Show filters
997 Total Results
Displaying 271-280 of 997
Sort by:
Attacker Value
Unknown
CVE-2018-10911
Disclosure Date: September 04, 2018 (last updated November 27, 2024)
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
0
Attacker Value
Unknown
CVE-2018-16435
Disclosure Date: September 04, 2018 (last updated November 27, 2024)
Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.
0
Attacker Value
Unknown
CVE-2018-14622
Disclosure Date: August 30, 2018 (last updated November 08, 2023)
A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.
0
Attacker Value
Unknown
CVE-2018-16062
Disclosure Date: August 29, 2018 (last updated November 08, 2023)
dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
0
Attacker Value
Unknown
CVE-2017-15399
Disclosure Date: August 28, 2018 (last updated November 08, 2023)
A use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2017-15398
Disclosure Date: August 28, 2018 (last updated November 08, 2023)
A stack buffer overflow in the QUIC networking stack in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to gain code execution via a malicious server.
0
Attacker Value
Unknown
CVE-2017-15429
Disclosure Date: August 28, 2018 (last updated November 08, 2023)
Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2017-15396
Disclosure Date: August 28, 2018 (last updated November 08, 2023)
A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ before 60.2, as used in V8 in Google Chrome prior to 62.0.3202.75 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2017-15412
Disclosure Date: August 28, 2018 (last updated November 08, 2023)
Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2017-15422
Disclosure Date: August 28, 2018 (last updated November 08, 2023)
Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
0