The readBytes function in util/read.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file that triggers a memory allocation failure.
The parseSWFACTIONRECORD function in util/parser.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a crafted swf file that triggers a memory allocation failure, a different vulnerability than CVE-2018-7876.
A flaw was found in ntfsendbufferasyncread in the ntfs.ko filesystem driver in the Linux kernel. This allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service or possibly have unspecified other impact via a crafted ntfs filesystem. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
References:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1763403
https://marc.info/?l=linux-ntfs-dev&m=152413769810234&w=2
https://marc.info/?t=152407734400002&r=1&w=2 (a whole thread)
A flaw was found in ntfsreadlockedinode in the ntfs.ko filesystem driver in the Linux kernel. This allows attackers to trigger a use-after-free read and possibly cause a denial of service via a crafted ntfs filesystem.
A flaw was found in ntfsattrfind in the ntfs.ko filesystem driver in the Linux kernel. This allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service or possibly have unspecified other impact via a crafted ntfs filesystem image. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
References:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1763403 https://marc.info/?l=linux-ntfs-dev&m=152413769810234&w=2
https://marc.info/?t=152407734400002&r=1&w=2 (a whole thread)
In the Linux kernel 4.15.0, a NULL pointer dereference was discovered in hfsextreadextent in hfs.ko. This can occur during a mount of a crafted hfs filesystem.