Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 355

Количество 25 355

msrc логотип

CVE-2021-3638

больше 3 лет назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2021-36386

больше 4 лет назад

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-36374

6 месяцев назад

Apache Ant ZIP and ZIP based archive denial of service vulerability

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-36373

6 месяцев назад

Apache Ant TAR archive denial of service vulnerability

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-36370

почти 5 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-3636

больше 2 лет назад

CVSS3: 4.6
EPSS: Низкий
msrc логотип

CVE-2021-36368

больше 4 лет назад

An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose and an attacker has silently modified the server to support the None authentication option then the user cannot determine whether FIDO authentication is going to confirm that the user wishes to connect to that server or that the user wishes to allow that server to connect to a different server on the user's behalf. NOTE: the vendor's position is "this is not an authentication bypass since nothing is being bypassed.

CVSS3: 3.7
EPSS: Низкий
msrc логотип

CVE-2021-3634

10 месяцев назад

A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, both of them are the same, but after key re-exchange, previous session_id is kept and used as an input to new secret_hash. Historically, both of these buffers had shared length variable, which worked as long as these buffers were same. But the key re-exchange operation can also change the key exchange method, which can be based on hash of different size, eventually creating "secret_hash" of different size than the session_id has. This becomes an issue when the session_id memory is zeroed or when it is used again during second key re-exchange.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2021-3631

больше 4 лет назад

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 6.3
EPSS: Низкий
msrc логотип

CVE-2021-36230

больше 4 лет назад

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2021-3622

больше 4 лет назад

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2021-36222

почти 5 лет назад

ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation.

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2021-36221

почти 5 лет назад

Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2021-3620

больше 4 лет назад

A flaw was found in Ansible Engine's ansible-connection module where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2021-3618

больше 4 лет назад

ALPACA is an application layer protocol content confusion attack exploiting TLS servers implementing different protocols but using compatible certificates such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.

CVSS3: 7.4
EPSS: Низкий
msrc логотип

CVE-2021-36160

почти 5 лет назад

mod_proxy_uwsgi out of bound read

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2021-3611

почти 2 года назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2021-3609

больше 4 лет назад

.A flaw was found in the CAN BCM networking protocol in the Linux kernel where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2021-3608

больше 4 лет назад

CVSS3: 6
EPSS: Низкий
msrc логотип

CVE-2021-3607

больше 4 лет назад

CVSS3: 6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 6.5
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2021-36386

report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument which might allow mail servers to cause a denial of service or possibly have unspecified other impact via long error messages. NOTE: it is unclear whether use of Fetchmail on any realistic platform results in an impact beyond an inconvenience to the client user.

CVSS3: 7.5
3%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-36374

Apache Ant ZIP and ZIP based archive denial of service vulerability

CVSS3: 5.5
3%
Низкий
6 месяцев назад
msrc логотип
CVE-2021-36373

Apache Ant TAR archive denial of service vulnerability

CVSS3: 5.5
3%
Низкий
6 месяцев назад
msrc логотип
CVSS3: 7.5
2%
Низкий
почти 5 лет назад
msrc логотип
CVSS3: 4.6
0%
Низкий
больше 2 лет назад
msrc логотип
CVE-2021-36368

An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose and an attacker has silently modified the server to support the None authentication option then the user cannot determine whether FIDO authentication is going to confirm that the user wishes to connect to that server or that the user wishes to allow that server to connect to a different server on the user's behalf. NOTE: the vendor's position is "this is not an authentication bypass since nothing is being bypassed.

CVSS3: 3.7
2%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-3634

A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, both of them are the same, but after key re-exchange, previous session_id is kept and used as an input to new secret_hash. Historically, both of these buffers had shared length variable, which worked as long as these buffers were same. But the key re-exchange operation can also change the key exchange method, which can be based on hash of different size, eventually creating "secret_hash" of different size than the session_id has. This becomes an issue when the session_id memory is zeroed or when it is used again during second key re-exchange.

CVSS3: 6.5
5%
Низкий
10 месяцев назад
msrc логотип
CVE-2021-3631

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 6.3
0%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 8.8
1%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 4.3
5%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-36222

ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference and daemon crash. This occurs because a return value is not properly managed in a certain situation.

CVSS3: 7.5
10%
Средний
почти 5 лет назад
msrc логотип
CVE-2021-36221

Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.

CVSS3: 5.9
3%
Низкий
почти 5 лет назад
msrc логотип
CVE-2021-3620

A flaw was found in Ansible Engine's ansible-connection module where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-3618

ALPACA is an application layer protocol content confusion attack exploiting TLS servers implementing different protocols but using compatible certificates such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to another resulting in a valid TLS session. This breaks the authentication of TLS and cross-protocol attacks may be possible where the behavior of one protocol service may compromise the other at the application layer.

CVSS3: 7.4
2%
Низкий
больше 4 лет назад
msrc логотип
CVE-2021-36160

mod_proxy_uwsgi out of bound read

CVSS3: 7.5
63%
Средний
почти 5 лет назад
msrc логотип
CVSS3: 6.5
0%
Низкий
почти 2 года назад
msrc логотип
CVE-2021-3609

.A flaw was found in the CAN BCM networking protocol in the Linux kernel where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.

CVSS3: 7
0%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 6
0%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 6
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу