Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 17 673

Количество 17 673

github логотип

GHSA-7399-wc2p-9q6p

больше 4 лет назад

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.

EPSS: Средний
github логотип

GHSA-68r6-xqmg-xhxx

больше 4 лет назад

Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket.

EPSS: Низкий
github логотип

GHSA-64x6-q8pq-xjmg

больше 4 лет назад

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-3f8j-8ww3-q7v6

больше 4 лет назад

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2684-x557-ppqj

больше 4 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability.

EPSS: Низкий
oracle-oval логотип

ELSA-2016-2824

почти 10 лет назад

ELSA-2016-2824: expat security update (MODERATE)

EPSS: Средний
oracle-oval логотип

ELSA-2014-1307

почти 12 лет назад

ELSA-2014-1307: nss security update (IMPORTANT)

EPSS: Средний
oracle-oval логотип

ELSA-2013-1804

почти 13 лет назад

ELSA-2013-1804: libjpeg security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2023-5217

почти 3 года назад

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Средний
redhat логотип

CVE-2023-5217

почти 3 года назад

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Средний
nvd логотип

CVE-2023-5217

почти 3 года назад

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Средний
debian логотип

CVE-2023-5217

почти 3 года назад

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior ...

CVSS3: 8.8
EPSS: Средний
ubuntu логотип

CVE-2016-7153

около 10 лет назад

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
EPSS: Средний
redhat логотип

CVE-2016-7153

около 10 лет назад

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 3.1
EPSS: Средний
nvd логотип

CVE-2016-7153

около 10 лет назад

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
EPSS: Средний
debian логотип

CVE-2016-7153

около 10 лет назад

The HTTP/2 protocol does not consider the role of the TCP congestion w ...

CVSS3: 5.3
EPSS: Средний
ubuntu логотип

CVE-2016-7152

около 10 лет назад

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
EPSS: Средний
redhat логотип

CVE-2016-7152

около 10 лет назад

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 3.1
EPSS: Средний
nvd логотип

CVE-2016-7152

около 10 лет назад

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
EPSS: Средний
debian логотип

CVE-2016-7152

около 10 лет назад

The HTTPS protocol does not consider the role of the TCP congestion wi ...

CVSS3: 5.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-7399-wc2p-9q6p

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.

17%
Средний
больше 4 лет назад
github логотип
GHSA-68r6-xqmg-xhxx

Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-64x6-q8pq-xjmg

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
16%
Средний
больше 4 лет назад
github логотип
GHSA-3f8j-8ww3-q7v6

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.

CVSS3: 9.8
13%
Средний
больше 4 лет назад
github логотип
GHSA-2684-x557-ppqj

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability.

8%
Низкий
больше 4 лет назад
oracle-oval логотип
ELSA-2016-2824

ELSA-2016-2824: expat security update (MODERATE)

13%
Средний
почти 10 лет назад
oracle-oval логотип
ELSA-2014-1307

ELSA-2014-1307: nss security update (IMPORTANT)

17%
Средний
почти 12 лет назад
oracle-oval логотип
ELSA-2013-1804

ELSA-2013-1804: libjpeg security update (MODERATE)

10%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2023-5217

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
49%
Средний
почти 3 года назад
redhat логотип
CVE-2023-5217

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
49%
Средний
почти 3 года назад
nvd логотип
CVE-2023-5217

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
49%
Средний
почти 3 года назад
debian логотип
CVE-2023-5217

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior ...

CVSS3: 8.8
49%
Средний
почти 3 года назад
ubuntu логотип
CVE-2016-7153

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
16%
Средний
около 10 лет назад
redhat логотип
CVE-2016-7153

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 3.1
16%
Средний
около 10 лет назад
nvd логотип
CVE-2016-7153

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
16%
Средний
около 10 лет назад
debian логотип
CVE-2016-7153

The HTTP/2 protocol does not consider the role of the TCP congestion w ...

CVSS3: 5.3
16%
Средний
около 10 лет назад
ubuntu логотип
CVE-2016-7152

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
16%
Средний
около 10 лет назад
redhat логотип
CVE-2016-7152

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 3.1
16%
Средний
около 10 лет назад
nvd логотип
CVE-2016-7152

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
16%
Средний
около 10 лет назад
debian логотип
CVE-2016-7152

The HTTPS protocol does not consider the role of the TCP congestion wi ...

CVSS3: 5.3
16%
Средний
около 10 лет назад

Уязвимостей на страницу