Skip to content
Commits on Source (2)
......@@ -61,9 +61,11 @@ CVE-2018-9137
CVE-2018-9136 (windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers ...)
NOT-FOR-US: Jungo
CVE-2018-9135 (In ImageMagick 7.0.7-24 Q16, there is a heap-based buffer over-read in ...)
TODO: check
- imagemagick <unfixed> (unimportant)
NOTE: https://github.com/ImageMagick/ImageMagick/commit/4f7196b0b7539b113f2580b6a77aa496813d8899
NOTE: webp support not enabled, see #806425
CVE-2018-9134 (file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename ...)
TODO: check
NOT-FOR-US: DedeCMS
CVE-2018-9133 (ImageMagick 7.0.7-26 Q16 has excessive iteration in the DecodeLabImage ...)
TODO: check
CVE-2018-9132 (libming 0.4.8 has a NULL pointer dereference in the getInt function of ...)
......@@ -13965,7 +13967,7 @@ CVE-2018-3819 (The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack sec
CVE-2018-3818 (Kibana versions 5.1.1 to 6.1.2 and 5.6.6 had a cross-site scripting ...)
- kibana <itp> (bug #700337)
CVE-2018-3817 (When logging warnings regarding deprecated settings, Logstash before ...)
TODO: check
- logstash <itp> (bug #664841)
CVE-2017-18017 (The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the ...)
- linux 4.11.6-1
[stretch] - linux 4.9.47-1