Логотип exploitDog
source:"msrc"
Консоль
Логотип exploitDog

exploitDog

source:"msrc"

Количество 18 769

Количество 18 769

msrc логотип

CVE-2020-4040

4 месяца назад

CSRF issue on preview pages in Bolt CMS

CVSS3: 8.6
EPSS: Низкий
msrc логотип

CVE-2020-36478

5 месяцев назад

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.

EPSS: Низкий
msrc логотип

CVE-2020-36477

5 месяцев назад

An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certificate name is mishandled: when the subjecAltName extension is present, the expected name is compared to any name in that extension regardless of its type. This means that an attacker could impersonate a 4-byte or 16-byte domain by getting a certificate for the corresponding IPv4 or IPv6 address (this would require the attacker to control that IP address, though).

EPSS: Низкий
msrc логотип

CVE-2020-36476

5 месяцев назад

An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.

EPSS: Низкий
msrc логотип

CVE-2020-36475

5 месяцев назад

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs.

EPSS: Низкий
msrc логотип

CVE-2020-36426

5 месяцев назад

An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte).

EPSS: Низкий
msrc логотип

CVE-2020-36425

5 месяцев назад

An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.

EPSS: Низкий
msrc логотип

CVE-2020-36424

5 месяцев назад

An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.

EPSS: Низкий
msrc логотип

CVE-2020-36422

5 месяцев назад

An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbedtls_ecp_mul_restartable.

EPSS: Низкий
msrc логотип

CVE-2020-36332

больше 4 лет назад

A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-36331

больше 4 лет назад

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2020-36330

больше 4 лет назад

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2020-36329

больше 4 лет назад

A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2020-36328

больше 4 лет назад

A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2020-36325

около 4 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-36323

почти 5 лет назад

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2020-36318

почти 5 лет назад

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2020-36317

почти 5 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-36242

почти 5 лет назад

In the cryptography package before 3.3.2 for Python certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow as demonstrated by the Fernet class.

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2020-36230

около 5 лет назад

A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element resulting in denial of service.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2020-4040

CSRF issue on preview pages in Bolt CMS

CVSS3: 8.6
1%
Низкий
4 месяца назад
msrc логотип
CVE-2020-36478

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.

1%
Низкий
5 месяцев назад
msrc логотип
CVE-2020-36477

An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certificate name is mishandled: when the subjecAltName extension is present, the expected name is compared to any name in that extension regardless of its type. This means that an attacker could impersonate a 4-byte or 16-byte domain by getting a certificate for the corresponding IPv4 or IPv6 address (this would require the attacker to control that IP address, though).

0%
Низкий
5 месяцев назад
msrc логотип
CVE-2020-36476

An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.

1%
Низкий
5 месяцев назад
msrc логотип
CVE-2020-36475

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs.

1%
Низкий
5 месяцев назад
msrc логотип
CVE-2020-36426

An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte).

1%
Низкий
5 месяцев назад
msrc логотип
CVE-2020-36425

An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.

1%
Низкий
5 месяцев назад
msrc логотип
CVE-2020-36424

An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.

0%
Низкий
5 месяцев назад
msrc логотип
CVE-2020-36422

An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbedtls_ecp_mul_restartable.

1%
Низкий
5 месяцев назад
msrc логотип
CVE-2020-36332

A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2020-36331

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.

CVSS3: 9.1
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2020-36330

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.

CVSS3: 9.1
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2020-36329

A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2020-36328

A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
около 4 лет назад
msrc логотип
CVSS3: 8.2
1%
Низкий
почти 5 лет назад
msrc логотип
CVSS3: 9.8
0%
Низкий
почти 5 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2020-36242

In the cryptography package before 3.3.2 for Python certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow as demonstrated by the Fernet class.

CVSS3: 9.1
1%
Низкий
почти 5 лет назад
msrc логотип
CVE-2020-36230

A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element resulting in denial of service.

CVSS3: 7.5
2%
Низкий
около 5 лет назад

Уязвимостей на страницу