.c in QEMU allows attackers to cause a denial of service (NULL pointer dereference or excessive memory allocation) in create_cq_ring or create_qp_rings.

CVSS3: 3.2
4%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20124

hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge value.

CVSS3: 5
0%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20123

pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error.

CVSS3: 3.2
0%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20103

An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaustion.

CVSS3: 7.5
6%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20102

An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-initialized part of the buffer, possibly accessing anything that was left on the stack, or even past the end of the 8193-byte buffer, depending on the value of accepted_payload_size.

CVSS3: 6.5
4%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20099

There is an infinite loop in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

CVSS3: 3.3
3%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-20098

There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.

CVSS3: 3.3
3%
Низкий
больше 7 лет назад

Уязвимостей на страницу