Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 250

Количество 55 250

redhat логотип

CVE-2018-19361

почти 8 лет назад

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2018-19360

почти 8 лет назад

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2018-19358

около 8 лет назад

GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms (involving the busconfig and policy XML elements) are not used. NOTE: the vendor disputes this because, according to the security model, untrusted applications must not be allowed to access the user's session bus socket.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2018-19270

почти 8 лет назад

No description is available for this CVE.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2018-19218

почти 8 лет назад

In LibSass 3.5-stable, there is an illegal address access at Sass::Parser::parse_css_variable_value_token that will lead to a DoS attack.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-19217

почти 8 лет назад

In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2018-19216

почти 8 лет назад

Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-19215

почти 8 лет назад

Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and ! characters.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-19214

почти 8 лет назад

Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-19213

почти 8 лет назад

Netwide Assembler (NASM) through 2.14rc16 has memory leaks that may lead to DoS, related to nasm_malloc in nasmlib/malloc.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-19211

почти 8 лет назад

In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2018-19210

почти 8 лет назад

In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-19209

почти 8 лет назад

Netwide Assembler (NASM) 2.14rc15 has a NULL pointer dereference in the function find_label in asm/labels.c that will lead to a DoS attack.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-19208

почти 8 лет назад

In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-19200

почти 8 лет назад

An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* function.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-19199

почти 8 лет назад

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2018-19198

почти 8 лет назад

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2018-19149

почти 8 лет назад

Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-19139

почти 8 лет назад

An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-19134

почти 8 лет назад

In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dictionary was a structure type.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-19361

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.

CVSS3: 7.3
10%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19360

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.

CVSS3: 7.3
10%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19358

GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms (involving the busconfig and policy XML elements) are not used. NOTE: the vendor disputes this because, according to the security model, untrusted applications must not be allowed to access the user's session bus socket.

CVSS3: 5.5
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-19270

No description is available for this CVE.

CVSS3: 7.8
почти 8 лет назад
redhat логотип
CVE-2018-19218

In LibSass 3.5-stable, there is an illegal address access at Sass::Parser::parse_css_variable_value_token that will lead to a DoS attack.

CVSS3: 3.3
1%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19217

In ncurses, possibly a 6.x version, there is a NULL pointer dereference at the function _nc_name_match that will lead to a denial of service attack. NOTE: the original report stated version 6.1, but the issue did not reproduce for that version according to the maintainer or a reliable third-party

CVSS3: 6.5
1%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19216

Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.

CVSS3: 3.3
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19215

Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and ! characters.

CVSS3: 3.3
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19214

Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.

CVSS3: 3.3
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19213

Netwide Assembler (NASM) through 2.14rc16 has memory leaks that may lead to DoS, related to nasm_malloc in nasmlib/malloc.c.

CVSS3: 3.3
1%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19211

In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.

CVSS3: 4.7
1%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19210

In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset.

CVSS3: 3.3
4%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19209

Netwide Assembler (NASM) 2.14rc15 has a NULL pointer dereference in the function find_label in asm/labels.c that will lead to a DoS attack.

CVSS3: 3.3
1%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19208

In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h.

CVSS3: 3.3
1%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19200

An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* function.

CVSS3: 5.3
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19199

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.

CVSS3: 7.3
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19198

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.

CVSS3: 7.3
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19149

Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment.

CVSS3: 3.3
3%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19139

An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c.

CVSS3: 3.3
3%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19134

In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dictionary was a structure type.

CVSS3: 7.3
5%
Низкий
почти 8 лет назад

Уязвимостей на страницу