Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 087

Количество 26 087

msrc логотип

CVE-2022-46175

почти 2 года назад

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2022-46174

7 дней назад

Race condition during concurrent TLS mounts in efs-utils

EPSS: Низкий
msrc логотип

CVE-2022-46146

почти 2 года назад

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2022-4603

около 1 года назад

ppp pppdump pppdump.c dumpppp array index

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2022-45939

больше 3 лет назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-45934

больше 3 лет назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-45919

больше 3 лет назад

An issue was discovered in the Linux kernel through 6.0.10. In drivers/media/dvb-core/dvb_ca_en50221.c a use-after-free can occur is there is a disconnect after an open because of the lack of a wait_event.

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2022-45888

больше 3 лет назад

An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use-after-free during physical removal of a USB device.

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2022-45887

больше 3 лет назад

An issue was discovered in the Linux kernel through 6.0.9. drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak because of the lack of a dvb_frontend_detach call.

CVSS3: 4.7
EPSS: Низкий
msrc логотип

CVE-2022-45886

больше 3 лет назад

An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_net.c has a .disconnect versus dvb_device_open race condition that leads to a use-after-free.

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2022-45885

11 месяцев назад

An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition that can cause a use-after-free when a device is disconnected.

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2022-45884

больше 3 лет назад

An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free related to dvb_register_device dynamically allocating fops.

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2022-45873

больше 3 лет назад

systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2022-45869

больше 3 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2022-45639

11 месяцев назад

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-4543

11 месяцев назад

A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2022-45419

11 месяцев назад

If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and then deleted the exception, Firefox would have kept the connection alive, making it seem like the certificate was still trusted. This vulnerability affects Firefox < 107.

EPSS: Низкий
msrc логотип

CVE-2022-45417

11 месяцев назад

Service Workers did not detect Private Browsing Mode correctly in all cases, which could have led to Service Workers being written to disk for websites visited in Private Browsing Mode. This would not have persisted them in a state where they would run again, but it would have leaked Private Browsing Mode details to disk. This vulnerability affects Firefox < 107.

EPSS: Низкий
msrc логотип

CVE-2022-45410

11 месяцев назад

When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

EPSS: Низкий
msrc логотип

CVE-2022-45380

11 месяцев назад

Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in an unsafe manner, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 8.8
9%
Низкий
почти 2 года назад
msrc логотип
CVE-2022-46174

Race condition during concurrent TLS mounts in efs-utils

1%
Низкий
7 дней назад
msrc логотип
CVSS3: 8.8
1%
Низкий
почти 2 года назад
msrc логотип
CVE-2022-4603

ppp pppdump pppdump.c dumpppp array index

CVSS3: 4.3
1%
Низкий
около 1 года назад
msrc логотип
CVSS3: 7.8
1%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 7.8
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-45919

An issue was discovered in the Linux kernel through 6.0.10. In drivers/media/dvb-core/dvb_ca_en50221.c a use-after-free can occur is there is a disconnect after an open because of the lack of a wait_event.

CVSS3: 7
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-45888

An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use-after-free during physical removal of a USB device.

CVSS3: 6.4
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-45887

An issue was discovered in the Linux kernel through 6.0.9. drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak because of the lack of a dvb_frontend_detach call.

CVSS3: 4.7
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-45886

An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_net.c has a .disconnect versus dvb_device_open race condition that leads to a use-after-free.

CVSS3: 7
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-45885

An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition that can cause a use-after-free when a device is disconnected.

CVSS3: 7
0%
Низкий
11 месяцев назад
msrc логотип
CVE-2022-45884

An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free related to dvb_register_device dynamically allocating fops.

CVSS3: 7
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-45873

systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-45639

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.

CVSS3: 7.8
5%
Низкий
11 месяцев назад
msrc логотип
CVE-2022-4543

A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.

CVSS3: 5.5
1%
Низкий
11 месяцев назад
msrc логотип
CVE-2022-45419

If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and then deleted the exception, Firefox would have kept the connection alive, making it seem like the certificate was still trusted. This vulnerability affects Firefox < 107.

0%
Низкий
11 месяцев назад
msrc логотип
CVE-2022-45417

Service Workers did not detect Private Browsing Mode correctly in all cases, which could have led to Service Workers being written to disk for websites visited in Private Browsing Mode. This would not have persisted them in a state where they would run again, but it would have leaked Private Browsing Mode details to disk. This vulnerability affects Firefox < 107.

0%
Низкий
11 месяцев назад
msrc логотип
CVE-2022-45410

When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

1%
Низкий
11 месяцев назад
msrc логотип
CVE-2022-45380

Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in an unsafe manner, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

CVSS3: 5.4
1%
Низкий
11 месяцев назад

Уязвимостей на страницу