Логотип exploitDog
source:"msrc"
Консоль
Логотип exploitDog

exploitDog

source:"msrc"

Количество 18 824

Количество 18 824

msrc логотип

CVE-2018-8114

почти 8 лет назад

Scripting Engine Memory Corruption Vulnerability

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2018-8113

больше 7 лет назад

Internet Explorer Security Feature Bypass Vulnerability

CVSS3: 4.3
EPSS: Средний
msrc логотип

CVE-2018-8112

почти 8 лет назад

Microsoft Edge Security Feature Bypass Vulnerability

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2018-8111

больше 7 лет назад

Microsoft Edge Memory Corruption Vulnerability

CVSS3: 4.2
EPSS: Средний
msrc логотип

CVE-2018-8110

больше 7 лет назад

Microsoft Edge Memory Corruption Vulnerability

CVSS3: 4.2
EPSS: Средний
msrc логотип

CVE-2018-7263

11 месяцев назад

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2018-7167

больше 4 лет назад

Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron") 8.x (LTS "Carbon") and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2018-7164

больше 4 лет назад

Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2018-7162

больше 4 лет назад

All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2018-7161

больше 4 лет назад

All versions of Node.js 8.x 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2018-7159

2 месяца назад

The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in the `Content-Length` value and the Node.js HTTP parser has been brought into line on this particular difference. The security risk of this flaw to Node.js users is considered to be VERY LOW as it is difficult, and may be impossible, to craft an attack that makes use of this flaw in a way that could not already be achieved by supplying an incorrect value for `Content-Length`. Vulnerabilities may exist in user-code that make incorrect assumptions about the potential accuracy of this value compared to the actual length of the data supplied. Node.js users crafting lower-level HTTP utilities are advised to re-check the length of any input supplied after parsing is complete.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2018-6952

больше 5 лет назад

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2018-6951

больше 5 лет назад

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2018-5996

около 4 лет назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2018-25091

5 месяцев назад

urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).

EPSS: Низкий
msrc логотип

CVE-2018-25078

4 месяца назад

man-db before 2.8.5 on Gentoo allows local users (with access to the man user account) to gain root privileges because /usr/bin/mandb is executed by root but not owned by root. (Also, the owner can strip the setuid and setgid bits.)

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2018-25032

почти 4 года назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2018-25014

больше 4 лет назад

A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2018-25013

больше 4 лет назад

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2018-25012

больше 4 лет назад

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2018-8114

Scripting Engine Memory Corruption Vulnerability

CVSS3: 7.5
18%
Средний
почти 8 лет назад
msrc логотип
CVE-2018-8113

Internet Explorer Security Feature Bypass Vulnerability

CVSS3: 4.3
21%
Средний
больше 7 лет назад
msrc логотип
CVE-2018-8112

Microsoft Edge Security Feature Bypass Vulnerability

CVSS3: 4.3
2%
Низкий
почти 8 лет назад
msrc логотип
CVE-2018-8111

Microsoft Edge Memory Corruption Vulnerability

CVSS3: 4.2
32%
Средний
больше 7 лет назад
msrc логотип
CVE-2018-8110

Microsoft Edge Memory Corruption Vulnerability

CVSS3: 4.2
32%
Средний
больше 7 лет назад
msrc логотип
CVSS3: 9.8
1%
Низкий
11 месяцев назад
msrc логотип
CVE-2018-7167

Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS "Boron") 8.x (LTS "Carbon") and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2018-7164

Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of data in short succession. This vulnerability was restored by reverting to the prior behaviour.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2018-7162

All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
msrc логотип
CVE-2018-7161

All versions of Node.js 8.x 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used in native code after they are no longer available. This has been addressed by updating the http2 implementation.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2018-7159

The HTTP parser in all current versions of Node.js ignores spaces in the `Content-Length` header, allowing input such as `Content-Length: 1 2` to be interpreted as having a value of `12`. The HTTP specification does not allow for spaces in the `Content-Length` value and the Node.js HTTP parser has been brought into line on this particular difference. The security risk of this flaw to Node.js users is considered to be VERY LOW as it is difficult, and may be impossible, to craft an attack that makes use of this flaw in a way that could not already be achieved by supplying an incorrect value for `Content-Length`. Vulnerabilities may exist in user-code that make incorrect assumptions about the potential accuracy of this value compared to the actual length of the data supplied. Node.js users crafting lower-level HTTP utilities are advised to re-check the length of any input supplied after parsing is complete.

CVSS3: 5.3
1%
Низкий
2 месяца назад
msrc логотип
CVSS3: 7.5
12%
Средний
больше 5 лет назад
msrc логотип
CVSS3: 7.5
14%
Средний
больше 5 лет назад
msrc логотип
CVSS3: 7.8
4%
Низкий
около 4 лет назад
msrc логотип
CVE-2018-25091

urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).

0%
Низкий
5 месяцев назад
msrc логотип
CVE-2018-25078

man-db before 2.8.5 on Gentoo allows local users (with access to the man user account) to gain root privileges because /usr/bin/mandb is executed by root but not owned by root. (Also, the owner can strip the setuid and setgid bits.)

CVSS3: 7.8
0%
Низкий
4 месяца назад
msrc логотип
CVSS3: 7.5
0%
Низкий
почти 4 года назад
msrc логотип
CVE-2018-25014

A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2018-25013

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().

CVSS3: 9.1
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2018-25012

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().

CVSS3: 9.1
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу