Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 087

Количество 26 087

msrc логотип

CVE-2022-40320

почти 4 года назад

cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2022-40307

почти 4 года назад

An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free.

CVSS3: 4.7
EPSS: Низкий
msrc логотип

CVE-2022-40304

больше 3 лет назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-40303

больше 3 лет назад

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2022-40284

почти 4 года назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-40133

больше 3 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2022-40023

почти 4 года назад

Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-3996

почти 2 года назад

X.509 Policy Constraints Double Locking

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-39842

почти 4 года назад

An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c the count parameter has a type conflict of size_t versus int causing an integer overflow and bypassing the size check. After that because it is used as the third argument to copy_from_user() a heap overflow may occur. NOTE: the original discoverer disputes that the overflow can actually happen.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2022-3970

больше 3 лет назад

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2022-39410

почти 4 года назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2022-39408

почти 4 года назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2022-39403

почти 4 года назад

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update insert or delete access to some of MySQL Shell accessible data as well as unauthorized read access to a subset of MySQL Shell accessible data. CVSS 3.1 Base Score 3.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).

CVSS3: 3.9
EPSS: Низкий
msrc логотип

CVE-2022-39402

почти 4 года назад

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell. While the vulnerability is in MySQL Shell attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Shell accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2022-39400

почти 4 года назад

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
EPSS: Низкий
msrc логотип

CVE-2022-39379

почти 4 года назад

CVSS3: 9.8
EPSS: Средний
msrc логотип

CVE-2022-39377

больше 3 лет назад

sysstat Incorrect Buffer Size calculation on 32-bit systems results in RCE via buffer overflow

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-39353

6 месяцев назад

xmldom allows multiple root nodes in a DOM

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2022-39348

почти 4 года назад

Twisted vulnerable to NameVirtualHost Host header injection

CVSS3: 5.4
EPSS: Низкий
msrc логотип

CVE-2022-39327

почти 4 года назад

GitHub: CVE-2022-39327 Improper Control of Generation of Code ('Code Injection') in Azure CLI

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2022-40320

cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-40307

An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free.

CVSS3: 4.7
0%
Низкий
почти 4 года назад
msrc логотип
CVSS3: 7.8
7%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 7.5
23%
Средний
больше 3 лет назад
msrc логотип
CVSS3: 7.8
0%
Низкий
почти 4 года назад
msrc логотип
CVSS3: 5.5
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-40023

Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.

CVSS3: 7.5
2%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-3996

X.509 Policy Constraints Double Locking

CVSS3: 7.5
1%
Низкий
почти 2 года назад
msrc логотип
CVE-2022-39842

An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c the count parameter has a type conflict of size_t versus int causing an integer overflow and bypassing the size check. After that because it is used as the third argument to copy_from_user() a heap overflow may occur. NOTE: the original discoverer disputes that the overflow can actually happen.

CVSS3: 6.1
1%
Низкий
почти 4 года назад
msrc логотип
CVSS3: 8.8
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-39410

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 6.5
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-39408

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 6.5
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-39403

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update insert or delete access to some of MySQL Shell accessible data as well as unauthorized read access to a subset of MySQL Shell accessible data. CVSS 3.1 Base Score 3.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).

CVSS3: 3.9
0%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-39402

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell. While the vulnerability is in MySQL Shell attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Shell accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).

CVSS3: 4.3
0%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-39400

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVSS3: 4.9
1%
Низкий
почти 4 года назад
msrc логотип
CVSS3: 9.8
45%
Средний
почти 4 года назад
msrc логотип
CVE-2022-39377

sysstat Incorrect Buffer Size calculation on 32-bit systems results in RCE via buffer overflow

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-39353

xmldom allows multiple root nodes in a DOM

CVSS3: 9.8
1%
Низкий
6 месяцев назад
msrc логотип
CVE-2022-39348

Twisted vulnerable to NameVirtualHost Host header injection

CVSS3: 5.4
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-39327

GitHub: CVE-2022-39327 Improper Control of Generation of Code ('Code Injection') in Azure CLI

3%
Низкий
почти 4 года назад

Уязвимостей на страницу