An elevation of privilege vulnerability exists when Microsoft Outlook does not validate attachment headers properly, aka “Microsoft Outlook Elevation of Privilege Vulnerability.” This affects Microsoft Office, Microsoft Outlook.
CWE-20
CVE-2018-8176
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka “Microsoft PowerPoint Remote Code Execution Vulnerability.” This affects Microsoft Office.
CVE-2018-8115
A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while importing a container image, aka “Windows Host Compute Service Shim Remote Code Execution Vulnerability.” This affects Windows Host Compute.
CVE-2018-8065
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access violation on the syncbrs.exe memory region that can be triggered by rapidly sending a variety of HTTP requests with long HTTP header values or long URIs.
CVE-2018-8030
A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than allowed maximum message size limit (100MB by default). The broker crashes due to the defect. AMQP protocols 0-10 and 1.0 are not affected.
CVE-2018-8038
Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.