Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 124

Количество 26 124

msrc логотип

CVE-2023-46045

больше 2 лет назад

Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2023-45929

12 месяцев назад

S-Lang 2.3.2 was discovered to contain a segmentation fault via the function fixup_tgetstr().

EPSS: Низкий
msrc логотип

CVE-2023-45927

12 месяцев назад

S-Lang 2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf().

EPSS: Низкий
msrc логотип

CVE-2023-45898

почти 3 года назад

The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c related to ext4_es_insert_extent.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2023-45872

11 дней назад

An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x before 6.6.1. When a QML image refers to an image whose content is not known yet, there is an assumption that it is an SVG document, leading to a denial of service (application crash) if it is not actually an SVG document.

EPSS: Низкий
msrc логотип

CVE-2023-45871

почти 3 года назад

An issue was discovered in drivers/net/ethernet/intel/igb/igb_main.c in the IGB driver in the Linux kernel before 6.5.3. A buffer size may not be adequate for frames larger than the MTU.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-45866

почти 2 года назад

CVSS3: 6.3
EPSS: Низкий
msrc логотип

CVE-2023-45863

почти 3 года назад

An issue was discovered in lib/kobject.c in the Linux kernel before 6.2.3. With root access an attacker can trigger a race condition that results in a fill_kobj_path out-of-bounds write.

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2023-45862

почти 3 года назад

An issue was discovered in drivers/usb/storage/ene_ub6250.c for the ENE UB6250 reader driver in the Linux kernel before 6.2.5. An object could potentially extend beyond the end of an allocation.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-45857

12 месяцев назад

An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.

EPSS: Низкий
msrc логотип

CVE-2023-45853

почти 3 года назад

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2023-4583

12 месяцев назад

When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

EPSS: Низкий
msrc логотип

CVE-2023-4580

6 месяцев назад

Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

EPSS: Низкий
msrc логотип

CVE-2023-45803

почти 2 года назад

CVSS3: 4.2
EPSS: Низкий
msrc логотип

CVE-2023-45802

почти 3 года назад

Apache HTTP Server: HTTP/2 stream memory not reclaimed right away on RST

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2023-4572

почти 3 года назад

Chromium: CVE-2023-4572 Use after free in MediaStream

EPSS: Низкий
msrc логотип

CVE-2023-4569

почти 3 года назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-45539

11 месяцев назад

HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to a static server.

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2023-4535

6 месяцев назад

Opensc: out-of-bounds read in myeid driver handling encryption using symmetric keys

CVSS3: 3.8
EPSS: Низкий
msrc логотип

CVE-2023-45322

больше 1 года назад

libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail."

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2023-46045

Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.

CVSS3: 7.8
1%
Низкий
больше 2 лет назад
msrc логотип
CVE-2023-45929

S-Lang 2.3.2 was discovered to contain a segmentation fault via the function fixup_tgetstr().

1%
Низкий
12 месяцев назад
msrc логотип
CVE-2023-45927

S-Lang 2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf().

1%
Низкий
12 месяцев назад
msrc логотип
CVE-2023-45898

The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c related to ext4_es_insert_extent.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
msrc логотип
CVE-2023-45872

An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x before 6.6.1. When a QML image refers to an image whose content is not known yet, there is an assumption that it is an SVG document, leading to a denial of service (application crash) if it is not actually an SVG document.

0%
Низкий
11 дней назад
msrc логотип
CVE-2023-45871

An issue was discovered in drivers/net/ethernet/intel/igb/igb_main.c in the IGB driver in the Linux kernel before 6.5.3. A buffer size may not be adequate for frames larger than the MTU.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 6.3
8%
Низкий
почти 2 года назад
msrc логотип
CVE-2023-45863

An issue was discovered in lib/kobject.c in the Linux kernel before 6.2.3. With root access an attacker can trigger a race condition that results in a fill_kobj_path out-of-bounds write.

CVSS3: 6.4
0%
Низкий
почти 3 года назад
msrc логотип
CVE-2023-45862

An issue was discovered in drivers/usb/storage/ene_ub6250.c for the ENE UB6250 reader driver in the Linux kernel before 6.2.5. An object could potentially extend beyond the end of an allocation.

CVSS3: 5.5
0%
Низкий
почти 3 года назад
msrc логотип
CVE-2023-45857

An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.

1%
Низкий
12 месяцев назад
msrc логотип
CVSS3: 9.8
3%
Низкий
почти 3 года назад
msrc логотип
CVE-2023-4583

When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

1%
Низкий
12 месяцев назад
msrc логотип
CVE-2023-4580

Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

0%
Низкий
6 месяцев назад
msrc логотип
CVSS3: 4.2
1%
Низкий
почти 2 года назад
msrc логотип
CVE-2023-45802

Apache HTTP Server: HTTP/2 stream memory not reclaimed right away on RST

CVSS3: 5.9
3%
Низкий
почти 3 года назад
msrc логотип
CVE-2023-4572

Chromium: CVE-2023-4572 Use after free in MediaStream

1%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 5.5
0%
Низкий
почти 3 года назад
msrc логотип
CVE-2023-45539

HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers to obtain sensitive information or have unspecified other impact upon misinterpretation of a path_end rule, such as routing index.html#.png to a static server.

CVSS3: 8.2
2%
Низкий
11 месяцев назад
msrc логотип
CVE-2023-4535

Opensc: out-of-bounds read in myeid driver handling encryption using symmetric keys

CVSS3: 3.8
0%
Низкий
6 месяцев назад
msrc логотип
CVE-2023-45322

libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This occurs in xmlUnlinkNode in tree.c. NOTE: the vendor's position is "I don't think these issues are critical enough to warrant a CVE ID ... because an attacker typically can't control when memory allocations fail."

CVSS3: 6.5
1%
Низкий
больше 1 года назад

Уязвимостей на страницу