Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 125

Количество 26 125

msrc логотип

CVE-2024-36893

около 2 лет назад

usb: typec: tcpm: Check for port partner validity before consuming it

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2024-36891

около 2 лет назад

maple_tree: fix mas_empty_area_rev() null pointer dereference

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2024-36623

больше 1 года назад

moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2024-36621

больше 1 года назад

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-36620

больше 1 года назад

moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-3660

12 месяцев назад

Arbitrary code injection vulnerability in Keras framework < 2.13

EPSS: Низкий
msrc логотип

CVE-2024-3652

больше 2 лет назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-3651

около 2 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2024-36481

около 2 лет назад

tracing/probes: fix error check in parse_btf_field()

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2024-36479

12 месяцев назад

fpga: bridge: add owner module and take its refcount

EPSS: Низкий
msrc логотип

CVE-2024-36478

почти 2 года назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2024-36477

около 2 лет назад

tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2024-36476

больше 1 года назад

RDMA/rtrs: Ensure 'ib_sge list' is accessible

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2024-36387

больше 1 года назад

Apache HTTP Server: DoS by Null pointer in websocket over HTTP/2

CVSS3: 5.4
EPSS: Низкий
msrc логотип

CVE-2024-36357

около 1 года назад

AMD: CVE-2024-36357 Transient Scheduler Attack in L1 Data Queue

CVSS3: 5.6
EPSS: Низкий
msrc логотип

CVE-2024-36350

около 1 года назад

AMD: CVE-2024-36350 Transient Scheduler Attack in Store Queue

CVSS3: 5.6
EPSS: Низкий
msrc логотип

CVE-2024-36288

около 2 лет назад

SUNRPC: Fix loop termination condition in gss_free_in_token_pages()

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2024-36244

11 месяцев назад

net/sched: taprio: extend minimum interval restriction to entire cycle too

EPSS: Низкий
msrc логотип

CVE-2024-36138

13 дней назад

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

EPSS: Низкий
msrc логотип

CVE-2024-36137

9 месяцев назад

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2024-36893

usb: typec: tcpm: Check for port partner validity before consuming it

CVSS3: 5.5
0%
Низкий
около 2 лет назад
msrc логотип
CVE-2024-36891

maple_tree: fix mas_empty_area_rev() null pointer dereference

CVSS3: 5.5
0%
Низкий
около 2 лет назад
msrc логотип
CVE-2024-36623

moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.

CVSS3: 8.1
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-36621

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-36620

moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-3660

Arbitrary code injection vulnerability in Keras framework < 2.13

2%
Низкий
12 месяцев назад
msrc логотип
CVSS3: 6.5
1%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 7.5
1%
Низкий
около 2 лет назад
msrc логотип
CVE-2024-36481

tracing/probes: fix error check in parse_btf_field()

CVSS3: 5.5
0%
Низкий
около 2 лет назад
msrc логотип
CVE-2024-36479

fpga: bridge: add owner module and take its refcount

0%
Низкий
12 месяцев назад
msrc логотип
CVSS3: 5.5
0%
Низкий
почти 2 года назад
msrc логотип
CVE-2024-36477

tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer

CVSS3: 7.8
0%
Низкий
около 2 лет назад
msrc логотип
CVE-2024-36476

RDMA/rtrs: Ensure 'ib_sge list' is accessible

CVSS3: 5.5
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-36387

Apache HTTP Server: DoS by Null pointer in websocket over HTTP/2

CVSS3: 5.4
2%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-36357

AMD: CVE-2024-36357 Transient Scheduler Attack in L1 Data Queue

CVSS3: 5.6
0%
Низкий
около 1 года назад
msrc логотип
CVE-2024-36350

AMD: CVE-2024-36350 Transient Scheduler Attack in Store Queue

CVSS3: 5.6
0%
Низкий
около 1 года назад
msrc логотип
CVE-2024-36288

SUNRPC: Fix loop termination condition in gss_free_in_token_pages()

CVSS3: 5.5
1%
Низкий
около 2 лет назад
msrc логотип
CVE-2024-36244

net/sched: taprio: extend minimum interval restriction to entire cycle too

0%
Низкий
11 месяцев назад
msrc логотип
CVE-2024-36138

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.

1%
Низкий
13 дней назад
msrc логотип
CVE-2024-36137

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.

CVSS3: 3.3
0%
Низкий
9 месяцев назад

Уязвимостей на страницу