Show filters
482 Total Results
Displaying 211-220 of 482
Sort by:
Attacker Value
Unknown
CVE-2018-1068
Disclosure Date: March 16, 2018 (last updated November 26, 2024)
A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privileged user to arbitrarily write to a limited range of kernel memory.
0
Attacker Value
Unknown
CVE-2018-7858
Disclosure Date: March 12, 2018 (last updated November 26, 2024)
Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds access and QEMU process crash) by leveraging incorrect region calculation when updating VGA display.
0
Attacker Value
Unknown
CVE-2016-9600
Disclosure Date: March 12, 2018 (last updated November 26, 2024)
JasPer before version 2.0.10 is vulnerable to a null pointer dereference was found in the decoded creation of JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash.
0
Attacker Value
Unknown
CVE-2018-7550
Disclosure Date: March 01, 2018 (last updated January 31, 2024)
The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU host via a mh_load_end_addr value greater than mh_bss_end_addr, which triggers an out-of-bounds read or write memory access.
0
Attacker Value
Unknown
CVE-2018-7225
Disclosure Date: February 19, 2018 (last updated November 26, 2024)
An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.
0
Attacker Value
Unknown
CVE-2018-5379
Disclosure Date: February 19, 2018 (last updated November 26, 2024)
The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A successful attack could cause a denial of service or potentially allow an attacker to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2018-1049
Disclosure Date: February 16, 2018 (last updated November 26, 2024)
In systemd prior to 234 a race condition exists between .mount and .automount units such that automount requests from kernel may not be serviced by systemd resulting in kernel holding the mountpoint and any processes that try to use said mount will hang. A race condition like this may lead to denial of service, until mount points are unmounted.
0
Attacker Value
Unknown
CVE-2018-6927
Disclosure Date: February 12, 2018 (last updated November 26, 2024)
The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact by triggering a negative wake or requeue value.
0
Attacker Value
Unknown
CVE-2018-6871
Disclosure Date: February 09, 2018 (last updated November 26, 2024)
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
0
Attacker Value
Unknown
CVE-2018-6574
Disclosure Date: February 07, 2018 (last updated November 08, 2023)
Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not blocked.
0