Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 124

Количество 26 124

msrc логотип

CVE-2023-31436

больше 3 лет назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2023-3141

около 3 лет назад

A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect possibly leading to a kernel information leak.

CVSS3: 7.1
EPSS: Низкий
msrc логотип

CVE-2023-31419

9 дней назад

Elasticsearch StackOverflow vulnerability

EPSS: Средний
msrc логотип

CVE-2023-31417

9 дней назад

Elasticsearch Insertion of sensitive information in audit logs

EPSS: Низкий
msrc логотип

CVE-2023-3138

около 3 лет назад

A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request Event or Error IDs are within the bounds of the arrays that those functions write to using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself possibly causing the client to crash with this memory corruption.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-3117

11 месяцев назад

Rejected reason: Duplicate of CVE-2023-3390.

EPSS: Низкий
msrc логотип

CVE-2023-31147

6 месяцев назад

Insufficient randomness in generation of DNS query IDs in c-ares

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2023-31130

больше 1 года назад

Buffer Underwrite in ares_inet_net_pton()

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2023-31124

около 3 лет назад

AutoTools does not set CARES_RANDOM_FILE during cross compilation

CVSS3: 3.7
EPSS: Низкий
msrc логотип

CVE-2023-3111

около 3 лет назад

A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag().

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2023-31096

7 месяцев назад

MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2023-31084

почти 2 года назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-3090

около 3 лет назад

Out-of-bounds write in Linux kernel's ipvlan network driver

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2023-3079

около 3 лет назад

Chromium: CVE-2023-3079 Type Confusion in V8

EPSS: Средний
msrc логотип

CVE-2023-30772

больше 3 лет назад

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2023-30630

больше 3 лет назад

CVSS3: 7.1
EPSS: Низкий
msrc логотип

CVE-2023-30612

больше 3 лет назад

CVSS3: 4.9
EPSS: Низкий
msrc логотип

CVE-2023-30589

6 месяцев назад

The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3 only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16 v18 and v20

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-30582

8 месяцев назад

A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument. This flaw arises from an inadequate permission model that fails to restrict file watching through the fs.watchFile API. As a result, malicious actors can monitor files that they do not have explicit read access to. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

EPSS: Низкий
msrc логотип

CVE-2023-30570

около 3 лет назад

pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. The earliest affected version is 3.28.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 7.8
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-3141

A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect possibly leading to a kernel information leak.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-31419

Elasticsearch StackOverflow vulnerability

61%
Средний
9 дней назад
msrc логотип
CVE-2023-31417

Elasticsearch Insertion of sensitive information in audit logs

0%
Низкий
9 дней назад
msrc логотип
CVE-2023-3138

A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided for the Request Event or Error IDs are within the bounds of the arrays that those functions write to using those IDs as array indexes. They trust that they were called with values provided by an Xserver adhering to the bounds specified in the X11 protocol as all X servers provided by X.Org do. As the protocol only specifies a single byte for these values an out-of-bounds value provided by a malicious server (or a malicious proxy-in-the-middle) can only overwrite other portions of the Display structure and not write outside the bounds of the Display structure itself possibly causing the client to crash with this memory corruption.

CVSS3: 7.5
2%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-3117

Rejected reason: Duplicate of CVE-2023-3390.

11 месяцев назад
msrc логотип
CVE-2023-31147

Insufficient randomness in generation of DNS query IDs in c-ares

CVSS3: 5.9
1%
Низкий
6 месяцев назад
msrc логотип
CVE-2023-31130

Buffer Underwrite in ares_inet_net_pton()

CVSS3: 6.4
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2023-31124

AutoTools does not set CARES_RANDOM_FILE during cross compilation

CVSS3: 3.7
1%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-3111

A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag().

CVSS3: 7.8
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-31096

MITRE: CVE-2023-31096 Windows Agere Soft Modem Driver Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
7 месяцев назад
msrc логотип
CVSS3: 5.5
0%
Низкий
почти 2 года назад
msrc логотип
CVE-2023-3090

Out-of-bounds write in Linux kernel's ipvlan network driver

CVSS3: 7.8
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-3079

Chromium: CVE-2023-3079 Type Confusion in V8

32%
Средний
около 3 лет назад
msrc логотип
CVSS3: 6.4
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 7.1
1%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 4.9
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-30589

The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3 only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16 v18 and v20

CVSS3: 7.5
4%
Низкий
6 месяцев назад
msrc логотип
CVE-2023-30582

A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument. This flaw arises from an inadequate permission model that fails to restrict file watching through the fs.watchFile API. As a result, malicious actors can monitor files that they do not have explicit read access to. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.

1%
Низкий
8 месяцев назад
msrc логотип
CVE-2023-30570

pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. The earliest affected version is 3.28.

CVSS3: 7.5
1%
Низкий
около 3 лет назад

Уязвимостей на страницу