Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 249

Количество 55 249

redhat логотип

CVE-2018-16491

больше 7 лет назад

A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2018-16490

больше 7 лет назад

A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype.

CVSS3: 4.2
EPSS: Низкий
redhat логотип

CVE-2018-16487

почти 8 лет назад

A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.

CVSS3: 5.6
EPSS: Низкий
redhat логотип

CVE-2018-16476

больше 7 лет назад

A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2018-16472

почти 8 лет назад

A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-16471

почти 8 лет назад

There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-16470

почти 8 лет назад

There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-16468

почти 8 лет назад

In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2018-16452

почти 7 лет назад

The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-16451

почти 7 лет назад

The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-16438

около 8 лет назад

An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in H5L_extern_query at H5Lexternal.c.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-16435

около 8 лет назад

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2018-16429

почти 8 лет назад

GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-16428

почти 8 лет назад

In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2018-16427

почти 8 лет назад

Various out of bounds reads when handling responses in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to potentially crash the opensc library using programs.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2018-16426

почти 8 лет назад

Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.

CVSS3: 2.4
EPSS: Низкий
redhat логотип

CVE-2018-16425

почти 8 лет назад

A double free when handling responses from an HSM Card in sc_pkcs15emu_sc_hsm_init in libopensc/pkcs15-sc-hsm.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2018-16424

почти 8 лет назад

A double free when handling responses in read_file in tools/egk-tool.c (aka the eGK card tool) in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2018-16423

почти 8 лет назад

A double free when handling responses from a smartcard in sc_file_set_sec_attr in libopensc/sc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2018-16422

почти 8 лет назад

A single byte buffer overflow when handling responses from an esteid Card in sc_pkcs15emu_esteid_init in libopensc/pkcs15-esteid.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-16491

A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.

CVSS3: 4.8
2%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-16490

A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype.

CVSS3: 4.2
1%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-16487

A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.

CVSS3: 5.6
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-16476

A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.

CVSS3: 4.3
3%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-16472

A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.

CVSS3: 5.3
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-16471

There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable.

CVSS3: 6.1
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-16470

There is a possible DoS vulnerability in the multipart parser in Rack before 2.0.6. Specially crafted requests can cause the multipart parser to enter a pathological state, causing the parser to use CPU resources disproportionate to the request size.

CVSS3: 5.3
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-16468

In the Loofah gem for Ruby, through v2.2.2, unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

CVSS3: 5.4
1%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-16452

The SMB parser in tcpdump before 4.9.3 has stack exhaustion in smbutil.c:smb_fdata() via recursion.

CVSS3: 7.5
4%
Низкий
почти 7 лет назад
redhat логотип
CVE-2018-16451

The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN.

CVSS3: 7.5
4%
Низкий
почти 7 лет назад
redhat логотип
CVE-2018-16438

An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in H5L_extern_query at H5Lexternal.c.

CVSS3: 5.3
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-16435

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

CVSS3: 5.5
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-16429

GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().

CVSS3: 7.5
4%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-16428

In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.

CVSS3: 9.8
5%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-16427

Various out of bounds reads when handling responses in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to potentially crash the opensc library using programs.

CVSS3: 4.3
0%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-16426

Endless recursion when handling responses from an IAS-ECC card in iasecc_select_file in libopensc/card-iasecc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to hang or crash the opensc library using programs.

CVSS3: 2.4
1%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-16425

A double free when handling responses from an HSM Card in sc_pkcs15emu_sc_hsm_init in libopensc/pkcs15-sc-hsm.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 4.3
1%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-16424

A double free when handling responses in read_file in tools/egk-tool.c (aka the eGK card tool) in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 4.3
1%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-16423

A double free when handling responses from a smartcard in sc_file_set_sec_attr in libopensc/sc.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 4.3
1%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-16422

A single byte buffer overflow when handling responses from an esteid Card in sc_pkcs15emu_esteid_init in libopensc/pkcs15-esteid.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact.

CVSS3: 4.3
1%
Низкий
почти 8 лет назад

Уязвимостей на страницу