Show filters
997 Total Results
Displaying 271-280 of 997
Sort by:
Attacker Value
Unknown

CVE-2018-10911

Disclosure Date: September 04, 2018 (last updated November 27, 2024)
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
Attacker Value
Unknown

CVE-2018-16435

Disclosure Date: September 04, 2018 (last updated November 27, 2024)
Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.
0
Attacker Value
Unknown

CVE-2018-14622

Disclosure Date: August 30, 2018 (last updated November 08, 2023)
A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.
Attacker Value
Unknown

CVE-2018-16062

Disclosure Date: August 29, 2018 (last updated November 08, 2023)
dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
Attacker Value
Unknown

CVE-2017-15399

Disclosure Date: August 28, 2018 (last updated November 08, 2023)
A use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
0
Attacker Value
Unknown

CVE-2017-15398

Disclosure Date: August 28, 2018 (last updated November 08, 2023)
A stack buffer overflow in the QUIC networking stack in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to gain code execution via a malicious server.
0
Attacker Value
Unknown

CVE-2017-15429

Disclosure Date: August 28, 2018 (last updated November 08, 2023)
Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
0
Attacker Value
Unknown

CVE-2017-15396

Disclosure Date: August 28, 2018 (last updated November 08, 2023)
A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ before 60.2, as used in V8 in Google Chrome prior to 62.0.3202.75 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
0
Attacker Value
Unknown

CVE-2017-15412

Disclosure Date: August 28, 2018 (last updated November 08, 2023)
Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
0
Attacker Value
Unknown

CVE-2017-15422

Disclosure Date: August 28, 2018 (last updated November 08, 2023)
Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
0