Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 124

Количество 26 124

msrc логотип

CVE-2023-3268

около 3 лет назад

An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information.

CVSS3: 7.1
EPSS: Низкий
msrc логотип

CVE-2023-32681

около 3 лет назад

Unintended leak of Proxy-Authorization header in requests

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2023-32665

11 месяцев назад

Gvariant deserialisation does not match spec for non-normal data

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-32643

больше 1 года назад

A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fix for CVE-2023-32665. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-32665.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2023-32636

больше 1 года назад

A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.

CVSS3: 4.7
EPSS: Низкий
msrc логотип

CVE-2023-32611

11 месяцев назад

G_variant_byteswap() can take a long time with some non-normal inputs

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-32573

6 месяцев назад

In Qt before 5.15.14 6.0.x through 6.2.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1 QtSvg QSvgFont m_unitsPerEm initialization is mishandled.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-32570

6 месяцев назад

VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.

EPSS: Низкий
msrc логотип

CVE-2023-3255

почти 2 года назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-32559

почти 3 года назад

A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x 18.x and 20.x. The use of the deprecated API `process.binding()` can bypass the policy mechanism by requiring internal modules and eventually take advantage of `process.binding('spawn_sync')` run arbitrary code outside of the limits defined in a `policy.json` file. Please note that at the time this CVE was issued the policy is an experimental feature of Node.js.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-3247

около 3 лет назад

Missing error check and insufficient random bytes in HTTP Digest authentication for SOAP

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2023-32324

больше 2 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-32269

больше 3 лет назад

An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c there is a use-after-free because accept is also allowed for a successfully connected AF_NETROM socket. However in order for an attacker to exploit this the system must have netrom routing configured or the attacker must have the CAP_NET_ADMIN capability.

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2023-32258

около 3 лет назад

Session race condition remote code execution vulnerability

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2023-32257

около 3 лет назад

Session race condition remote code execution vulnerability

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2023-32254

около 3 лет назад

Tree connection race condition remote code execution vulnerability

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2023-32252

около 3 лет назад

Session null pointer dereference denial-of-service vulnerability

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-32250

около 3 лет назад

Session race condition remote code execution vulnerability

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2023-32248

около 3 лет назад

Tree connection null pointer dereference denial-of-service vulnerability

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-32247

около 3 лет назад

Session setup memory exhaustion denial-of-service vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2023-3268

An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-32681

Unintended leak of Proxy-Authorization header in requests

CVSS3: 6.1
3%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-32665

Gvariant deserialisation does not match spec for non-normal data

CVSS3: 5.5
0%
Низкий
11 месяцев назад
msrc логотип
CVE-2023-32643

A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fix for CVE-2023-32665. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-32665.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2023-32636

A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.

CVSS3: 4.7
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2023-32611

G_variant_byteswap() can take a long time with some non-normal inputs

CVSS3: 5.5
0%
Низкий
11 месяцев назад
msrc логотип
CVE-2023-32573

In Qt before 5.15.14 6.0.x through 6.2.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1 QtSvg QSvgFont m_unitsPerEm initialization is mishandled.

CVSS3: 6.5
1%
Низкий
6 месяцев назад
msrc логотип
CVE-2023-32570

VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.

1%
Низкий
6 месяцев назад
msrc логотип
CVSS3: 6.5
2%
Низкий
почти 2 года назад
msrc логотип
CVE-2023-32559

A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x 18.x and 20.x. The use of the deprecated API `process.binding()` can bypass the policy mechanism by requiring internal modules and eventually take advantage of `process.binding('spawn_sync')` run arbitrary code outside of the limits defined in a `policy.json` file. Please note that at the time this CVE was issued the policy is an experimental feature of Node.js.

CVSS3: 7.5
2%
Низкий
почти 3 года назад
msrc логотип
CVE-2023-3247

Missing error check and insufficient random bytes in HTTP Digest authentication for SOAP

CVSS3: 4.3
1%
Низкий
около 3 лет назад
msrc логотип
CVSS3: 5.5
1%
Низкий
больше 2 лет назад
msrc логотип
CVE-2023-32269

An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c there is a use-after-free because accept is also allowed for a successfully connected AF_NETROM socket. However in order for an attacker to exploit this the system must have netrom routing configured or the attacker must have the CAP_NET_ADMIN capability.

CVSS3: 6.7
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-32258

Session race condition remote code execution vulnerability

CVSS3: 8.1
3%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-32257

Session race condition remote code execution vulnerability

CVSS3: 8.1
2%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-32254

Tree connection race condition remote code execution vulnerability

CVSS3: 8.1
3%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-32252

Session null pointer dereference denial-of-service vulnerability

CVSS3: 7.5
4%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-32250

Session race condition remote code execution vulnerability

CVSS3: 8.1
3%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-32248

Tree connection null pointer dereference denial-of-service vulnerability

CVSS3: 7.5
4%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-32247

Session setup memory exhaustion denial-of-service vulnerability

CVSS3: 7.5
4%
Низкий
около 3 лет назад

Уязвимостей на страницу