Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 175

Количество 55 175

redhat логотип

CVE-2018-11683

около 8 лет назад

Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2018-11656

больше 8 лет назад

In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function ReadDCMImage in coders/dcm.c, which allows attackers to cause a denial of service via a crafted DCM image file.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-11655

больше 8 лет назад

In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function GetImagePixelCache in MagickCore/cache.c, which allows attackers to cause a denial of service via a crafted CALS image file.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-11645

почти 10 лет назад

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-11627

больше 8 лет назад

Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-11625

около 8 лет назад

In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over-read via a crafted file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-11624

около 8 лет назад

In ImageMagick 7.0.7-36 Q16, the ReadMATImage function in coders/mat.c allows attackers to cause a use after free via a crafted file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-11577

около 8 лет назад

Liblouis 3.5.0 has a Segmentation fault in lou_logPrint in logging.c.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2018-11574

около 8 лет назад

Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-11531

больше 8 лет назад

Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-1152

около 8 лет назад

libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2018-11508

больше 8 лет назад

The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-11506

больше 8 лет назад

The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact because sense buffers have different sizes at the CDROM layer and the SCSI layer, as demonstrated by a CDROMREADMODE2 ioctl call.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-11504

около 8 лет назад

The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html.

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2018-11503

около 8 лет назад

The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html.

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2018-11490

больше 8 лет назад

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is not checked. This will lead to a denial of service or possibly unspecified other impact.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-11489

больше 8 лет назад

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain CrntCode array index is not checked. This will lead to a denial of service or possibly unspecified other impact.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-11469

около 8 лет назад

Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, related to the proto_http.c check_request_for_cacheability function.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-11468

около 8 лет назад

The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html.

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2018-11440

около 8 лет назад

Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c.

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-11683

Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440.

CVSS3: 7.8
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-11656

In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function ReadDCMImage in coders/dcm.c, which allows attackers to cause a denial of service via a crafted DCM image file.

CVSS3: 5.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-11655

In ImageMagick 7.0.7-20 Q16 x86_64, a memory leak vulnerability was found in the function GetImagePixelCache in MagickCore/cache.c, which allows attackers to cause a denial of service via a crafted CALS image file.

CVSS3: 5.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-11645

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.

CVSS3: 5.3
3%
Низкий
почти 10 лет назад
redhat логотип
CVE-2018-11627

Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.

CVSS3: 6.1
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-11625

In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over-read via a crafted file.

CVSS3: 3.3
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-11624

In ImageMagick 7.0.7-36 Q16, the ReadMATImage function in coders/mat.c allows attackers to cause a use after free via a crafted file.

CVSS3: 3.3
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-11577

Liblouis 3.5.0 has a Segmentation fault in lou_logPrint in logging.c.

CVSS3: 4.3
3%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-11574

Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.

CVSS3: 7.5
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-11531

Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.

CVSS3: 3.3
3%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1152

libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image.

CVSS3: 4.3
3%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-11508

The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.

CVSS3: 3.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-11506

The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact because sense buffers have different sizes at the CDROM layer and the SCSI layer, as demonstrated by a CDROMREADMODE2 ioctl call.

CVSS3: 5.3
0%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-11504

The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html.

CVSS3: 4.4
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-11503

The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html.

CVSS3: 4.4
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-11490

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private->RunningCode - 2" array index is not checked. This will lead to a denial of service or possibly unspecified other impact.

CVSS3: 3.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-11489

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain CrntCode array index is not checked. This will lead to a denial of service or possibly unspecified other impact.

CVSS3: 3.3
3%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-11469

Incorrect caching of responses to requests including an Authorization header in HAProxy 1.8.0 through 1.8.9 (if cache enabled) allows attackers to achieve information disclosure via an unauthenticated remote request, related to the proto_http.c check_request_for_cacheability function.

CVSS3: 7.5
3%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-11468

The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file, as demonstrated by mkd2html.

CVSS3: 4.4
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-11440

Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c.

CVSS3: 3.3
3%
Низкий
около 8 лет назад

Уязвимостей на страницу