Show filters
197 Total Results
Displaying 51-60 of 197
Sort by:
Attacker Value
Unknown

CVE-2018-14461

Disclosure Date: October 03, 2019 (last updated November 08, 2023)
The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().
Attacker Value
Unknown

CVE-2018-16228

Disclosure Date: October 03, 2019 (last updated November 08, 2023)
The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().
Attacker Value
Unknown

CVE-2018-14882

Disclosure Date: October 03, 2019 (last updated November 08, 2023)
The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.
Attacker Value
Unknown

CVE-2018-14464

Disclosure Date: October 03, 2019 (last updated November 08, 2023)
The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().
Attacker Value
Unknown

CVE-2018-14881

Disclosure Date: October 03, 2019 (last updated November 08, 2023)
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTART).
Attacker Value
Unknown

CVE-2018-14468

Disclosure Date: October 03, 2019 (last updated November 08, 2023)
The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().
Attacker Value
Unknown

CVE-2019-11042

Disclosure Date: August 09, 2019 (last updated November 27, 2024)
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
Attacker Value
Unknown

CVE-2019-11041

Disclosure Date: August 09, 2019 (last updated November 27, 2024)
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
Attacker Value
Unknown

CVE-2017-11103

Disclosure Date: July 13, 2017 (last updated November 26, 2024)
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.
Attacker Value
Unknown

CVE-2015-2301

Disclosure Date: March 30, 2015 (last updated October 05, 2023)
Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted renaming of a Phar archive to the name of an existing file.
0