Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 355

Количество 25 355

msrc логотип

CVE-2021-3738

почти 2 года назад

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2021-3737

больше 4 лет назад

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker who controls the HTTP server to make the client script enter an infinite loop consuming CPU time. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2021-3736

почти 4 года назад

A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in Virtual Function I/O (VFIO) Mediated devices. This flaw could allow a local attacker to leak internal kernel information.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-3733

около 4 лет назад

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2021-3732

больше 4 лет назад

A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local user to gain access to hidden files that should not be accessible.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-37322

больше 4 лет назад

GCC c++filt v2.26 was discovered to contain a use-after-free vulnerability via the component cplus-dem.c.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-3716

10 месяцев назад

A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session. The highest threat from this vulnerability is to system availability.

CVSS3: 3.1
EPSS: Низкий
msrc логотип

CVE-2021-37159

около 5 лет назад

hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state leading to a use-after-free and a double free.

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2021-3713

больше 3 лет назад

CVSS3: 7.4
EPSS: Низкий
msrc логотип

CVE-2021-3712

почти 5 лет назад

CVSS3: 7.4
EPSS: Средний
msrc логотип

CVE-2021-3711

больше 4 лет назад

OpenSSL: CVE-2021-3711 SM2 Decryption Buffer Overflow

EPSS: Высокий
msrc логотип

CVE-2021-3700

больше 4 лет назад

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2021-3698

больше 4 лет назад

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-36980

около 5 лет назад

Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-3697

почти 3 года назад

A crafted JPEG image may lead the JPEG reader to underflow its data pointer allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2021-36976

больше 4 лет назад

Libarchive Remote Code Execution Vulnerability

EPSS: Низкий
msrc логотип

CVE-2021-36975

почти 5 лет назад

Win32k Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-36974

почти 5 лет назад

Windows SMB Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-36973

почти 5 лет назад

Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2021-36972

почти 5 лет назад

Windows SMB Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 8.8
2%
Низкий
почти 2 года назад
msrc логотип
CVE-2021-3737

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker who controls the HTTP server to make the client script enter an infinite loop consuming CPU time. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
12%
Средний
больше 4 лет назад
msrc логотип
CVE-2021-3736

A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in Virtual Function I/O (VFIO) Mediated devices. This flaw could allow a local attacker to leak internal kernel information.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
msrc логотип
CVE-2021-3733

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.

CVSS3: 6.5
5%
Низкий
около 4 лет назад
msrc логотип
CVE-2021-3732

A flaw was found in the Linux kernel's OverlayFS subsystem in the way the user mounts the TmpFS filesystem with OverlayFS. This flaw allows a local user to gain access to hidden files that should not be accessible.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-37322

GCC c++filt v2.26 was discovered to contain a use-after-free vulnerability via the component cplus-dem.c.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-3716

A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session. The highest threat from this vulnerability is to system availability.

CVSS3: 3.1
1%
Низкий
10 месяцев назад
msrc логотип
CVE-2021-37159

hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state leading to a use-after-free and a double free.

CVSS3: 6.4
0%
Низкий
около 5 лет назад
msrc логотип
CVSS3: 7.4
1%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 7.4
50%
Средний
почти 5 лет назад
msrc логотип
CVE-2021-3711

OpenSSL: CVE-2021-3711 SM2 Decryption Buffer Overflow

88%
Высокий
больше 4 лет назад
msrc логотип
CVSS3: 6.4
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-3698

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-36980

Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_decode and ofpacts_decode) during the decoding of a RAW_ENCAP action.

CVSS3: 5.5
1%
Низкий
около 5 лет назад
msrc логотип
CVE-2021-3697

A crafted JPEG image may lead the JPEG reader to underflow its data pointer allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution or secure boot circumvention. This flaw affects grub2 versions prior grub-2.12.

CVSS3: 7
0%
Низкий
почти 3 года назад
msrc логотип
CVE-2021-36976

Libarchive Remote Code Execution Vulnerability

3%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-36975

Win32k Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-36974

Windows SMB Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-36973

Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability

CVSS3: 7.8
0%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-36972

Windows SMB Information Disclosure Vulnerability

CVSS3: 5.5
1%
Низкий
почти 5 лет назад

Уязвимостей на страницу