Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 249

Количество 55 249

redhat логотип

CVE-2018-14469

почти 7 лет назад

The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-14468

почти 7 лет назад

The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-14467

почти 7 лет назад

The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP).

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-14466

почти 7 лет назад

The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert().

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-14465

почти 7 лет назад

The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-14464

почти 7 лет назад

The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-14463

почти 7 лет назад

The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-14462

почти 7 лет назад

The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-14461

почти 7 лет назад

The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-14460

около 8 лет назад

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_sdspace_decode in H5Osdspace.c.

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2018-14438

около 8 лет назад

In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the access control arbitrarily.

CVSS3: 5.6
EPSS: Низкий
redhat логотип

CVE-2018-14437

около 8 лет назад

ImageMagick 7.0.8-4 has a memory leak in parse8BIM in coders/meta.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-14436

около 8 лет назад

ImageMagick 7.0.8-4 has a memory leak in ReadMIFFImage in coders/miff.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-14435

около 8 лет назад

ImageMagick 7.0.8-4 has a memory leak in DecodeImage in coders/pcd.c.

CVSS3: 3.5
EPSS: Низкий
redhat логотип

CVE-2018-14434

около 8 лет назад

ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-14432

около 8 лет назад

In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated user may discover projects they have no authority to access, leaking all projects in the deployment and their attributes. Only Keystone with the /v3/OS-FEDERATION endpoint enabled via policy.json is affected.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-14424

около 8 лет назад

The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2018-14423

около 8 лет назад

Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-14404

около 8 лет назад

A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the application.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2018-14378

около 8 лет назад

No description is available for this CVE.

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-14469

The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().

CVSS3: 7.5
5%
Низкий
почти 7 лет назад
redhat логотип
CVE-2018-14468

The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().

CVSS3: 7.5
4%
Низкий
почти 7 лет назад
redhat логотип
CVE-2018-14467

The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP).

CVSS3: 7.5
4%
Низкий
почти 7 лет назад
redhat логотип
CVE-2018-14466

The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert().

CVSS3: 7.5
4%
Низкий
почти 7 лет назад
redhat логотип
CVE-2018-14465

The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().

CVSS3: 7.5
4%
Низкий
почти 7 лет назад
redhat логотип
CVE-2018-14464

The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().

CVSS3: 7.5
4%
Низкий
почти 7 лет назад
redhat логотип
CVE-2018-14463

The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.

CVSS3: 7.5
5%
Низкий
почти 7 лет назад
redhat логотип
CVE-2018-14462

The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().

CVSS3: 7.5
4%
Низкий
почти 7 лет назад
redhat логотип
CVE-2018-14461

The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().

CVSS3: 7.5
4%
Низкий
почти 7 лет назад
redhat логотип
CVE-2018-14460

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_sdspace_decode in H5Osdspace.c.

CVSS3: 4.7
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14438

In Wireshark through 2.6.2, the create_app_running_mutex function in wsutil/file_util.c calls SetSecurityDescriptorDacl to set a NULL DACL, which allows attackers to modify the access control arbitrarily.

CVSS3: 5.6
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14437

ImageMagick 7.0.8-4 has a memory leak in parse8BIM in coders/meta.c.

CVSS3: 3.3
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14436

ImageMagick 7.0.8-4 has a memory leak in ReadMIFFImage in coders/miff.c.

CVSS3: 3.3
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14435

ImageMagick 7.0.8-4 has a memory leak in DecodeImage in coders/pcd.c.

CVSS3: 3.5
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14434

ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c.

CVSS3: 3.3
3%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14432

In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated user may discover projects they have no authority to access, leaking all projects in the deployment and their attributes. Only Keystone with the /v3/OS-FEDERATION endpoint enabled via policy.json is affected.

CVSS3: 5.3
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14424

The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution.

CVSS3: 7.3
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14423

Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service (application crash).

CVSS3: 3.3
3%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14404

A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the application.

CVSS3: 6.5
4%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14378

No description is available for this CVE.

CVSS3: 3.3
около 8 лет назад

Уязвимостей на страницу