Show filters
1,191 Total Results
Displaying 471-480 of 1,191
Sort by:
Attacker Value
Unknown
CVE-2018-17360
Disclosure Date: September 23, 2018 (last updated November 27, 2024)
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allows an attacker to cause a denial of service through a crafted PE file. This vulnerability can be triggered by the executable objdump.
0
Attacker Value
Unknown
CVE-2018-17358
Disclosure Date: September 23, 2018 (last updated November 27, 2024)
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exists in _bfd_stab_section_find_nearest_line in syms.c. Attackers could leverage this vulnerability to cause a denial of service (application crash) via a crafted ELF file.
0
Attacker Value
Unknown
CVE-2018-16430
Disclosure Date: September 04, 2018 (last updated November 27, 2024)
GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.
0
Attacker Value
Unknown
CVE-2018-10845
Disclosure Date: August 22, 2018 (last updated November 27, 2024)
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.
0
Attacker Value
Unknown
CVE-2018-10844
Disclosure Date: August 22, 2018 (last updated November 27, 2024)
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data using crafted packets.
0
Attacker Value
Unknown
CVE-2018-10846
Disclosure Date: August 22, 2018 (last updated November 27, 2024)
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets.
0
Attacker Value
Unknown
CVE-2018-1000654
Disclosure Date: August 20, 2018 (last updated November 08, 2023)
GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.
0
Attacker Value
Unknown
CVE-2018-1000637
Disclosure Date: August 20, 2018 (last updated November 27, 2024)
zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary code execution. This attack appear to be exploitable via the victim openning a crafted compressed file. This vulnerability appears to have been fixed in 1.8-pre2.
0
Attacker Value
Unknown
CVE-2018-0618
Disclosure Date: July 26, 2018 (last updated November 27, 2024)
Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-7526
Disclosure Date: July 26, 2018 (last updated November 08, 2023)
libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on the hardware where the private RSA key is used.
0