VYPR

Enterprise Linux Workstation

by Red Hat

CVEs (1,846)

  • CVE-2018-12379HigOct 18, 2018
    risk 0.51cvss 7.8epss 0.00

    When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in…

  • CVE-2018-17183HigSep 19, 2018
    risk 0.51cvss 7.8epss 0.02

    Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code.

  • CVE-2018-11781HigSep 17, 2018
    risk 0.51cvss 7.8epss 0.01

    Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.

  • CVE-2018-16802HigSep 10, 2018
    risk 0.51cvss 7.8epss 0.02

    An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. This is due to…

  • CVE-2018-16540HigSep 5, 2018
    risk 0.51cvss 7.8epss 0.02

    In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.

  • CVE-2018-16511HigSep 5, 2018
    risk 0.51cvss 7.8epss 0.02

    An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact.

  • CVE-2018-15911HigAug 28, 2018
    risk 0.51cvss 7.8epss 0.03

    In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.

  • CVE-2018-15910HigAug 27, 2018
    risk 0.51cvss 7.8epss 0.03

    In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.

  • CVE-2018-15909HigAug 27, 2018
    risk 0.51cvss 7.8epss 0.03

    In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.

  • CVE-2018-15908HigAug 27, 2018
    risk 0.51cvss 7.8epss 0.02

    In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.

  • CVE-2018-10902HigAug 21, 2018
    risk 0.51cvss 7.8epss 0.01

    It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() which are part of snd_rawmidi_ioctl() handler in rawmidi.c file. A malicious local…

  • CVE-2018-14682HigJul 28, 2018
    risk 0.51cvss 8.8epss 0.04

    An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.

  • CVE-2018-14681HigJul 28, 2018
    risk 0.51cvss 8.8epss 0.04

    An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.

  • CVE-2017-15101HigJul 27, 2018
    risk 0.51cvss 7.8epss 0.02

    A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution.

  • CVE-2018-5848HigJun 12, 2018
    risk 0.51cvss 7.8epss 0.00

    In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using…

  • CVE-2018-5158HigJun 11, 2018
    risk 0.51cvss 8.8epss 0.10

    The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR <…

  • CVE-2017-7814HigJun 11, 2018
    risk 0.51cvss 7.8epss 0.01

    File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables…

  • CVE-2018-11237HigMay 18, 2018
    risk 0.51cvss 7.8epss 0.01

    An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupper.

  • CVE-2018-8781HigApr 23, 2018
    risk 0.51cvss 7.8epss 0.01

    The udl_fb_mmap function in drivers/gpu/drm/udl/udl_fb.c at the Linux kernel version 3.4 and up to and including 4.15 has an integer-overflow vulnerability allowing local users with access to the udldrmfb driver to obtain full read and write permissions on kernel physical pages,…

  • CVE-2018-10194HigApr 18, 2018
    risk 0.51cvss 7.8epss 0.02

    The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause a denial of service (application crash) or possibly have…

Page 32 of 93