Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 249

Количество 55 249

redhat логотип

CVE-2018-14348

около 8 лет назад

libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2018-14344

около 8 лет назад

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ISMP dissector could crash. This was addressed in epan/dissectors/packet-ismp.c by validating the IPX address length to avoid a buffer over-read.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-14343

около 8 лет назад

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ASN.1 BER dissector could crash. This was addressed in epan/dissectors/packet-ber.c by ensuring that length values do not exceed the maximum signed integer.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-14342

около 8 лет назад

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop. This was addressed in epan/dissectors/packet-bgp.c by validating Path Attribute lengths.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-14341

около 8 лет назад

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the DICOM dissector could go into a large or infinite loop. This was addressed in epan/dissectors/packet-dcm.c by preventing an offset overflow.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-14340

около 8 лет назад

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, dissectors that support zlib decompression could crash. This was addressed in epan/tvbuff_zlib.c by rejecting negative lengths to avoid a buffer over-read.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-14339

около 8 лет назад

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the MMSE dissector could go into an infinite loop. This was addressed in epan/proto.c by adding offset and length validation.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-14338

около 8 лет назад

samples/geotag.cpp in the example code of Exiv2 0.26 misuses the realpath function on POSIX platforms (other than Apple platforms) where glibc is not used, possibly leading to a buffer overflow.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-14335

около 8 лет назад

An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.

CVSS3: 4.3
EPSS: Средний
redhat логотип

CVE-2018-1417

больше 8 лет назад

Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code running under a security manager to elevate its privileges. IBM X-Force ID: 138823.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-14048

около 8 лет назад

An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-14046

около 8 лет назад

Exiv2 0.26 has a heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-14045

около 8 лет назад

The FIRFilter::evaluateFilterMulti function in FIRFilter.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-14044

около 8 лет назад

The RateTransposer::setChannels function in RateTransposer.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2018-14042

около 8 лет назад

In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-14041

около 8 лет назад

In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-14040

около 8 лет назад

In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-14038

около 8 лет назад

No description is available for this CVE.

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2018-14036

около 8 лет назад

Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c.

CVSS3: 5
EPSS: Низкий
redhat логотип

CVE-2018-14035

около 8 лет назад

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5VM_memcpyvv in H5VM.c.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-14348

libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.

CVSS3: 4.4
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14344

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ISMP dissector could crash. This was addressed in epan/dissectors/packet-ismp.c by validating the IPX address length to avoid a buffer over-read.

CVSS3: 5.9
3%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14343

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the ASN.1 BER dissector could crash. This was addressed in epan/dissectors/packet-ber.c by ensuring that length values do not exceed the maximum signed integer.

CVSS3: 5.9
3%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14342

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the BGP protocol dissector could go into a large loop. This was addressed in epan/dissectors/packet-bgp.c by validating Path Attribute lengths.

CVSS3: 5.9
4%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14341

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the DICOM dissector could go into a large or infinite loop. This was addressed in epan/dissectors/packet-dcm.c by preventing an offset overflow.

CVSS3: 5.9
4%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14340

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, dissectors that support zlib decompression could crash. This was addressed in epan/tvbuff_zlib.c by rejecting negative lengths to avoid a buffer over-read.

CVSS3: 5.9
3%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14339

In Wireshark 2.6.0 to 2.6.1, 2.4.0 to 2.4.7, and 2.2.0 to 2.2.15, the MMSE dissector could go into an infinite loop. This was addressed in epan/proto.c by adding offset and length validation.

CVSS3: 5.9
4%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14338

samples/geotag.cpp in the example code of Exiv2 0.26 misuses the realpath function on POSIX platforms (other than Apple platforms) where glibc is not used, possibly leading to a buffer overflow.

CVSS3: 3.3
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14335

An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.

CVSS3: 4.3
13%
Средний
около 8 лет назад
redhat логотип
CVE-2018-1417

Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code running under a security manager to elevate its privileges. IBM X-Force ID: 138823.

CVSS3: 7.5
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-14048

An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.

CVSS3: 3.3
3%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14046

Exiv2 0.26 has a heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp.

CVSS3: 3.3
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14045

The FIRFilter::evaluateFilterMulti function in FIRFilter.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch.

CVSS3: 3.3
3%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14044

The RateTransposer::setChannels function in RateTransposer.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch.

CVSS3: 6.5
3%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14042

In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.

CVSS3: 6.1
4%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14041

In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

CVSS3: 6.1
4%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14040

In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

CVSS3: 6.1
4%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14038

No description is available for this CVE.

CVSS3: 4.7
около 8 лет назад
redhat логотип
CVE-2018-14036

Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c.

CVSS3: 5
3%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-14035

An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5VM_memcpyvv in H5VM.c.

CVSS3: 5.3
1%
Низкий
около 8 лет назад

Уязвимостей на страницу