|
248441
|
9.8 |
CRITICAL
Network
|
opennetworking
|
openflow
|
OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake: The DPID (DataPath IDentifier) in the features_reply message are inherently t…
|
CWE-863
Incorrect Authorization
|
CVE-2018-1000155
|
2024-11-21 12:39 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248442
|
7.8 |
HIGH
Local
|
artifex
|
mupdf
|
In Artifex MuPDF 1.12.0 and earlier, a stack buffer overflow in function pdf_lookup_cmap_full in pdf/pdf-cmap.c could allow an attacker to execute arbitrary code via a crafted file.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-1000038
|
2024-11-21 12:39 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248443
|
5.5 |
MEDIUM
Local
|
artifex debian
|
mupdf debian_linux
|
In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) via a crafted file.
|
CWE-20
Improper Input Validation
|
CVE-2018-1000037
|
2024-11-21 12:39 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248444
|
5.5 |
MEDIUM
Local
|
artifex debian
|
mupdf debian_linux
|
In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of service (memory leak) via a crafted file.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-1000036
|
2024-11-21 12:39 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248445
|
8.8 |
HIGH
Network
|
kubernetes
|
cri-o
|
Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated …
|
CWE-269
Improper Privilege Management
|
CVE-2018-1000400
|
2024-11-21 12:39 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248446
|
7.6 |
HIGH
Adjacent
|
microsoft
|
windows_10 windows_server_2016
|
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate vSMB packet data, aka "Hyper-V vSMB Remote Code Execution Vulnerability." This affects Wi…
|
CWE-20
Improper Input Validation
|
CVE-2018-0961
|
2024-11-21 12:39 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248447
|
7.6 |
HIGH
Adjacent
|
microsoft
|
windows_server_2012 windows_10 windows_server_2016 windows_8.1 windows_server_2008 windows_7 windows_rt_8.1
|
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system, aka "Hyper-V Remote Code Ex…
|
CWE-20
Improper Input Validation
|
CVE-2018-0959
|
2024-11-21 12:39 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248448
|
5.3 |
MEDIUM
Local
|
microsoft
|
windows_10 windows_server_2016
|
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, …
|
NVD-CWE-noinfo
|
CVE-2018-0958
|
2024-11-21 12:39 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248449
|
7.5 |
HIGH
Network
|
microsoft
|
internet_explorer
|
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects …
|
CWE-787
Out-of-bounds Write
|
CVE-2018-0955
|
2024-11-21 12:39 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248450
|
7.5 |
HIGH
Network
|
microsoft
|
edge chakracore
|
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Mic…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-0953
|
2024-11-21 12:39 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|