Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 249

Количество 55 249

redhat логотип

CVE-2018-17983

почти 8 лет назад

cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest entry.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2018-17977

почти 8 лет назад

The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute crafted applications, as demonstrated on CentOS 7.

CVSS3: 4.9
EPSS: Низкий
redhat логотип

CVE-2018-17972

почти 8 лет назад

An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through 4.18.11. It does not ensure that only root may inspect the kernel stack of an arbitrary task, allowing a local attacker to exploit racy stack unwinding and leak kernel task stack contents.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-17967

больше 8 лет назад

ImageMagick 7.0.7-28 has a memory leak vulnerability in ReadBGRImage in coders/bgr.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-17966

больше 8 лет назад

ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePDBImage in coders/pdb.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-17965

больше 8 лет назад

ImageMagick 7.0.7-28 has a memory leak vulnerability in WriteSGIImage in coders/sgi.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-17963

больше 8 лет назад

qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2018-17962

почти 8 лет назад

Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2018-17961

почти 8 лет назад

Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-17958

почти 8 лет назад

Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2018-17953

почти 8 лет назад

A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE Linux Enterprise 15 could lead to pam_access rules not being applied (fail open).

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-17942

почти 8 лет назад

The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because memory is not allocated for a trailing '\0' character during %f processing.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-17848

почти 8 лет назад

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "panic: runtime error" (index out of range) in (*insertionModeStack).pop in node.go, called from inHeadIM, during an html.Parse call.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-17847

почти 8 лет назад

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a "panic: runtime error" (index out of range) in (*nodeStack).pop in node.go, called from (*parser).clearActiveFormattingElements, during an html.Parse call.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-17846

почти 8 лет назад

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <table><math><select><mi><select></table>, leading to an infinite loop during an html.Parse call because inSelectIM and inSelectInTableIM do not comply with a specification.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-17828

почти 8 лет назад

Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2018-17795

почти 8 лет назад

The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, a similar issue to CVE-2017-9935.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2018-17794

почти 8 лет назад

An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_to_from when called from iterate_demangle_function.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-17581

почти 8 лет назад

CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-17572

больше 10 лет назад

InfluxDB 0.9.5 has Reflected XSS in the Write Data module.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-17983

cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest entry.

CVSS3: 4.3
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-17977

The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute crafted applications, as demonstrated on CentOS 7.

CVSS3: 4.9
0%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-17972

An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through 4.18.11. It does not ensure that only root may inspect the kernel stack of an arbitrary task, allowing a local attacker to exploit racy stack unwinding and leak kernel task stack contents.

CVSS3: 3.3
0%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-17967

ImageMagick 7.0.7-28 has a memory leak vulnerability in ReadBGRImage in coders/bgr.c.

CVSS3: 3.3
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-17966

ImageMagick 7.0.7-28 has a memory leak vulnerability in WritePDBImage in coders/pdb.c.

CVSS3: 3.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-17965

ImageMagick 7.0.7-28 has a memory leak vulnerability in WriteSGIImage in coders/sgi.c.

CVSS3: 3.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-17963

qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.

CVSS3: 6.5
5%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-17962

Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.

CVSS3: 6.5
5%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-17961

Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.

CVSS3: 7.5
10%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-17958

Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used.

CVSS3: 6.5
6%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-17953

A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE Linux Enterprise 15 could lead to pam_access rules not being applied (fail open).

CVSS3: 7.5
1%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-17942

The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because memory is not allocated for a trailing '\0' character during %f processing.

CVSS3: 3.3
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-17848

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "panic: runtime error" (index out of range) in (*insertionModeStack).pop in node.go, called from inHeadIM, during an html.Parse call.

CVSS3: 5.3
3%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-17847

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a "panic: runtime error" (index out of range) in (*nodeStack).pop in node.go, called from (*parser).clearActiveFormattingElements, during an html.Parse call.

CVSS3: 5.3
3%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-17846

The html package (aka x/net/html) through 2018-09-25 in Go mishandles <table><math><select><mi><select></table>, leading to an infinite loop during an html.Parse call because inSelectIM and inSelectInTableIM do not comply with a specification.

CVSS3: 5.3
3%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-17828

Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file.

CVSS3: 5.5
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-17795

The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, a similar issue to CVE-2017-9935.

CVSS3: 4.3
4%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-17794

An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_to_from when called from iterate_demangle_function.

CVSS3: 3.3
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-17581

CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to Denial of service.

CVSS3: 3.3
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-17572

InfluxDB 0.9.5 has Reflected XSS in the Write Data module.

CVSS3: 4.8
1%
Низкий
больше 10 лет назад

Уязвимостей на страницу