Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 124

Количество 26 124

msrc логотип

CVE-2023-50229

6 месяцев назад

BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability

CVSS3: 7.1
EPSS: Низкий
msrc логотип

CVE-2023-49994

6 месяцев назад

Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-49993

6 месяцев назад

Espeak-ng 1.52-dev was discovered to contain a Buffer Overflow

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2023-49992

больше 1 года назад

Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Overflow via the function RemoveEnding at dictionary.c.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2023-49991

6 месяцев назад

Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2023-49990

около 2 лет назад

Espeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2023-49921

5 дней назад

An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents of documents stored in Elasticsearch to be printed in logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by removing this excessive logging. This issue only affects users that use Watcher and have a Watch defined that uses the search input and additionally have set the search input’s logger to DEBUG or finer, for example using: org.elasticsearch.xpack.watcher.input.search, org.elasticsearch.xpack.watcher.input, org.elasticsearch.xpack.watcher, or wider, since the loggers are hierarchical.

EPSS: Низкий
msrc логотип

CVE-2023-49582

почти 2 года назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-49569

около 2 лет назад

Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2023-49568

около 2 лет назад

Maliciously crafted Git server replies can cause DoS on go-git clients

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-49558

12 месяцев назад

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component.

EPSS: Низкий
msrc логотип

CVE-2023-49557

12 месяцев назад

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component.

EPSS: Низкий
msrc логотип

CVE-2023-49556

12 месяцев назад

Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component.

EPSS: Низкий
msrc логотип

CVE-2023-49555

12 месяцев назад

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nasm-pp.c component.

EPSS: Низкий
msrc логотип

CVE-2023-49554

12 месяцев назад

Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component.

EPSS: Низкий
msrc логотип

CVE-2023-49355

12 месяцев назад

decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input. NOTE: this is not the same as CVE-2023-50246. The CVE-2023-50246 71c2ab5 reference mentions -10E-1000010001, which is not in normalized scientific notation.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-49295

больше 2 лет назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-49292

6 месяцев назад

Possible private key restoration in go package github.com/ecies/go

CVSS3: 4.9
EPSS: Низкий
msrc логотип

CVE-2023-49284

больше 2 лет назад

Command substitution output can trigger shell expansion in fish shell

CVSS3: 6.6
EPSS: Низкий
msrc логотип

CVE-2023-4921

почти 3 года назад

Use-after-free in Linux kernel's net/sched: sch_qfq component

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2023-50229

BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability

CVSS3: 7.1
2%
Низкий
6 месяцев назад
msrc логотип
CVE-2023-49994

Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c.

CVSS3: 5.5
0%
Низкий
6 месяцев назад
msrc логотип
CVE-2023-49993

Espeak-ng 1.52-dev was discovered to contain a Buffer Overflow

CVSS3: 5.3
0%
Низкий
6 месяцев назад
msrc логотип
CVE-2023-49992

Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Overflow via the function RemoveEnding at dictionary.c.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2023-49991

Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
msrc логотип
CVE-2023-49990

Espeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c.

CVSS3: 5.3
0%
Низкий
около 2 лет назад
msrc логотип
CVE-2023-49921

An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents of documents stored in Elasticsearch to be printed in logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by removing this excessive logging. This issue only affects users that use Watcher and have a Watch defined that uses the search input and additionally have set the search input’s logger to DEBUG or finer, for example using: org.elasticsearch.xpack.watcher.input.search, org.elasticsearch.xpack.watcher.input, org.elasticsearch.xpack.watcher, or wider, since the loggers are hierarchical.

0%
Низкий
5 дней назад
msrc логотип
CVSS3: 5.5
0%
Низкий
почти 2 года назад
msrc логотип
CVE-2023-49569

Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

CVSS3: 9.8
2%
Низкий
около 2 лет назад
msrc логотип
CVE-2023-49568

Maliciously crafted Git server replies can cause DoS on go-git clients

CVSS3: 7.5
1%
Низкий
около 2 лет назад
msrc логотип
CVE-2023-49558

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component.

0%
Низкий
12 месяцев назад
msrc логотип
CVE-2023-49557

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component.

0%
Низкий
12 месяцев назад
msrc логотип
CVE-2023-49556

Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component.

0%
Низкий
12 месяцев назад
msrc логотип
CVE-2023-49555

An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nasm-pp.c component.

0%
Низкий
12 месяцев назад
msrc логотип
CVE-2023-49554

Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component.

0%
Низкий
12 месяцев назад
msrc логотип
CVE-2023-49355

decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input. NOTE: this is not the same as CVE-2023-50246. The CVE-2023-50246 71c2ab5 reference mentions -10E-1000010001, which is not in normalized scientific notation.

CVSS3: 7.5
1%
Низкий
12 месяцев назад
msrc логотип
CVSS3: 6.5
1%
Низкий
больше 2 лет назад
msrc логотип
CVE-2023-49292

Possible private key restoration in go package github.com/ecies/go

CVSS3: 4.9
0%
Низкий
6 месяцев назад
msrc логотип
CVE-2023-49284

Command substitution output can trigger shell expansion in fish shell

CVSS3: 6.6
0%
Низкий
больше 2 лет назад
msrc логотип
CVE-2023-4921

Use-after-free in Linux kernel's net/sched: sch_qfq component

CVSS3: 7.8
0%
Низкий
почти 3 года назад

Уязвимостей на страницу