Show filters
492 Total Results
Displaying 41-50 of 492
Sort by:
Attacker Value
Unknown

CVE-2018-12910

Disclosure Date: July 05, 2018 (last updated November 08, 2023)
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
0
Attacker Value
Unknown

CVE-2018-13153

Disclosure Date: July 05, 2018 (last updated November 27, 2024)
In ImageMagick 7.0.8-4, there is a memory leak in the XMagickCommand function in MagickCore/animate.c.
0
Attacker Value
Unknown

CVE-2018-0499

Disclosure Date: July 02, 2018 (last updated November 26, 2024)
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 1.4.6 exists due to incomplete HTML escaping by Xapian::MSet::snippet().
0
Attacker Value
Unknown

CVE-2018-13043

Disclosure Date: July 01, 2018 (last updated November 26, 2024)
scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing.
0
Attacker Value
Unknown

CVE-2018-10860

Disclosure Date: June 29, 2018 (last updated November 26, 2024)
perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.
0
Attacker Value
Unknown

CVE-2018-12600

Disclosure Date: June 20, 2018 (last updated November 26, 2024)
In ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow attackers to cause an out of bounds write via a crafted file.
0
Attacker Value
Unknown

CVE-2018-12599

Disclosure Date: June 20, 2018 (last updated November 26, 2024)
In ImageMagick 7.0.8-3 Q16, ReadBMPImage and WriteBMPImage in coders/bmp.c allow attackers to cause an out of bounds write via a crafted file.
0
Attacker Value
Unknown

CVE-2018-12293

Disclosure Date: June 19, 2018 (last updated November 26, 2024)
The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer overflow, which could be abused by crafted HTML content.
0
Attacker Value
Unknown

CVE-2018-1152

Disclosure Date: June 18, 2018 (last updated November 26, 2024)
libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image.
0
Attacker Value
Unknown

CVE-2018-0495

Disclosure Date: June 13, 2018 (last updated November 08, 2023)
Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
0