Total
11483 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-18756 | 1 Kangujang | 1 Local Server | 2018-12-31 | 5.0 MEDIUM | 7.5 HIGH |
Local Server 1.0.9 has a Buffer Overflow via crafted data on Port 4008. | |||||
CVE-2014-0779 | 1 Aveva | 1 Clearscada | 2018-12-31 | 6.8 MEDIUM | N/A |
The PLC driver in ServerMain.exe in the Kepware KepServerEX 4 component in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R2 build 71.4165, 2010 R2.1 build 71.4325, 2010 R3 build 72.4560, 2010 R3.1 build 72.4644, 2013 R1 build 73.4729, 2013 R1.1 build 73.4832, 2013 R1.1a build 73.4903, 2013 R1.2 build 73.4955, and 2013 R2 build 74.5094 allows remote attackers to cause a denial of service (application crash) via a crafted OPF file (aka project file). | |||||
CVE-2017-9962 | 1 Aveva | 1 Clearscada | 2018-12-31 | 5.0 MEDIUM | 7.5 HIGH |
Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed requests can be sent to ClearSCADA client applications to cause unexpected behavior. Client applications affected include ViewX and the Server Icon. | |||||
CVE-2018-20331 | 1 Antiy | 1 Anti Virus Lab Atool | 2018-12-31 | 7.2 HIGH | 7.8 HIGH |
Local attackers can trigger a Kernel Pool Buffer Overflow in Antiy AVL ATool v1.0.0.22. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x80002004 by the ssdt.sys kernel driver. The bug is caused by failure to properly validate the length of the user-supplied data. An attacker can leverage this vulnerability to execute arbitrary code in the context of the kernel, which could lead to privilege escalation. A failed exploit could lead to denial of service. | |||||
CVE-2018-7114 | 1 Hp | 1 Intelligent Management Center | 2018-12-29 | 10.0 HIGH | 9.8 CRITICAL |
HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to remote buffer overflow in dbman leading to code execution. This problem is resolved in IMC PLAT 7.3 (E0605P06) or subsequent versions. | |||||
CVE-2018-7115 | 2 Hp, Microsoft | 2 Intelligent Management Center, Windows | 2018-12-29 | 5.0 MEDIUM | 5.3 MEDIUM |
HPE Intelligent Management Center (IMC) prior to IMC PLAT 7.3 (E0605P06) is vulnerable to a remote buffer overflow in dbman.exe opcode 10001 on Windows. This problem is resolved in IMC PLAT 7.3 (E0605P06) or subsequent versions. | |||||
CVE-2018-19278 | 1 Digium | 1 Asterisk | 2018-12-29 | 5.0 MEDIUM | 7.5 HIGH |
Buffer overflow in DNS SRV and NAPTR lookups in Digium Asterisk 15.x before 15.6.2 and 16.x before 16.0.1 allows remote attackers to crash Asterisk via a specially crafted DNS SRV or NAPTR response, because a buffer size is supposed to match an expanded length but actually matches a compressed length. | |||||
CVE-2017-16909 | 2 Canonical, Libraw | 2 Ubuntu Linux, Libraw | 2018-12-28 | 6.8 MEDIUM | 8.8 HIGH |
An error related to the "LibRaw::panasonic_load_raw()" function (dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash via a specially crafted TIFF image. | |||||
CVE-2016-10349 | 1 Libarchive | 1 Libarchive | 2018-12-28 | 4.3 MEDIUM | 5.5 MEDIUM |
The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. | |||||
CVE-2016-10350 | 1 Libarchive | 1 Libarchive | 2018-12-28 | 4.3 MEDIUM | 5.5 MEDIUM |
The archive_read_format_cab_read_header function in archive_read_support_format_cab.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. | |||||
CVE-2018-19887 | 1 Audiocoding | 1 Freeware Advanced Audio Coder | 2018-12-28 | 4.3 MEDIUM | 5.5 MEDIUM |
An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the book 4 case. | |||||
CVE-2018-19888 | 1 Audiocoding | 1 Freeware Advanced Audio Coder | 2018-12-28 | 4.3 MEDIUM | 5.5 MEDIUM |
An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the HCB_ESC case. | |||||
CVE-2018-19889 | 1 Audiocoding | 1 Freeware Advanced Audio Coder | 2018-12-28 | 4.3 MEDIUM | 5.5 MEDIUM |
An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the book 6 case. | |||||
CVE-2018-19890 | 1 Audiocoding | 1 Freeware Advanced Audio Coder | 2018-12-28 | 4.3 MEDIUM | 5.5 MEDIUM |
An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the book 2 case. | |||||
CVE-2018-19891 | 1 Audiocoding | 1 Freeware Advanced Audio Coder | 2018-12-28 | 4.3 MEDIUM | 5.5 MEDIUM |
An invalid memory address dereference was discovered in the huffcode function (libfaac/huff2.c) in Freeware Advanced Audio Coder (FAAC) 1.29.9.2. The vulnerability causes a segmentation fault and application crash, which leads to denial of service in the book 10 case. | |||||
CVE-2018-14749 | 1 Qnap | 1 Qts | 2018-12-27 | 7.5 HIGH | 9.8 CRITICAL |
Buffer Overflow vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could have unspecified impact on the NAS. | |||||
CVE-2018-18983 | 1 Invt | 1 Vt-designer | 2018-12-27 | 6.8 MEDIUM | 8.8 HIGH |
VT-Designer Version 2.1.7.31 is vulnerable by the program reading the contents of a file (which is already in memory) into another heap-based buffer, which may cause the program to crash or allow remote code execution. | |||||
CVE-2018-16713 | 1 Iobit | 1 Advanced Systemcare | 2018-12-27 | 6.8 MEDIUM | 6.5 MEDIUM |
IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402084) with a buffer containing user defined content. The driver's subroutine will execute a rdmsr instruction with the user's buffer for input, and provide output from the instruction. | |||||
CVE-2018-5870 | 1 Qualcomm | 6 Sd 835, Sd 835 Firmware, Sda660 and 3 more | 2018-12-26 | 7.2 HIGH | 7.8 HIGH |
While loading a service image, an untrusted pointer dereference can occur in Snapdragon Mobile in versions SD 835, SDA660, SDX24. | |||||
CVE-2018-5877 | 1 Qualcomm | 32 Mdm9206, Mdm9206 Firmware, Mdm9607 and 29 more | 2018-12-26 | 7.2 HIGH | 7.8 HIGH |
In the device programmer target-side code for firehose, a string may not be properly NULL terminated can lead to a incorrect buffer size in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9640, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 600, SD 820, SD 820A, SD 835, SDA660, SDX20. |