Логотип exploitDog
source:"msrc"
Консоль
Логотип exploitDog

exploitDog

source:"msrc"

Количество 18 769

Количество 18 769

msrc логотип

CVE-2020-26558

почти 4 года назад

CVSS3: 4.2
EPSS: Низкий
msrc логотип

CVE-2020-26541

больше 5 лет назад

The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protection mechanism. This affects certs/blacklist.c and certs/system_keyring.c.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2020-26160

больше 1 года назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-26159

4 месяца назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Further investigation showed that it was not a security issue. Notes: none

EPSS: Низкий
msrc логотип

CVE-2020-26154

около 4 лет назад

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2020-26144

больше 4 лет назад

Windows Wireless Networking Spoofing Vulnerability

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2020-26137

около 5 лет назад

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2020-26116

больше 5 лет назад

http.client in Python 3.x before 3.5.10 3.6.x before 3.6.12 3.7.x before 3.7.9 and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.

CVSS3: 7.2
EPSS: Низкий
msrc логотип

CVE-2020-26088

больше 5 лет назад

A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets bypassing security mechanisms aka CID-26896f01467a.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-25796

больше 5 лет назад

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the InlineArray implementation an unaligned reference may be generated for a type that has a large alignment requirement.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-25795

больше 5 лет назад

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation insert_from can have a memory-safety issue upon a panic.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-25794

больше 5 лет назад

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation clone can have a memory-safety issue upon a panic.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-25793

больше 5 лет назад

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation the array size is not checked when constructed with From<InlineArray<A T>>.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-25792

больше 5 лет назад

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation the array size is not checked when constructed with pair().

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-25791

больше 5 лет назад

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation the array size is not checked when constructed with unit().

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-25743

больше 5 лет назад

hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.

CVSS3: 3.2
EPSS: Низкий
msrc логотип

CVE-2020-25742

больше 5 лет назад

pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.

CVSS3: 3.2
EPSS: Низкий
msrc логотип

CVE-2020-25723

около 5 лет назад

A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse this flaw to send bogus USB requests and crash the QEMU process on the host resulting in a denial of service.

CVSS3: 3.2
EPSS: Низкий
msrc логотип

CVE-2020-25722

больше 1 года назад

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2020-25719

больше 1 года назад

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 4.2
0%
Низкий
почти 4 года назад
msrc логотип
CVE-2020-26541

The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protection mechanism. This affects certs/blacklist.c and certs/system_keyring.c.

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2020-26159

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Further investigation showed that it was not a security issue. Notes: none

4 месяца назад
msrc логотип
CVSS3: 9.8
1%
Низкий
около 4 лет назад
msrc логотип
CVE-2020-26144

Windows Wireless Networking Spoofing Vulnerability

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2020-26137

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.

CVSS3: 6.5
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-26116

http.client in Python 3.x before 3.5.10 3.6.x before 3.6.12 3.7.x before 3.7.9 and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.

CVSS3: 7.2
1%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-26088

A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets bypassing security mechanisms aka CID-26896f01467a.

CVSS3: 5.5
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-25796

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the InlineArray implementation an unaligned reference may be generated for a type that has a large alignment requirement.

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-25795

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation insert_from can have a memory-safety issue upon a panic.

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-25794

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation clone can have a memory-safety issue upon a panic.

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-25793

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation the array size is not checked when constructed with From<InlineArray<A T>>.

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-25792

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation the array size is not checked when constructed with pair().

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-25791

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation the array size is not checked when constructed with unit().

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-25743

hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.

CVSS3: 3.2
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-25742

pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.

CVSS3: 3.2
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-25723

A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse this flaw to send bogus USB requests and crash the QEMU process on the host resulting in a denial of service.

CVSS3: 3.2
0%
Низкий
около 5 лет назад
msrc логотип
CVSS3: 8.8
0%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 7.2
0%
Низкий
больше 1 года назад

Уязвимостей на страницу