Логотип exploitDog
source:"msrc"
Консоль
Логотип exploitDog

exploitDog

source:"msrc"

Количество 18 520

Количество 18 520

msrc логотип

CVE-2012-2653

3 месяца назад

arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon.

EPSS: Низкий
msrc логотип

CVE-2012-0883

4 месяца назад

envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.

EPSS: Низкий
msrc логотип

CVE-2011-5244

3 месяца назад

Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, different vulnerabilities than CVE-2010-2642 and CVE-2011-0433.

EPSS: Низкий
msrc логотип

CVE-2011-4969

4 месяца назад

Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.

EPSS: Низкий
msrc логотип

CVE-2011-4966

3 месяца назад

modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.

EPSS: Низкий
msrc логотип

CVE-2011-3048

4 месяца назад

The png_set_text_2 function in pngset.c in libpng 1.0.x before 1.0.59, 1.2.x before 1.2.49, 1.4.x before 1.4.11, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted text chunk in a PNG image file, which triggers a memory allocation failure that is not properly handled, leading to a heap-based buffer overflow.

EPSS: Средний
msrc логотип

CVE-2011-3045

6 месяцев назад

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2011-2691

8 месяцев назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2011-2519

около 5 лет назад

EPSS: Низкий
msrc логотип

CVE-2011-2501

8 месяцев назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2011-1429

3 месяца назад

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

EPSS: Низкий
msrc логотип

CVE-2011-10034

около 1 месяца назад

IRAI AUTOMGEN <= 8.0.0.7 Use-After-Free Remote DoS

EPSS: Низкий
msrc логотип

CVE-2011-0640

около 5 лет назад

The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB which allows user-assisted attackers to execute arbitrary programs via crafted USB data as demonstrated by keyboard and mouse data sent by malware on a smartphone that the user connected to the computer.

EPSS: Низкий
msrc логотип

CVE-2011-0433

3 месяца назад

Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different vulnerability than CVE-2010-2642.

EPSS: Низкий
msrc логотип

CVE-2010-4756

4 месяца назад

The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.

EPSS: Низкий
msrc логотип

CVE-2010-4563

около 5 лет назад

The Linux kernel when using IPv6 allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent as demonstrated by thcping.

EPSS: Низкий
msrc логотип

CVE-2010-4226

4 месяца назад

cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.

CVSS3: 7.2
EPSS: Низкий
msrc логотип

CVE-2010-3865

около 5 лет назад

EPSS: Низкий
msrc логотип

CVE-2010-3190

около 7 лет назад

MFC Insecure Library Loading Vulnerability

EPSS: Средний
msrc логотип

CVE-2010-2891

около 4 лет назад

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2012-2653

arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon.

2%
Низкий
3 месяца назад
msrc логотип
CVE-2012-0883

envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.

0%
Низкий
4 месяца назад
msrc логотип
CVE-2011-5244

Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, different vulnerabilities than CVE-2010-2642 and CVE-2011-0433.

2%
Низкий
3 месяца назад
msrc логотип
CVE-2011-4969

Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.

4%
Низкий
4 месяца назад
msrc логотип
CVE-2011-4966

modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.

1%
Низкий
3 месяца назад
msrc логотип
CVE-2011-3048

The png_set_text_2 function in pngset.c in libpng 1.0.x before 1.0.59, 1.2.x before 1.2.49, 1.4.x before 1.4.11, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted text chunk in a PNG image file, which triggers a memory allocation failure that is not properly handled, leading to a heap-based buffer overflow.

17%
Средний
4 месяца назад
msrc логотип
CVSS3: 8.8
8%
Низкий
6 месяцев назад
msrc логотип
CVSS3: 6.5
6%
Низкий
8 месяцев назад
msrc логотип
0%
Низкий
около 5 лет назад
msrc логотип
CVSS3: 6.5
1%
Низкий
8 месяцев назад
msrc логотип
CVE-2011-1429

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

1%
Низкий
3 месяца назад
msrc логотип
CVE-2011-10034

IRAI AUTOMGEN <= 8.0.0.7 Use-After-Free Remote DoS

1%
Низкий
около 1 месяца назад
msrc логотип
CVE-2011-0640

The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB which allows user-assisted attackers to execute arbitrary programs via crafted USB data as demonstrated by keyboard and mouse data sent by malware on a smartphone that the user connected to the computer.

0%
Низкий
около 5 лет назад
msrc логотип
CVE-2011-0433

Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different vulnerability than CVE-2010-2642.

2%
Низкий
3 месяца назад
msrc логотип
CVE-2010-4756

The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.

0%
Низкий
4 месяца назад
msrc логотип
CVE-2010-4563

The Linux kernel when using IPv6 allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent as demonstrated by thcping.

0%
Низкий
около 5 лет назад
msrc логотип
CVE-2010-4226

cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.

CVSS3: 7.2
1%
Низкий
4 месяца назад
msrc логотип
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2010-3190

MFC Insecure Library Loading Vulnerability

47%
Средний
около 7 лет назад
msrc логотип
33%
Средний
около 4 лет назад

Уязвимостей на страницу