Логотип exploitDog
source:"msrc"
Консоль
Логотип exploitDog

exploitDog

source:"msrc"

Количество 18 769

Количество 18 769

msrc логотип

CVE-2019-9070

больше 5 лет назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2019-8457

больше 1 года назад

CVSS3: 9.8
EPSS: Средний
msrc логотип

CVE-2019-7317

11 месяцев назад

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2019-7309

больше 5 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2019-6706

больше 5 лет назад

Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2019-6488

больше 5 лет назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2019-6486

5 месяцев назад

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

EPSS: Низкий
msrc логотип

CVE-2019-6470

больше 5 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2019-6462

больше 5 лет назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2019-6461

больше 5 лет назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2019-6454

больше 5 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2019-6293

больше 5 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2019-6292

больше 5 лет назад

An issue was discovered in singledocparser.cpp in yaml-cpp (aka LibYaml-C++) 0.6.2. Stack Exhaustion occurs in YAML::SingleDocParser and there is a stack consumption problem caused by recursive stack frames: HandleCompactMap HandleMap HandleFlowSequence HandleSequence HandleNode. Remote attackers could leverage this vulnerability to cause a denial-of-service via a cpp file.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2019-6290

5 месяцев назад

An infinite recursion issue was discovered in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhaustion problem resulting from infinite recursion in the functions expr, rexp, bexpr and cexpr in certain scenarios involving lots of '{' characters. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted asm file.

EPSS: Низкий
msrc логотип

CVE-2019-6285

больше 5 лет назад

The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2019-5737

больше 4 лет назад

In Node.js including 6.x before 6.17.0 8.x before 8.15.1 10.x before 10.15.2 and 11.x before 11.10.1 an attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in keep-alive mode and by sending headers very slowly. This keeps the connection and associated resources alive for a long period of time. Potential attacks are mitigated by the use of a load balancer or other proxy layer. This vulnerability is an extension of CVE-2018-12121 addressed in November and impacts all active Node.js release lines including 6.x before 6.17.0 8.x before 8.15.1 10.x before 10.15.2 and 11.x before 11.10.1.

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2019-5736

больше 4 лет назад

CVSS3: 8.6
EPSS: Средний
msrc логотип

CVE-2019-5544

около 4 лет назад

CVSS3: 9.8
EPSS: Критический
msrc логотип

CVE-2019-5188

около 5 лет назад

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2019-5094

около 5 лет назад

CVSS3: 6.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 7.8
0%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 9.8
27%
Средний
больше 1 года назад
msrc логотип
CVSS3: 5.3
1%
Низкий
11 месяцев назад
msrc логотип
CVSS3: 5.5
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2019-6706

Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.

CVSS3: 7.5
1%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 7.8
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2019-6486

Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a denial of service (CPU consumption) or possibly conduct ECDH private key recovery attacks.

2%
Низкий
5 месяцев назад
msrc логотип
CVSS3: 7.5
0%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 6.5
0%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 6.5
0%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2019-6292

An issue was discovered in singledocparser.cpp in yaml-cpp (aka LibYaml-C++) 0.6.2. Stack Exhaustion occurs in YAML::SingleDocParser and there is a stack consumption problem caused by recursive stack frames: HandleCompactMap HandleMap HandleFlowSequence HandleSequence HandleNode. Remote attackers could leverage this vulnerability to cause a denial-of-service via a cpp file.

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
msrc логотип
CVE-2019-6290

An infinite recursion issue was discovered in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhaustion problem resulting from infinite recursion in the functions expr, rexp, bexpr and cexpr in certain scenarios involving lots of '{' characters. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted asm file.

0%
Низкий
5 месяцев назад
msrc логотип
CVE-2019-6285

The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
msrc логотип
CVE-2019-5737

In Node.js including 6.x before 6.17.0 8.x before 8.15.1 10.x before 10.15.2 and 11.x before 11.10.1 an attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in keep-alive mode and by sending headers very slowly. This keeps the connection and associated resources alive for a long period of time. Potential attacks are mitigated by the use of a load balancer or other proxy layer. This vulnerability is an extension of CVE-2018-12121 addressed in November and impacts all active Node.js release lines including 6.x before 6.17.0 8.x before 8.15.1 10.x before 10.15.2 and 11.x before 11.10.1.

CVSS3: 7.5
36%
Средний
больше 4 лет назад
msrc логотип
CVSS3: 8.6
56%
Средний
больше 4 лет назад
msrc логотип
CVSS3: 9.8
93%
Критический
около 4 лет назад
msrc логотип
CVSS3: 6.7
0%
Низкий
около 5 лет назад
msrc логотип
CVSS3: 6.7
0%
Низкий
около 5 лет назад

Уязвимостей на страницу