Latest CVE Feed
-
5.5
MEDIUMCVE-2018-7755
An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel through 4.15.7. The floppy driver will copy a kernel pointer to user memory in response to the FDGETPRM ioctl. An attacker can send the FDGETPRM ioctl an... Read more
- Published: Mar. 08, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-7754
The aoedisk_debugfs_show function in drivers/block/aoe/aoeblk.c in the Linux kernel through 4.16.4rc4 allows local users to obtain sensitive address information by reading "ffree: " lines in a debugfs file.... Read more
Affected Products : linux_kernel- Published: Aug. 10, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-7191
In the tun subsystem in the Linux kernel before 4.13.14, dev_get_valid_name is not called before register_netdevice. This allows local users to cause a denial of service (NULL pointer dereference and panic) via an ioctl(TUNSETIFF) call with a dev name con... Read more
Affected Products : linux_kernel- Published: May. 17, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-19568
A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code.... Read more
Affected Products : dcraw- Published: Nov. 26, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-19213
Netwide Assembler (NASM) through 2.14rc16 has memory leaks that may lead to DoS, related to nasm_malloc in nasmlib/malloc.c.... Read more
Affected Products : netwide_assembler- Published: Nov. 12, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-18607
An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in elf_link_input_bfd when used for finding STT_TLS symbols witho... Read more
- Published: Oct. 23, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-18384
Info-ZIP UnZip 6.0 has a buffer overflow in list.c, when a ZIP archive has a crafted relationship between the compressed-size value and the uncompressed-size value, because a buffer size is 10 and is supposed to be 12.... Read more
- Published: Oct. 16, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-18309
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory address dereference was discovered in read_reloc in reloc.c. The vulnerability causes a segmentation fault and applica... Read more
Affected Products : binutils- Published: Oct. 15, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-17358
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exists in _bfd_stab_section_find_nearest_line in syms.c. Attackers could leverage this vulnerability to cause a... Read more
Affected Products : binutils- Published: Sep. 23, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-16885
A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buffer length which causes the read beyond the buffer boundaries, in certain cases causing a memory access fault and ... Read more
- Published: Jan. 03, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-13099
An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A denial of service (out-of-bounds memory access and BUG) can occur for a modified f2fs filesystem image in which an inline inode contains an invalid reserved blkaddr.... Read more
- Published: Jul. 03, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-13097
An issue was discovered in fs/f2fs/super.c in the Linux kernel through 4.17.3. There is an out-of-bounds read or a divide-by-zero error for an incorrect user_block_count in a corrupted f2fs image, leading to a denial of service (BUG).... Read more
Affected Products : linux_kernel- Published: Jul. 03, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-15145
DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2Dict::JB2Codec::get_direct_context in libdjvu/JB2Image.h because of a missi... Read more
- Published: Aug. 18, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1000079
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation... Read more
- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-9039
GNU Binutils 2.28 allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file with many program headers, related to the get_program_headers function in readelf.c.... Read more
Affected Products : binutils- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8908
The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.... Read more
Affected Products : ghostscript- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7982
Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.... Read more
Affected Products : libplist- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7741
In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585... Read more
Affected Products : libsndfile- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2023-51384
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS... Read more
- Published: Dec. 18, 2023
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-7346
The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.7 does not validate certain levels data, which allows local users to cause a denial of service (system hang) via a crafted ioctl call for ... Read more
Affected Products : linux_kernel- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025