Show filters
1,191 Total Results
Displaying 441-450 of 1,191
Sort by:
Attacker Value
Unknown
CVE-2018-20482
Disclosure Date: December 26, 2018 (last updated November 27, 2024)
GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c) by modifying a file that is supposed to be archived by a different user's process (e.g., a system backup running as root).
0
Attacker Value
Unknown
CVE-2018-20483
Disclosure Date: December 26, 2018 (last updated November 27, 2024)
set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.
0
Attacker Value
Unknown
CVE-2018-20431
Disclosure Date: December 24, 2018 (last updated November 27, 2024)
GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/ole2_extractor.c.
0
Attacker Value
Unknown
CVE-2018-20430
Disclosure Date: December 24, 2018 (last updated November 27, 2024)
GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in common/convert.c.
0
Attacker Value
Unknown
CVE-2018-1000858
Disclosure Date: December 20, 2018 (last updated November 27, 2024)
GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This attack appear to be exploitable via Victim must perform a WKD request, e.g. enter an email address in the composer window of Thunderbird/Enigmail. This vulnerability appears to have been fixed in after commit 4a4bb874f63741026bd26264c43bb32b1099f060.
0
Attacker Value
Unknown
CVE-2018-1000876
Disclosure Date: December 20, 2018 (last updated November 08, 2023)
binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f.
0
Attacker Value
Unknown
CVE-2018-20230
Disclosure Date: December 19, 2018 (last updated November 27, 2024)
An issue was discovered in PSPP 1.2.0. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
0
Attacker Value
Unknown
CVE-2018-20002
Disclosure Date: December 10, 2018 (last updated November 08, 2023)
The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a denial of service (memory consumption), as demonstrated by nm.
0
Attacker Value
Unknown
CVE-2018-19932
Disclosure Date: December 07, 2018 (last updated November 08, 2023)
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.
0
Attacker Value
Unknown
CVE-2018-19931
Disclosure Date: December 07, 2018 (last updated November 08, 2023)
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h because the number of program headers is not restricted.
0