Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 379

Количество 25 379

msrc логотип

CVE-2022-24122

больше 4 лет назад

kernel/ucount.c in the Linux kernel 5.14 through 5.16.4 when unprivileged user namespaces are enabled allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-24070

больше 4 лет назад

Apache Subversion mod_dav_svn is vulnerable to memory corruption

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-24052

больше 4 лет назад

MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16190.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-24051

больше 4 лет назад

MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16193.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-24050

больше 4 лет назад

MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16207.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-24048

больше 4 лет назад

MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16191.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-23990

больше 4 лет назад

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-23960

почти 4 года назад

Arm: CVE-2022-23960 Cache Speculation Restriction Vulnerability

EPSS: Низкий
msrc логотип

CVE-2022-23943

больше 4 лет назад

mod_sed: Read/write beyond bounds

CVSS3: 9.8
EPSS: Средний
msrc логотип

CVE-2022-23901

больше 1 года назад

A stack overflow re2c 2.2 exists due to infinite recursion issues in src/dfa/dead_rules.cc.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2022-23852

больше 4 лет назад

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer for configurations with a nonzero XML_CONTEXT_BYTES.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2022-23825

около 4 лет назад

AMD: CVE-2022-23825 AMD CPU Branch Type Confusion

EPSS: Низкий
msrc логотип

CVE-2022-23824

почти 4 года назад

AMD: CVE-2022-23824 IBPB and Return Address Predictor Interactions

EPSS: Низкий
msrc логотип

CVE-2022-23816

около 4 лет назад

AMD: CVE-2022-23816 AMD CPU Branch Type Confusion

EPSS: Низкий
msrc логотип

CVE-2022-2380

около 4 лет назад

The Linux kernel was found vulnerable out of bounds memory access in the drivers/video/fbdev/sm712fb.c:smtcfb_read() function. The vulnerability could result in local attackers being able to crash the kernel.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2022-23806

больше 4 лет назад

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2022-23773

больше 4 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-23772

больше 4 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-23712

около 4 лет назад

A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-23648

больше 4 лет назад

Insecure handling of image volumes in containerd CRI plugin

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2022-24122

kernel/ucount.c in the Linux kernel 5.14 through 5.16.4 when unprivileged user namespaces are enabled allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2022-24070

Apache Subversion mod_dav_svn is vulnerable to memory corruption

CVSS3: 7.5
9%
Низкий
больше 4 лет назад
msrc логотип
CVE-2022-24052

MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16190.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2022-24051

MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of a user-supplied string before using it as a format specifier. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16193.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2022-24050

MariaDB CONNECT Storage Engine Use-After-Free Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16207.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2022-24048

MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account. Was ZDI-CAN-16191.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2022-23990

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

CVSS3: 7.5
4%
Низкий
больше 4 лет назад
msrc логотип
CVE-2022-23960

Arm: CVE-2022-23960 Cache Speculation Restriction Vulnerability

0%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-23943

mod_sed: Read/write beyond bounds

CVSS3: 9.8
50%
Средний
больше 4 лет назад
msrc логотип
CVE-2022-23901

A stack overflow re2c 2.2 exists due to infinite recursion issues in src/dfa/dead_rules.cc.

CVSS3: 9.8
2%
Низкий
больше 1 года назад
msrc логотип
CVE-2022-23852

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer for configurations with a nonzero XML_CONTEXT_BYTES.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
msrc логотип
CVE-2022-23825

AMD: CVE-2022-23825 AMD CPU Branch Type Confusion

1%
Низкий
около 4 лет назад
msrc логотип
CVE-2022-23824

AMD: CVE-2022-23824 IBPB and Return Address Predictor Interactions

1%
Низкий
почти 4 года назад
msrc логотип
CVE-2022-23816

AMD: CVE-2022-23816 AMD CPU Branch Type Confusion

около 4 лет назад
msrc логотип
CVE-2022-2380

The Linux kernel was found vulnerable out of bounds memory access in the drivers/video/fbdev/sm712fb.c:smtcfb_read() function. The vulnerability could result in local attackers being able to crash the kernel.

CVSS3: 5.5
0%
Низкий
около 4 лет назад
msrc логотип
CVSS3: 9.1
3%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 7.5
3%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 7.5
3%
Низкий
больше 4 лет назад
msrc логотип
CVE-2022-23712

A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.

CVSS3: 7.5
8%
Низкий
около 4 лет назад
msrc логотип
CVE-2022-23648

Insecure handling of image volumes in containerd CRI plugin

CVSS3: 7.5
27%
Средний
больше 4 лет назад

Уязвимостей на страницу