Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 091

Количество 26 091

msrc логотип

CVE-2023-23004

больше 3 лет назад

In the Linux kernel before 5.19 drivers/gpu/drm/arm/malidp_planes.c misinterprets the get_sg_table return value (expects it to be NULL in the error case whereas it is actually an error pointer).

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-23003

больше 3 лет назад

In the Linux kernel before 5.16 tools/perf/util/expr.c lacks a check for the hashmap__new return value.

CVSS3: 4
EPSS: Низкий
msrc логотип

CVE-2023-23002

больше 3 лет назад

In the Linux kernel before 5.16.3 drivers/bluetooth/hci_qca.c misinterprets the devm_gpiod_get_index_optional return value (expects it to be NULL in the error case whereas it is actually an error pointer).

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-23001

больше 3 лет назад

In the Linux kernel before 5.16.3 drivers/scsi/ufs/ufs-mediatek.c misinterprets the regulator_get return value (expects it to be NULL in the error case whereas it is actually an error pointer).

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-23000

больше 3 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-22999

больше 3 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-22998

больше 3 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-22997

больше 3 лет назад

In the Linux kernel before 6.1.2 kernel/module/decompress.c misinterprets the module_get_next_page return value (expects it to be NULL in the error case whereas it is actually an error pointer).

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-22996

больше 3 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2023-22995

больше 3 лет назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2023-22895

больше 3 лет назад

The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of service via a large file that triggers an integer overflow in mem.rs. NOTE: this is unrelated to the https://crates.io/crates/bzip2-rs product.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-22809

11 месяцев назад

In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.

CVSS3: 7.8
EPSS: Средний
msrc логотип

CVE-2023-22795

больше 3 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-22745

больше 3 лет назад

Buffer Overlow in TSS2_RC_Decode in tpm2-tss

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2023-22743

больше 3 лет назад

GitHub: CVE-2023-22743 Git for Windows Installer Elevation of Privilege Vulnerability

EPSS: Низкий
msrc логотип

CVE-2023-22742

около 2 лет назад

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2023-2253

около 3 лет назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-22490

больше 3 лет назад

GitHub: CVE-2023-22490 mingit Information Disclosure Vulnerability

EPSS: Низкий
msrc логотип

CVE-2023-2248

11 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it was the duplicate of CVE-2023-31436.

EPSS: Низкий
msrc логотип

CVE-2023-22466

6 месяцев назад

Tokio's reject_remote_clients configuration may get dropped when creating a Windows named pipe

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2023-23004

In the Linux kernel before 5.19 drivers/gpu/drm/arm/malidp_planes.c misinterprets the get_sg_table return value (expects it to be NULL in the error case whereas it is actually an error pointer).

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-23003

In the Linux kernel before 5.16 tools/perf/util/expr.c lacks a check for the hashmap__new return value.

CVSS3: 4
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-23002

In the Linux kernel before 5.16.3 drivers/bluetooth/hci_qca.c misinterprets the devm_gpiod_get_index_optional return value (expects it to be NULL in the error case whereas it is actually an error pointer).

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-23001

In the Linux kernel before 5.16.3 drivers/scsi/ufs/ufs-mediatek.c misinterprets the regulator_get return value (expects it to be NULL in the error case whereas it is actually an error pointer).

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-22997

In the Linux kernel before 6.1.2 kernel/module/decompress.c misinterprets the module_get_next_page return value (expects it to be NULL in the error case whereas it is actually an error pointer).

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 7.8
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-22895

The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of service via a large file that triggers an integer overflow in mem.rs. NOTE: this is unrelated to the https://crates.io/crates/bzip2-rs product.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-22809

In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.

CVSS3: 7.8
55%
Средний
11 месяцев назад
msrc логотип
CVSS3: 7.5
2%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-22745

Buffer Overlow in TSS2_RC_Decode in tpm2-tss

CVSS3: 6.4
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-22743

GitHub: CVE-2023-22743 Git for Windows Installer Elevation of Privilege Vulnerability

0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 5.9
1%
Низкий
около 2 лет назад
msrc логотип
CVSS3: 6.5
1%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-22490

GitHub: CVE-2023-22490 mingit Information Disclosure Vulnerability

1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2023-2248

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it was the duplicate of CVE-2023-31436.

11 месяцев назад
msrc логотип
CVE-2023-22466

Tokio's reject_remote_clients configuration may get dropped when creating a Windows named pipe

CVSS3: 5.4
1%
Низкий
6 месяцев назад

Уязвимостей на страницу