Show filters
112 Total Results
Displaying 81-90 of 112
Sort by:
Attacker Value
Unknown
CVE-2018-20060
Disclosure Date: December 11, 2018 (last updated November 08, 2023)
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
0
Attacker Value
Unknown
CVE-2018-20005
Disclosure Date: December 10, 2018 (last updated November 08, 2023)
An issue has been found in Mini-XML (aka mxml) 2.12. It is a use-after-free in mxmlWalkNext in mxml-search.c, as demonstrated by mxmldoc.
0
Attacker Value
Unknown
CVE-2018-20004
Disclosure Date: December 10, 2018 (last updated November 08, 2023)
An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a double-precision floating point number and the '<order type="real">' substring, as demonstrated by testmxml.
0
Attacker Value
Unknown
CVE-2018-19591
Disclosure Date: December 04, 2018 (last updated November 08, 2023)
In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.
0
Attacker Value
Unknown
CVE-2018-19841
Disclosure Date: December 04, 2018 (last updated November 08, 2023)
The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application crash) via a crafted WavPack Lossless Audio file, as demonstrated by wvunpack.
0
Attacker Value
Unknown
CVE-2018-19840
Disclosure Date: December 04, 2018 (last updated November 08, 2023)
The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because WavpackSetConfiguration64 mishandles a sample rate of zero.
0
Attacker Value
Unknown
CVE-2018-8786
Disclosure Date: November 29, 2018 (last updated November 08, 2023)
FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corruption and probably even a remote code execution.
0
Attacker Value
Unknown
CVE-2018-18408
Disclosure Date: October 17, 2018 (last updated November 08, 2023)
A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets triggered in the function post_args() at tcpbridge.c, causing a denial of service or possibly unspecified other impact.
0
Attacker Value
Unknown
CVE-2018-18407
Disclosure Date: October 17, 2018 (last updated November 08, 2023)
A heap-based buffer over-read was discovered in the tcpreplay-edit binary of Tcpreplay 4.3.0 beta1, during the incremental checksum operation. The issue gets triggered in the function csum_replace4() in incremental_checksum.h, causing a denial of service.
0
Attacker Value
Unknown
CVE-2018-18409
Disclosure Date: October 17, 2018 (last updated November 08, 2023)
A stack-based buffer over-read exists in setbit() at iptree.h of TCPFLOW 1.5.0, due to received incorrect values causing incorrect computation, leading to denial of service during an address_histogram call or a get_histogram call.
0