Vulnerabilities > Canonical > Ubuntu Linux > 17.10

DATE CVE VULNERABILITY TITLE RISK
2018-12-07 CVE-2017-16910 Out-of-bounds Read vulnerability in multiple products
An error within the "LibRaw::xtrans_interpolate()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause an invalid read memory access and subsequently a Denial of Service condition.
network
low complexity
libraw canonical CWE-125
6.5
2018-12-07 CVE-2017-16909 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
An error related to the "LibRaw::panasonic_load_raw()" function (dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash via a specially crafted TIFF image.
network
low complexity
libraw canonical CWE-119
8.8
2018-10-18 CVE-2018-5188 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8.
network
low complexity
debian canonical mozilla redhat CWE-119
critical
9.8
2018-10-18 CVE-2018-5187 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Memory safety bugs present in Firefox 60 and Firefox ESR 60.
network
low complexity
debian canonical mozilla CWE-119
critical
9.8
2018-10-18 CVE-2018-5186 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Memory safety bugs present in Firefox 60.
network
low complexity
mozilla canonical CWE-119
critical
9.8
2018-10-18 CVE-2018-5156 Improper Input Validation vulnerability in multiple products
A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring.
network
low complexity
redhat debian canonical mozilla CWE-20
critical
9.8
2018-10-18 CVE-2018-12374 Information Exposure vulnerability in multiple products
Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field.
network
low complexity
mozilla redhat debian canonical CWE-200
4.3
2018-10-18 CVE-2018-12373 Information Exposure vulnerability in multiple products
dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward.
network
low complexity
mozilla redhat debian canonical CWE-200
6.5
2018-10-18 CVE-2018-12372 Information Exposure vulnerability in multiple products
Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward.
network
low complexity
mozilla redhat debian canonical CWE-200
6.5
2018-10-18 CVE-2018-12370 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
In Reader View SameSite cookie protections are not checked on exiting.
network
low complexity
canonical mozilla CWE-352
8.8