Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

oracle-oval логотип

ELSA-2026-50251

3 месяца назад

ELSA-2026-50251: dtrace security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-50250

3 месяца назад

ELSA-2026-50250: dtrace security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-50249

3 месяца назад

ELSA-2026-50249: dtrace security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2026-35233

3 месяца назад

An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches to -- or instruments -- that process (via dtrace -p , pid probes, or USDT), the ELF parser reads heap memory beyond the allocated section cache array without any bounds check. This results in an uninitialized/out-of-bounds heap read that can cause a NULL pointer dereference crash of the dtrace process (DoS), or -- depending on heap layout -- a read-then-use of a garbage pointer controlled by adjacent allocations, providing a foothold toward further exploitation in a privileged context.

CVSS3: 4.4
EPSS: Низкий
nvd логотип

CVE-2026-35233

3 месяца назад

An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches to -- or instruments -- that process (via dtrace -p , pid probes, or USDT), the ELF parser reads heap memory beyond the allocated section cache array without any bounds check. This results in an uninitialized/out-of-bounds heap read that can cause a NULL pointer dereference crash of the dtrace process (DoS), or -- depending on heap layout -- a read-then-use of a garbage pointer controlled by adjacent allocations, providing a foothold toward further exploitation in a privileged context.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2026-35233

3 месяца назад

An unprivileged attacker can craft a user-space process with a malicio ...

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2026-21996

3 месяца назад

An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an integer Divide-by-Zero in Pbuild_file_symtab()

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2026-21996

3 месяца назад

An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an integer Divide-by-Zero in Pbuild_file_symtab()

CVSS3: 3.3
EPSS: Низкий
debian логотип

CVE-2026-21996

3 месяца назад

An unprivileged attacker can reliably trigger a crash of the dtrace pr ...

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-w2v2-5qjc-q2jw

3 месяца назад

An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an integer Divide-by-Zero in Pbuild_file_symtab()

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-cjc5-j2ff-wq2w

3 месяца назад

An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches to -- or instruments -- that process (via dtrace -p , pid probes, or USDT), the ELF parser reads heap memory beyond the allocated section cache array without any bounds check. This results in an uninitialized/out-of-bounds heap read that can cause a NULL pointer dereference crash of the dtrace process (DoS), or -- depending on heap layout -- a read-then-use of a garbage pointer controlled by adjacent allocations, providing a foothold toward further exploitation in a privileged context.

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2026-50251

ELSA-2026-50251: dtrace security update (MODERATE)

3 месяца назад
oracle-oval логотип
ELSA-2026-50250

ELSA-2026-50250: dtrace security update (MODERATE)

3 месяца назад
oracle-oval логотип
ELSA-2026-50249

ELSA-2026-50249: dtrace security update (MODERATE)

3 месяца назад
ubuntu логотип
CVE-2026-35233

An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches to -- or instruments -- that process (via dtrace -p , pid probes, or USDT), the ELF parser reads heap memory beyond the allocated section cache array without any bounds check. This results in an uninitialized/out-of-bounds heap read that can cause a NULL pointer dereference crash of the dtrace process (DoS), or -- depending on heap layout -- a read-then-use of a garbage pointer controlled by adjacent allocations, providing a foothold toward further exploitation in a privileged context.

CVSS3: 4.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-35233

An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches to -- or instruments -- that process (via dtrace -p , pid probes, or USDT), the ELF parser reads heap memory beyond the allocated section cache array without any bounds check. This results in an uninitialized/out-of-bounds heap read that can cause a NULL pointer dereference crash of the dtrace process (DoS), or -- depending on heap layout -- a read-then-use of a garbage pointer controlled by adjacent allocations, providing a foothold toward further exploitation in a privileged context.

CVSS3: 4.4
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-35233

An unprivileged attacker can craft a user-space process with a malicio ...

CVSS3: 4.4
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-21996

An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an integer Divide-by-Zero in Pbuild_file_symtab()

CVSS3: 3.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-21996

An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an integer Divide-by-Zero in Pbuild_file_symtab()

CVSS3: 3.3
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-21996

An unprivileged attacker can reliably trigger a crash of the dtrace pr ...

CVSS3: 3.3
0%
Низкий
3 месяца назад
github логотип
GHSA-w2v2-5qjc-q2jw

An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an integer Divide-by-Zero in Pbuild_file_symtab()

CVSS3: 3.3
0%
Низкий
3 месяца назад
github логотип
GHSA-cjc5-j2ff-wq2w

An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link field. When root-level dtrace attaches to -- or instruments -- that process (via dtrace -p , pid probes, or USDT), the ELF parser reads heap memory beyond the allocated section cache array without any bounds check. This results in an uninitialized/out-of-bounds heap read that can cause a NULL pointer dereference crash of the dtrace process (DoS), or -- depending on heap layout -- a read-then-use of a garbage pointer controlled by adjacent allocations, providing a foothold toward further exploitation in a privileged context.

CVSS3: 4.4
0%
Низкий
3 месяца назад

Уязвимостей на страницу