Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 124

Количество 26 124

msrc логотип

CVE-2023-30456

больше 3 лет назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-30402

12 месяцев назад

YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code.

EPSS: Низкий
msrc логотип

CVE-2023-3019

больше 1 года назад

Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest()

CVSS3: 6
EPSS: Низкий
msrc логотип

CVE-2023-29942

больше 1 года назад

llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::Type::isa<mlir::LLVM::LLVMVoidType.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-29941

больше 1 года назад

llvm-project commit a0138390 was discovered to contain a segmentation fault via the component matchAndRewriteSortOp<mlir::sparse_tensor::SortOp>(mlir::sparse_tensor::SortOp.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-29935

больше 1 года назад

llvm-project commit a0138390 was discovered to contain an assertion failure at !replacements.count(op) && "operation was already replaced.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-29933

больше 1 года назад

llvm-project commit bd456297 was discovered to contain a segmentation fault via the component mlir::Block::getArgument.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-29932

7 месяцев назад

llvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOperand.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-2985

около 3 лет назад

A use after free flaw was found in hfsplus_put_super in fs/hfsplus/super.c in the Linux Kernel. This flaw could allow a local user to cause a denial of service problem.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-2977

около 3 лет назад

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.

CVSS3: 7.1
EPSS: Низкий
msrc логотип

CVE-2023-2976

около 2 лет назад

CVSS3: 7.1
EPSS: Низкий
msrc логотип

CVE-2023-2975

больше 1 года назад

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2023-2961

около 3 лет назад

A segmentation fault flaw was found in the Advancecomp package. This may lead to decreased availability.

CVSS3: 3.3
EPSS: Низкий
msrc логотип

CVE-2023-29583

9 дней назад

yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code.

EPSS: Низкий
msrc логотип

CVE-2023-29582

12 месяцев назад

yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code.

EPSS: Низкий
msrc логотип

CVE-2023-29581

12 месяцев назад

yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if this were exploited, the vendor's position is that there is no security relevance because there is either supposed to be input validation before data reaches libyasm, or a sandbox in which the application runs.

EPSS: Низкий
msrc логотип

CVE-2023-29580

12 месяцев назад

yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/expr.c.

EPSS: Низкий
msrc логотип

CVE-2023-29549

6 месяцев назад

Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

EPSS: Низкий
msrc логотип

CVE-2023-29547

12 месяцев назад

When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

EPSS: Низкий
msrc логотип

CVE-2023-29544

12 месяцев назад

If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 6.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-30402

YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code.

0%
Низкий
12 месяцев назад
msrc логотип
CVE-2023-3019

Qemu: e1000e: heap use-after-free in e1000e_write_packet_to_guest()

CVSS3: 6
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2023-29942

llvm-project commit a0138390 was discovered to contain a segmentation fault via the component mlir::Type::isa<mlir::LLVM::LLVMVoidType.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2023-29941

llvm-project commit a0138390 was discovered to contain a segmentation fault via the component matchAndRewriteSortOp<mlir::sparse_tensor::SortOp>(mlir::sparse_tensor::SortOp.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2023-29935

llvm-project commit a0138390 was discovered to contain an assertion failure at !replacements.count(op) && "operation was already replaced.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2023-29933

llvm-project commit bd456297 was discovered to contain a segmentation fault via the component mlir::Block::getArgument.

CVSS3: 5.5
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2023-29932

llvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOperand.

CVSS3: 5.5
0%
Низкий
7 месяцев назад
msrc логотип
CVE-2023-2985

A use after free flaw was found in hfsplus_put_super in fs/hfsplus/super.c in the Linux Kernel. This flaw could allow a local user to cause a denial of service problem.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-2977

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can supply a smart card package with malformed ASN1 context. The cardos_have_verifyrc_package function scans the ASN1 buffer for 2 tags where remaining length is wrongly caculated due to moved starting pointer. This leads to possible heap-based buffer oob read. In cases where ASAN is enabled while compiling this causes a crash. Further info leak or more damage is possible.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
msrc логотип
CVSS3: 7.1
0%
Низкий
около 2 лет назад
msrc логотип
CVSS3: 5.3
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2023-2961

A segmentation fault flaw was found in the Advancecomp package. This may lead to decreased availability.

CVSS3: 3.3
0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-29583

yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code.

0%
Низкий
9 дней назад
msrc логотип
CVE-2023-29582

yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code.

0%
Низкий
12 месяцев назад
msrc логотип
CVE-2023-29581

yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if this were exploited, the vendor's position is that there is no security relevance because there is either supposed to be input validation before data reaches libyasm, or a sandbox in which the application runs.

0%
Низкий
12 месяцев назад
msrc логотип
CVE-2023-29580

yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/expr.c.

0%
Низкий
12 месяцев назад
msrc логотип
CVE-2023-29549

Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

0%
Низкий
6 месяцев назад
msrc логотип
CVE-2023-29547

When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

0%
Низкий
12 месяцев назад
msrc логотип
CVE-2023-29544

If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

0%
Низкий
12 месяцев назад

Уязвимостей на страницу