Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 124

Количество 26 124

msrc логотип

CVE-2023-32010

около 3 лет назад

Windows Bus Filter Driver Elevation of Privilege Vulnerability

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2023-32009

около 3 лет назад

Windows Collaborative Translation Framework Elevation of Privilege Vulnerability

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2023-32008

около 3 лет назад

Windows Resilient File System (ReFS) Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2023-32006

почти 3 года назад

The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x 18.x and 20.x. Please note that at the time this CVE was issued the policy is an experimental feature of Node.js.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2023-32004

почти 3 года назад

A vulnerability has been discovered in Node.js version 20 specifically within the experimental permission model. This flaw relates to improper handling of Buffers in file system APIs causing a traversal path to bypass when verifying file permissions. This vulnerability affects all users using the experimental permission model in Node.js 20. Please note that at the time this CVE was issued the permission model is an experimental feature of Node.js.

EPSS: Низкий
msrc логотип

CVE-2023-32003

почти 3 года назад

`fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. This flaw arises from a missing check in the fs.mkdtemp() API and the impact is a malicious actor could create an arbitrary directory. This vulnerability affects all users using the experimental permission model in Node.js 20. Please note that at the time this CVE was issued the permission model is an experimental feature of Node.js.

EPSS: Низкий
msrc логотип

CVE-2023-32002

больше 1 года назад

HackerOne: CVE-2023-32002 Node.js `Module._load()` policy Remote Code Execution Vulnerability

EPSS: Низкий
msrc логотип

CVE-2023-32002 - M

почти 3 года назад

EPSS: Низкий
msrc логотип

CVE-2023-32001

около 2 лет назад

Rejected reason: We issued this CVE pre-maturely as we have subsequently realized that this issue points out a problem that there really is no safe measures around or protections for.

EPSS: Низкий
msrc логотип

CVE-2023-31975

больше 3 лет назад

yasm v1.3.0 was discovered to contain a memory leak via the function yasm_intnum_copy at /libyasm/intnum.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy.

CVSS3: 3.3
EPSS: Низкий
msrc логотип

CVE-2023-3180

почти 2 года назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-31670

6 месяцев назад

An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a Denial of Service (DoS) via running a crafted binary.

EPSS: Низкий
msrc логотип

CVE-2023-3164

больше 1 года назад

Heap-buffer-overflow in extractimagesection()

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-3161

около 3 лет назад

A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font since there are no checks in place a shift-out-of-bounds occurs leading to undefined behavior and possible denial of service.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-3159

около 3 лет назад

A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker with special privilege may cause a use after free problem when queue_event() fails.

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2023-31490

около 3 лет назад

An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-31486

около 3 лет назад

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2023-31484

12 месяцев назад

CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2023-31439

9 дней назад

An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."

EPSS: Низкий
msrc логотип

CVE-2023-31438

9 дней назад

An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2023-32010

Windows Bus Filter Driver Elevation of Privilege Vulnerability

CVSS3: 7
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-32009

Windows Collaborative Translation Framework Elevation of Privilege Vulnerability

CVSS3: 8.8
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-32008

Windows Resilient File System (ReFS) Remote Code Execution Vulnerability

CVSS3: 7.8
1%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-32006

The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x 18.x and 20.x. Please note that at the time this CVE was issued the policy is an experimental feature of Node.js.

CVSS3: 8.8
2%
Низкий
почти 3 года назад
msrc логотип
CVE-2023-32004

A vulnerability has been discovered in Node.js version 20 specifically within the experimental permission model. This flaw relates to improper handling of Buffers in file system APIs causing a traversal path to bypass when verifying file permissions. This vulnerability affects all users using the experimental permission model in Node.js 20. Please note that at the time this CVE was issued the permission model is an experimental feature of Node.js.

2%
Низкий
почти 3 года назад
msrc логотип
CVE-2023-32003

`fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. This flaw arises from a missing check in the fs.mkdtemp() API and the impact is a malicious actor could create an arbitrary directory. This vulnerability affects all users using the experimental permission model in Node.js 20. Please note that at the time this CVE was issued the permission model is an experimental feature of Node.js.

1%
Низкий
почти 3 года назад
msrc логотип
CVE-2023-32002

HackerOne: CVE-2023-32002 Node.js `Module._load()` policy Remote Code Execution Vulnerability

2%
Низкий
больше 1 года назад
msrc логотип
почти 3 года назад
msrc логотип
CVE-2023-32001

Rejected reason: We issued this CVE pre-maturely as we have subsequently realized that this issue points out a problem that there really is no safe measures around or protections for.

около 2 лет назад
msrc логотип
CVE-2023-31975

yasm v1.3.0 was discovered to contain a memory leak via the function yasm_intnum_copy at /libyasm/intnum.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 6.5
0%
Низкий
почти 2 года назад
msrc логотип
CVE-2023-31670

An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a Denial of Service (DoS) via running a crafted binary.

1%
Низкий
6 месяцев назад
msrc логотип
CVE-2023-3164

Heap-buffer-overflow in extractimagesection()

CVSS3: 5.5
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2023-3161

A flaw was found in the Framebuffer Console (fbcon) in the Linux Kernel. When providing font->width and font->height greater than 32 to fbcon_set_font since there are no checks in place a shift-out-of-bounds occurs leading to undefined behavior and possible denial of service.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-3159

A use after free issue was discovered in driver/firewire in outbound_phy_packet_callback in the Linux Kernel. In this flaw a local attacker with special privilege may cause a use after free problem when queue_event() fails.

CVSS3: 6.7
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-31490

An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.

CVSS3: 7.5
2%
Низкий
около 3 лет назад
msrc логотип
CVSS3: 8.1
2%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-31484

CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

CVSS3: 8.1
2%
Низкий
12 месяцев назад
msrc логотип
CVE-2023-31439

An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."

0%
Низкий
9 дней назад
msrc логотип
CVE-2023-31438

An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."

0%
Низкий
9 дней назад

Уязвимостей на страницу