Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 356

Количество 25 356

msrc логотип

CVE-2021-42782

больше 4 лет назад

Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2021-42781

больше 4 лет назад

Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2021-42780

больше 4 лет назад

A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2021-42779

больше 4 лет назад

A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2021-42778

больше 4 лет назад

A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2021-42771

почти 5 лет назад

Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal leading to code execution.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-42739

почти 5 лет назад

The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c because avc_ca_pmt mishandles bounds checking.

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2021-42523

почти 4 года назад

There are two Information Disclosure vulnerabilities in colord and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use while libxml2 emphasizes that the caller needs to release it.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-4238

6 месяцев назад

Insufficient randomness in github.com/Masterminds/goutils

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2021-42386

больше 4 лет назад

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function

CVSS3: 7.2
EPSS: Низкий
msrc логотип

CVE-2021-42385

больше 4 лет назад

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function

CVSS3: 7.2
EPSS: Низкий
msrc логотип

CVE-2021-42384

больше 4 лет назад

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the handle_special function

CVSS3: 7.2
EPSS: Низкий
msrc логотип

CVE-2021-42382

больше 4 лет назад

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function

CVSS3: 7.2
EPSS: Низкий
msrc логотип

CVE-2021-42381

больше 4 лет назад

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the hash_init function

CVSS3: 7.2
EPSS: Низкий
msrc логотип

CVE-2021-42380

больше 4 лет назад

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar function

CVSS3: 7.2
EPSS: Низкий
msrc логотип

CVE-2021-42379

больше 4 лет назад

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the next_input_file function

CVSS3: 7.2
EPSS: Низкий
msrc логотип

CVE-2021-42378

больше 4 лет назад

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_i function

CVSS3: 7.2
EPSS: Низкий
msrc логотип

CVE-2021-42376

больше 4 лет назад

A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-42374

больше 4 лет назад

An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2021-4235

больше 3 лет назад

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2021-42782

Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.

CVSS3: 5.3
3%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-42781

Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.

CVSS3: 5.3
3%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-42780

A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-42779

A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-42778

A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-42771

Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal leading to code execution.

CVSS3: 7.8
1%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-42739

The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c because avc_ca_pmt mishandles bounds checking.

CVSS3: 6.7
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-42523

There are two Information Disclosure vulnerabilities in colord and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the 'err_msg' of 'sqlite3_exec' is not releasing after use while libxml2 emphasizes that the caller needs to release it.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
msrc логотип
CVE-2021-4238

Insufficient randomness in github.com/Masterminds/goutils

CVSS3: 9.1
1%
Низкий
6 месяцев назад
msrc логотип
CVE-2021-42386

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function

CVSS3: 7.2
3%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-42385

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function

CVSS3: 7.2
3%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-42384

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the handle_special function

CVSS3: 7.2
3%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-42382

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function

CVSS3: 7.2
3%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-42381

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the hash_init function

CVSS3: 7.2
3%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-42380

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar function

CVSS3: 7.2
3%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-42379

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the next_input_file function

CVSS3: 7.2
3%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-42378

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_i function

CVSS3: 7.2
3%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-42376

A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-42374

An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу