Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 124

Количество 26 124

msrc логотип

CVE-2023-3420

около 3 лет назад

Chromium: CVE-2023-3420 Type Confusion in V8

EPSS: Средний
msrc логотип

CVE-2023-34059

почти 3 года назад

open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2023-34058

почти 3 года назад

VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-33976

почти 2 года назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-33953

6 месяцев назад

Denial-of-Service in gRPC

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-33952

около 3 лет назад

Kernel: vmwgfx: double free within the handling of vmw_buffer_object objects

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2023-33951

около 3 лет назад

Kernel: vmwgfx: race condition leading to information disclosure vulnerability

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2023-3390

11 месяцев назад

Use-after-free in Linux kernel's netfilter subsystem

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2023-3389

около 3 лет назад

Use after free in io_uring in the Linux Kernel

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2023-3359

около 3 лет назад

An issue was discovered in the Linux kernel brcm_nvram_parse in drivers/nvmem/brcm_nvram.c. Lacks for the check of the return value of kzalloc() can cause the NULL Pointer Dereference.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-3358

около 3 лет назад

A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver. This issue could allow a local user to crash the system.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-3357

около 3 лет назад

A NULL pointer dereference flaw was found in the Linux kernel AMD Sensor Fusion Hub driver. This flaw allows a local user to crash the system.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-3355

около 3 лет назад

Null pointer dereference in submit_lookup_cmds() in drivers/gpu/drm/msm/msm_gem_submit.c

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-3354

около 2 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-33461

около 1 года назад

iniparser v4.1 is vulnerable to NULL Pointer Dereference in function iniparser_getlongint which misses check NULL for function iniparser_getstring's return.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-33460

около 3 лет назад

There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-3341

около 2 лет назад

A stack exhaustion flaw in control channel code may cause named to terminate unexpectedly

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-3338

6 месяцев назад

Crash due to a null pointer dereference in the dn_nsp_send function

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-33288

около 3 лет назад

An issue was discovered in the Linux kernel before 6.2.9. A use-after-free was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race condition.

CVSS3: 4.7
EPSS: Низкий
msrc логотип

CVE-2023-33285

около 3 лет назад

An issue was discovered in Qt 5.x before 5.15.14 6.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2023-3420

Chromium: CVE-2023-3420 Type Confusion in V8

56%
Средний
около 3 лет назад
msrc логотип
CVE-2023-34059

open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.

CVSS3: 7
0%
Низкий
почти 3 года назад
msrc логотип
CVE-2023-34058

VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .

CVSS3: 7.5
1%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 7.5
0%
Низкий
почти 2 года назад
msrc логотип
CVE-2023-33953

Denial-of-Service in gRPC

CVSS3: 7.5
0%
Низкий
6 месяцев назад
msrc логотип
CVE-2023-33952

Kernel: vmwgfx: double free within the handling of vmw_buffer_object objects

CVSS3: 6.7
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-33951

Kernel: vmwgfx: race condition leading to information disclosure vulnerability

CVSS3: 5.3
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-3390

Use-after-free in Linux kernel's netfilter subsystem

CVSS3: 7.8
1%
Низкий
11 месяцев назад
msrc логотип
CVE-2023-3389

Use after free in io_uring in the Linux Kernel

CVSS3: 7.8
1%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-3359

An issue was discovered in the Linux kernel brcm_nvram_parse in drivers/nvmem/brcm_nvram.c. Lacks for the check of the return value of kzalloc() can cause the NULL Pointer Dereference.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-3358

A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver. This issue could allow a local user to crash the system.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-3357

A NULL pointer dereference flaw was found in the Linux kernel AMD Sensor Fusion Hub driver. This flaw allows a local user to crash the system.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-3355

Null pointer dereference in submit_lookup_cmds() in drivers/gpu/drm/msm/msm_gem_submit.c

CVSS3: 5.5
0%
Низкий
около 3 лет назад
msrc логотип
CVSS3: 7.5
2%
Низкий
около 2 лет назад
msrc логотип
CVE-2023-33461

iniparser v4.1 is vulnerable to NULL Pointer Dereference in function iniparser_getlongint which misses check NULL for function iniparser_getstring's return.

CVSS3: 5.5
0%
Низкий
около 1 года назад
msrc логотип
CVE-2023-33460

There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-3341

A stack exhaustion flaw in control channel code may cause named to terminate unexpectedly

CVSS3: 7.5
3%
Низкий
около 2 лет назад
msrc логотип
CVE-2023-3338

Crash due to a null pointer dereference in the dn_nsp_send function

CVSS3: 6.5
8%
Низкий
6 месяцев назад
msrc логотип
CVE-2023-33288

An issue was discovered in the Linux kernel before 6.2.9. A use-after-free was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race condition.

CVSS3: 4.7
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-33285

An issue was discovered in Qt 5.x before 5.15.14 6.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.

CVSS3: 5.3
1%
Низкий
около 3 лет назад

Уязвимостей на страницу