Vulnerabilities > Debian > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-12-28 CVE-2018-20570 Out-of-bounds Read vulnerability in multiple products
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
network
low complexity
jasper-project debian CWE-125
6.5
2018-12-28 CVE-2018-20544 Divide By Zero vulnerability in multiple products
There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19.
network
low complexity
libcaca-project debian canonical CWE-369
6.5
2018-12-27 CVE-2018-20511 Information Exposure vulnerability in multiple products
An issue was discovered in the Linux kernel before 4.18.11.
local
low complexity
linux debian CWE-200
5.5
2018-12-26 CVE-2018-20217 Reachable Assertion vulnerability in multiple products
A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17.
network
high complexity
mit debian CWE-617
5.3
2018-12-26 CVE-2018-20482 Infinite Loop vulnerability in multiple products
GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c) by modifying a file that is supposed to be archived by a different user's process (e.g., a system backup running as root).
local
high complexity
gnu debian opensuse CWE-835
4.7
2018-12-26 CVE-2018-20481 NULL Pointer Dereference vulnerability in multiple products
XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PDF document, when XRefEntry::setFlag in XRef.h is called from Parser::makeStream in Parser.cc.
network
low complexity
freedesktop canonical debian CWE-476
6.5
2018-12-26 CVE-2018-20467 Infinite Loop vulnerability in multiple products
In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption.
network
low complexity
imagemagick opensuse debian canonical CWE-835
6.5
2018-12-24 CVE-2018-20431 NULL Pointer Dereference vulnerability in multiple products
GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/ole2_extractor.c.
network
low complexity
gnu debian CWE-476
6.5
2018-12-24 CVE-2018-20430 Out-of-bounds Read vulnerability in multiple products
GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in common/convert.c.
network
low complexity
gnu debian CWE-125
6.5
2018-12-22 CVE-2018-20360 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8.
local
low complexity
audiocoding debian CWE-119
5.5