Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 087

Количество 26 087

msrc логотип

CVE-2022-43945

почти 4 года назад

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2022-4379

больше 3 лет назад

A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-4378

больше 3 лет назад

A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-43750

почти 4 года назад

drivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a user-space client to corrupt the monitor's internal memory.

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2022-43680

6 месяцев назад

In libexpat through 2.4.9 there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-43552

больше 3 лет назад

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET curl would use a heap-allocated struct after it had been freed in its transfer shutdown code path.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2022-43551

6 месяцев назад

A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. However the HSTS mechanism could be bypassed if the host name in the given URL first uses IDN characters that get replaced to ASCII counterparts as part of the IDN conversion. Like using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop (U+002E) `.`. Then in a subsequent request it does not detect the HSTS state and makes a clear text transfer. Because it would store the info IDN encoded but look for it IDN decoded.

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2022-43548

больше 3 лет назад

CVSS3: 8.1
EPSS: Средний
msrc логотип

CVE-2022-4344

больше 3 лет назад

Memory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2022-43410

6 дней назад

Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2022-4338

больше 3 лет назад

An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2022-4337

больше 3 лет назад

An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2022-43358

больше 1 года назад

Stack overflow vulnerability in ast_selectors.cpp: in function Sass::ComplexSelector::has_placeholder in libsass:3.6.5-8-g210218, which can be exploited by attackers to cause a denial of service (DoS).

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-43357

больше 1 года назад

Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-4318

11 месяцев назад

Cri-o: /etc/passwd tampering privesc

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-4304

8 месяцев назад

Timing Oracle in RSA Decryption

CVSS3: 5.9
EPSS: Средний
msrc логотип

CVE-2022-42969

6 дней назад

The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled. Note: This has been disputed by multiple third parties as not being reproduceable and they argue this is not a valid vulnerability.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-42931

11 месяцев назад

Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk. Instead, the username (not password) was saved by the Form Manager to an unencrypted file on disk. This vulnerability affects Firefox < 106.

EPSS: Низкий
msrc логотип

CVE-2022-42919

почти 4 года назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-42916

6 месяцев назад

In curl before 7.86.0 the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be bypassed if the host name in the given URL uses IDN characters that get replaced with ASCII counterparts as part of the IDN conversion e.g. using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop of U+002E (.). The earliest affected version is 7.77.0 2021-05-26.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 7.5
21%
Средний
почти 4 года назад
msrc логотип
CVE-2022-4379

A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial

CVSS3: 7.5
6%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-4378

A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-43750

drivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a user-space client to corrupt the monitor's internal memory.

CVSS3: 6.7
0%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-43680

In libexpat through 2.4.9 there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.

CVSS3: 7.5
2%
Низкий
6 месяцев назад
msrc логотип
CVE-2022-43552

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET curl would use a heap-allocated struct after it had been freed in its transfer shutdown code path.

CVSS3: 5.9
3%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-43551

A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. However the HSTS mechanism could be bypassed if the host name in the given URL first uses IDN characters that get replaced to ASCII counterparts as part of the IDN conversion. Like using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop (U+002E) `.`. Then in a subsequent request it does not detect the HSTS state and makes a clear text transfer. Because it would store the info IDN encoded but look for it IDN decoded.

CVSS3: 7.5
17%
Средний
6 месяцев назад
msrc логотип
CVSS3: 8.1
14%
Средний
больше 3 лет назад
msrc логотип
CVE-2022-4344

Memory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of service via packet injection or crafted capture file

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-43410

Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.

CVSS3: 5.3
1%
Низкий
6 дней назад
msrc логотип
CVE-2022-4338

An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-4337

An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-43358

Stack overflow vulnerability in ast_selectors.cpp: in function Sass::ComplexSelector::has_placeholder in libsass:3.6.5-8-g210218, which can be exploited by attackers to cause a denial of service (DoS).

CVSS3: 7.5
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2022-43357

Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2022-4318

Cri-o: /etc/passwd tampering privesc

CVSS3: 7.8
0%
Низкий
11 месяцев назад
msrc логотип
CVE-2022-4304

Timing Oracle in RSA Decryption

CVSS3: 5.9
16%
Средний
8 месяцев назад
msrc логотип
CVE-2022-42969

The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled. Note: This has been disputed by multiple third parties as not being reproduceable and they argue this is not a valid vulnerability.

CVSS3: 7.5
2%
Низкий
6 дней назад
msrc логотип
CVE-2022-42931

Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk. Instead, the username (not password) was saved by the Form Manager to an unencrypted file on disk. This vulnerability affects Firefox < 106.

0%
Низкий
11 месяцев назад
msrc логотип
CVSS3: 7.8
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-42916

In curl before 7.86.0 the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even when HTTP is provided in the URL. This mechanism could be bypassed if the host name in the given URL uses IDN characters that get replaced with ASCII counterparts as part of the IDN conversion e.g. using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop of U+002E (.). The earliest affected version is 7.77.0 2021-05-26.

CVSS3: 7.5
2%
Низкий
6 месяцев назад

Уязвимостей на страницу