|
247291
|
5.5 |
MEDIUM
Local
|
artifex debian
|
mupdf debian_linux
|
In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker to cause a denial of service (crash) or influence program flow via a crafted fi…
|
CWE-20
Improper Input Validation
|
CVE-2018-1000040
|
2024-11-21 12:39 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247292
|
7.8 |
HIGH
Local
|
artifex
|
mupdf
|
In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or cause a denial of service via a crafted fil…
|
CWE-416
Use After Free
|
CVE-2018-1000039
|
2024-11-21 12:39 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247293
|
9.1 |
CRITICAL
Network
|
debian canonical haxx redhat oracle
|
debian_linux ubuntu_linux curl enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_manager_ops_center peoplesoft_enterprise_peopletools co…
|
curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end o…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-1000301
|
2024-11-21 12:39 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247294
|
5.5 |
MEDIUM
Local
|
debian linux canonical redhat
|
debian_linux linux_kernel ubuntu_linux enterprise_linux_desktop enterprise_linux enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterpris…
|
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable v…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-1000199
|
2024-11-21 12:39 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247295
|
9.8 |
CRITICAL
Network
|
opennetworking
|
openflow
|
OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake: The DPID (DataPath IDentifier) in the features_reply message are inherently t…
|
CWE-863
Incorrect Authorization
|
CVE-2018-1000155
|
2024-11-21 12:39 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247296
|
7.8 |
HIGH
Local
|
artifex
|
mupdf
|
In Artifex MuPDF 1.12.0 and earlier, a stack buffer overflow in function pdf_lookup_cmap_full in pdf/pdf-cmap.c could allow an attacker to execute arbitrary code via a crafted file.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-1000038
|
2024-11-21 12:39 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247297
|
5.5 |
MEDIUM
Local
|
artifex debian
|
mupdf debian_linux
|
In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) via a crafted file.
|
CWE-20
Improper Input Validation
|
CVE-2018-1000037
|
2024-11-21 12:39 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247298
|
5.5 |
MEDIUM
Local
|
artifex debian
|
mupdf debian_linux
|
In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of service (memory leak) via a crafted file.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-1000036
|
2024-11-21 12:39 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247299
|
8.8 |
HIGH
Network
|
kubernetes
|
cri-o
|
Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated …
|
CWE-269
Improper Privilege Management
|
CVE-2018-1000400
|
2024-11-21 12:39 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247300
|
7.6 |
HIGH
Adjacent
|
microsoft
|
windows_10 windows_server_2016
|
A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate vSMB packet data, aka "Hyper-V vSMB Remote Code Execution Vulnerability." This affects Wi…
|
CWE-20
Improper Input Validation
|
CVE-2018-0961
|
2024-11-21 12:39 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|