Логотип exploitDog
source:"msrc"
Консоль
Логотип exploitDog

exploitDog

source:"msrc"

Количество 18 769

Количество 18 769

msrc логотип

CVE-2020-29396

около 5 лет назад

A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0 when running with Python 3.6 or later allows remote authenticated users to execute arbitrary code leading to privilege escalation.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2020-29374

около 5 лет назад

An issue was discovered in the Linux kernel before 5.7.3 related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation when used for a copy-on-write page does not properly consider the semantics of read operations and therefore can grant unintended write access aka CID-17839856fd58.

CVSS3: 3.6
EPSS: Низкий
msrc логотип

CVE-2020-29373

около 5 лет назад

An issue was discovered in fs/io_uring.c in the Linux kernel before 5.6. It unsafely handles the root directory during path lookups and thus a process inside a mount namespace can escape to unintended filesystem locations aka CID-ff002b30181d.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2020-29372

около 5 лет назад

An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation aka CID-bc0c4d1e176e.

CVSS3: 4.7
EPSS: Низкий
msrc логотип

CVE-2020-29371

около 5 лет назад

An issue was discovered in romfs_dev_read in fs/romfs/storage.c in the Linux kernel before 5.8.4. Uninitialized memory leaks to userspace aka CID-bcf85fcedfdd.

CVSS3: 3.3
EPSS: Низкий
msrc логотип

CVE-2020-29370

около 5 лет назад

An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment aka CID-fd4d9c7d0c71.

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2020-29369

около 5 лет назад

An issue was discovered in mm/mmap.c in the Linux kernel before 5.7.11. There is a race condition between certain expand functions (expand_downwards and expand_upwards) and page-table free operations from an munmap call aka CID-246c320a8cfe.

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2020-29368

около 5 лет назад

An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check aka CID-c444eb564fb1.

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2020-29363

около 5 лет назад

An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE the receiving entity may not allocate sufficient length for the buffer to store the deserialized value.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-29362

около 5 лет назад

An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2020-29361

около 5 лет назад

An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command where overflow checks are missing before calling realloc or calloc.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-28974

около 5 лет назад

A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 could be used by local attackers to read privileged information or potentially crash the kernel aka CID-3c4e0dff2095. This occurs because KD_FONT_OP_COPY in drivers/tty/vt/vt.c can be used for manipulations such as font height.

CVSS3: 5
EPSS: Низкий
msrc логотип

CVE-2020-28941

около 5 лет назад

An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack aka CID-d41227544427. This occurs because of an invalid free when the line discipline is used more than once.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-28935

около 5 лет назад

Local symlink attack in Unbound and NSD

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-28925

4 месяца назад

Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Your PHP for Better Security" guidance.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2020-28915

около 5 лет назад

A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local attackers to read kernel memory aka CID-6735b4632def.

CVSS3: 5.8
EPSS: Низкий
msrc логотип

CVE-2020-28852

больше 1 года назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-28851

больше 1 года назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-28493

больше 3 лет назад

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2020-28458

около 1 года назад

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2020-29396

A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0 when running with Python 3.6 or later allows remote authenticated users to execute arbitrary code leading to privilege escalation.

CVSS3: 8.8
4%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-29374

An issue was discovered in the Linux kernel before 5.7.3 related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation when used for a copy-on-write page does not properly consider the semantics of read operations and therefore can grant unintended write access aka CID-17839856fd58.

CVSS3: 3.6
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-29373

An issue was discovered in fs/io_uring.c in the Linux kernel before 5.6. It unsafely handles the root directory during path lookups and thus a process inside a mount namespace can escape to unintended filesystem locations aka CID-ff002b30181d.

CVSS3: 6.5
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-29372

An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation aka CID-bc0c4d1e176e.

CVSS3: 4.7
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-29371

An issue was discovered in romfs_dev_read in fs/romfs/storage.c in the Linux kernel before 5.8.4. Uninitialized memory leaks to userspace aka CID-bcf85fcedfdd.

CVSS3: 3.3
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-29370

An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment aka CID-fd4d9c7d0c71.

CVSS3: 7
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-29369

An issue was discovered in mm/mmap.c in the Linux kernel before 5.7.11. There is a race condition between certain expand functions (expand_downwards and expand_upwards) and page-table free operations from an munmap call aka CID-246c320a8cfe.

CVSS3: 7
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-29368

An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check aka CID-c444eb564fb1.

CVSS3: 7
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-29363

An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE the receiving entity may not allocate sufficient length for the buffer to store the deserialized value.

CVSS3: 7.5
1%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-29362

An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation.

CVSS3: 5.3
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-29361

An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command where overflow checks are missing before calling realloc or calloc.

CVSS3: 7.5
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-28974

A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 could be used by local attackers to read privileged information or potentially crash the kernel aka CID-3c4e0dff2095. This occurs because KD_FONT_OP_COPY in drivers/tty/vt/vt.c can be used for manipulations such as font height.

CVSS3: 5
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-28941

An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack aka CID-d41227544427. This occurs because of an invalid free when the line discipline is used more than once.

CVSS3: 5.5
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-28935

Local symlink attack in Unbound and NSD

CVSS3: 5.5
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-28925

Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Your PHP for Better Security" guidance.

CVSS3: 5.3
0%
Низкий
4 месяца назад
msrc логотип
CVE-2020-28915

A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local attackers to read kernel memory aka CID-6735b4632def.

CVSS3: 5.8
0%
Низкий
около 5 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 7.5
0%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 5.3
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 7.3
1%
Низкий
около 1 года назад

Уязвимостей на страницу