Show filters
19 Total Results
Displaying 11-19 of 19
Sort by:
Attacker Value
Unknown
CVE-2018-13988
Disclosure Date: July 25, 2018 (last updated November 27, 2024)
Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file.
0
Attacker Value
Unknown
CVE-2018-12910
Disclosure Date: July 05, 2018 (last updated November 08, 2023)
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
0
Attacker Value
Unknown
CVE-2018-1061
Disclosure Date: June 19, 2018 (last updated November 08, 2023)
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.
0
Attacker Value
Unknown
CVE-2018-1060
Disclosure Date: June 18, 2018 (last updated November 08, 2023)
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.
0
Attacker Value
Unknown
CVE-2018-0495
Disclosure Date: June 13, 2018 (last updated November 08, 2023)
Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
0
Attacker Value
Unknown
CVE-2017-18267
Disclosure Date: May 10, 2018 (last updated November 26, 2024)
The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.
0
Attacker Value
Unknown
CVE-2018-10768
Disclosure Date: May 06, 2018 (last updated November 26, 2024)
There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected.
0
Attacker Value
Unknown
CVE-2018-10767
Disclosure Date: May 06, 2018 (last updated November 26, 2024)
There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack.
0
Attacker Value
Unknown
CVE-2018-10733
Disclosure Date: May 04, 2018 (last updated November 26, 2024)
There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack.
0