Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 124

Количество 26 124

msrc логотип

CVE-2023-2804

6 месяцев назад

Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-27986

больше 3 лет назад

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2023-27985

больше 3 лет назад

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2023-27911

больше 2 лет назад

AutoDesk: CVE-2023-27911 Heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2023-27910

около 3 лет назад

AutoDesk: CVE-2023-27910 stack buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior

EPSS: Низкий
msrc логотип

CVE-2023-27909

около 3 лет назад

AutoDesk: CVE-2023-27909 Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK 2020 or prior

EPSS: Низкий
msrc логотип

CVE-2023-27579

около 2 лет назад

TensorFlow has Floating Point Exception in TFLite in conv kernel

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-27561

больше 3 лет назад

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges related to libcontainer/rootfs_linux.go. To exploit this an attacker must be able to spawn two containers with custom volume-mount configurations and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2023-27538

больше 3 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-27537

6 месяцев назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2023-27536

больше 3 лет назад

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2023-27535

больше 3 лет назад

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2023-27534

больше 3 лет назад

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2023-27533

больше 3 лет назад

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2023-27522

больше 3 лет назад

Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-27478

около 2 лет назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-27477

больше 3 лет назад

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2023-27371

больше 3 лет назад

GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data boundary field which - assuming a specific heap layout - will result in an out-of-bounds read and a crash in the find_boundary() function.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2023-27320

больше 3 лет назад

CVSS3: 7.2
EPSS: Низкий
msrc логотип

CVE-2023-2731

около 3 лет назад

A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file resulting in a program crash or denial of service.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2023-2804

Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo

CVSS3: 6.5
1%
Низкий
6 месяцев назад
msrc логотип
CVE-2023-27986

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-27985

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-27911

AutoDesk: CVE-2023-27911 Heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior

CVSS3: 7.8
1%
Низкий
больше 2 лет назад
msrc логотип
CVE-2023-27910

AutoDesk: CVE-2023-27910 stack buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior

1%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-27909

AutoDesk: CVE-2023-27909 Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK 2020 or prior

0%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-27579

TensorFlow has Floating Point Exception in TFLite in conv kernel

CVSS3: 7.5
0%
Низкий
около 2 лет назад
msrc логотип
CVE-2023-27561

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges related to libcontainer/rootfs_linux.go. To exploit this an attacker must be able to spawn two containers with custom volume-mount configurations and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.

CVSS3: 7
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 5.5
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-27537

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
2%
Низкий
6 месяцев назад
msrc логотип
CVSS3: 5.9
2%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 5.9
2%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 8.8
2%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 8.8
2%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-27522

Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 6.5
1%
Низкий
около 2 лет назад
msrc логотип
CVSS3: 4.3
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-27371

GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data boundary field which - assuming a specific heap layout - will result in an out-of-bounds read and a crash in the find_boundary() function.

CVSS3: 5.9
1%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 7.2
2%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-2731

A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file resulting in a program crash or denial of service.

CVSS3: 5.5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу