Логотип exploitDog
source:"msrc"
Консоль
Логотип exploitDog

exploitDog

source:"msrc"

Количество 19 414

Количество 19 414

msrc логотип

CVE-2011-2519

больше 5 лет назад

EPSS: Низкий
msrc логотип

CVE-2011-2501

11 месяцев назад

The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a CVE-2004-0421 regression. NOTE: this is called an off-by-one error by some sources.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2011-1429

6 месяцев назад

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

EPSS: Низкий
msrc логотип

CVE-2011-10034

4 месяца назад

IRAI AUTOMGEN <= 8.0.0.7 Use-After-Free Remote DoS

EPSS: Низкий
msrc логотип

CVE-2011-0640

больше 5 лет назад

The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB which allows user-assisted attackers to execute arbitrary programs via crafted USB data as demonstrated by keyboard and mouse data sent by malware on a smartphone that the user connected to the computer.

EPSS: Низкий
msrc логотип

CVE-2011-0433

6 месяцев назад

Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different vulnerability than CVE-2010-2642.

EPSS: Низкий
msrc логотип

CVE-2010-4756

7 месяцев назад

The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.

EPSS: Низкий
msrc логотип

CVE-2010-4563

около 1 месяца назад

The Linux kernel when using IPv6 allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent as demonstrated by thcping.

EPSS: Низкий
msrc логотип

CVE-2010-4226

7 месяцев назад

cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.

CVSS3: 7.2
EPSS: Низкий
msrc логотип

CVE-2010-3865

больше 5 лет назад

EPSS: Низкий
msrc логотип

CVE-2010-3190

больше 7 лет назад

MFC Insecure Library Loading Vulnerability

EPSS: Средний
msrc логотип

CVE-2010-2891

больше 4 лет назад

EPSS: Средний
msrc логотип

CVE-2010-2642

6 месяцев назад

Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.

EPSS: Средний
msrc логотип

CVE-2010-2542

больше 5 лет назад

EPSS: Низкий
msrc логотип

CVE-2010-2249

7 месяцев назад

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2010-0309

больше 5 лет назад

The pit_ioport_read function in the Programmable Interval Timer (PIT) emulation in i8254.c in KVM 83 does not properly use the pit_state data structure which allows guest OS users to cause a denial of service (host OS crash or hang) by attempting to read the /dev/port file.

EPSS: Низкий
msrc логотип

CVE-2010-0298

около 1 месяца назад

The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) in determining the memory access available to CPL3 code which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region a related issue to CVE-2010-0306.

EPSS: Низкий
msrc логотип

CVE-2010-0291

около 1 месяца назад

The Linux kernel before 2.6.32.4 allows local users to gain privileges or cause a denial of service (panic) by calling the (1) mmap or (2) mremap function, aka the "do_mremap() mess" or "mremap/mmap mess."

EPSS: Низкий
msrc логотип

CVE-2009-5063

7 месяцев назад

Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a JPEG image containing an iCCP chunk with a negative embedded profile length. NOTE: this is due to an incomplete fix for CVE-2006-7244.

EPSS: Низкий
msrc логотип

CVE-2009-4487

больше 5 лет назад

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2011-2501

The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a CVE-2004-0421 regression. NOTE: this is called an off-by-one error by some sources.

CVSS3: 6.5
2%
Низкий
11 месяцев назад
msrc логотип
CVE-2011-1429

Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.

0%
Низкий
6 месяцев назад
msrc логотип
CVE-2011-10034

IRAI AUTOMGEN <= 8.0.0.7 Use-After-Free Remote DoS

1%
Низкий
4 месяца назад
msrc логотип
CVE-2011-0640

The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB which allows user-assisted attackers to execute arbitrary programs via crafted USB data as demonstrated by keyboard and mouse data sent by malware on a smartphone that the user connected to the computer.

0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2011-0433

Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different vulnerability than CVE-2010-2642.

2%
Низкий
6 месяцев назад
msrc логотип
CVE-2010-4756

The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.

0%
Низкий
7 месяцев назад
msrc логотип
CVE-2010-4563

The Linux kernel when using IPv6 allows remote attackers to determine whether a host is sniffing the network by sending an ICMPv6 Echo Request to a multicast address and determining whether an Echo Reply is sent as demonstrated by thcping.

0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2010-4226

cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.

CVSS3: 7.2
0%
Низкий
7 месяцев назад
msrc логотип
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2010-3190

MFC Insecure Library Loading Vulnerability

47%
Средний
больше 7 лет назад
msrc логотип
33%
Средний
больше 4 лет назад
msrc логотип
CVE-2010-2642

Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.

13%
Средний
6 месяцев назад
msrc логотип
2%
Низкий
больше 5 лет назад
msrc логотип
CVE-2010-2249

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.

CVSS3: 6.5
2%
Низкий
7 месяцев назад
msrc логотип
CVE-2010-0309

The pit_ioport_read function in the Programmable Interval Timer (PIT) emulation in i8254.c in KVM 83 does not properly use the pit_state data structure which allows guest OS users to cause a denial of service (host OS crash or hang) by attempting to read the /dev/port file.

1%
Низкий
больше 5 лет назад
msrc логотип
CVE-2010-0298

The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) in determining the memory access available to CPL3 code which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region a related issue to CVE-2010-0306.

1%
Низкий
около 1 месяца назад
msrc логотип
CVE-2010-0291

The Linux kernel before 2.6.32.4 allows local users to gain privileges or cause a denial of service (panic) by calling the (1) mmap or (2) mremap function, aka the "do_mremap() mess" or "mremap/mmap mess."

0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2009-5063

Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a JPEG image containing an iCCP chunk with a negative embedded profile length. NOTE: this is due to an incomplete fix for CVE-2006-7244.

0%
Низкий
7 месяцев назад
msrc логотип
2%
Низкий
больше 5 лет назад

Уязвимостей на страницу