Show filters
1,191 Total Results
Displaying 471-480 of 1,191
Sort by:
Attacker Value
Unknown

CVE-2018-17360

Disclosure Date: September 23, 2018 (last updated November 27, 2024)
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allows an attacker to cause a denial of service through a crafted PE file. This vulnerability can be triggered by the executable objdump.
0
Attacker Value
Unknown

CVE-2018-17358

Disclosure Date: September 23, 2018 (last updated November 27, 2024)
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exists in _bfd_stab_section_find_nearest_line in syms.c. Attackers could leverage this vulnerability to cause a denial of service (application crash) via a crafted ELF file.
0
Attacker Value
Unknown

CVE-2018-16430

Disclosure Date: September 04, 2018 (last updated November 27, 2024)
GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.
0
Attacker Value
Unknown

CVE-2018-10845

Disclosure Date: August 22, 2018 (last updated November 27, 2024)
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plain text recovery attacks via statistical analysis of timing data using crafted packets.
Attacker Value
Unknown

CVE-2018-10844

Disclosure Date: August 22, 2018 (last updated November 27, 2024)
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack. Remote attackers could use this flaw to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data using crafted packets.
Attacker Value
Unknown

CVE-2018-10846

Disclosure Date: August 22, 2018 (last updated November 27, 2024)
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found. An attacker could use a combination of "Just in Time" Prime+probe attack in combination with Lucky-13 attack to recover plain text using crafted packets.
Attacker Value
Unknown

CVE-2018-1000654

Disclosure Date: August 20, 2018 (last updated November 08, 2023)
GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.
0
Attacker Value
Unknown

CVE-2018-1000637

Disclosure Date: August 20, 2018 (last updated November 27, 2024)
zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary code execution. This attack appear to be exploitable via the victim openning a crafted compressed file. This vulnerability appears to have been fixed in 1.8-pre2.
0
Attacker Value
Unknown

CVE-2018-0618

Disclosure Date: July 26, 2018 (last updated November 27, 2024)
Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2017-7526

Disclosure Date: July 26, 2018 (last updated November 08, 2023)
libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion. The same attack is believed to work on RSA-2048 with moderately more computation. This side-channel requires that attacker can run arbitrary software on the hardware where the private RSA key is used.
0