Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 045

Количество 25 045

msrc логотип

CVE-2020-4040

10 месяцев назад

CSRF issue on preview pages in Bolt CMS

CVSS3: 8.6
EPSS: Низкий
msrc логотип

CVE-2020-36478

6 месяцев назад

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.

EPSS: Низкий
msrc логотип

CVE-2020-36477

6 месяцев назад

An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certificate name is mishandled: when the subjecAltName extension is present, the expected name is compared to any name in that extension regardless of its type. This means that an attacker could impersonate a 4-byte or 16-byte domain by getting a certificate for the corresponding IPv4 or IPv6 address (this would require the attacker to control that IP address, though).

EPSS: Низкий
msrc логотип

CVE-2020-36476

11 месяцев назад

An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.

EPSS: Низкий
msrc логотип

CVE-2020-36475

6 месяцев назад

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs.

EPSS: Низкий
msrc логотип

CVE-2020-36426

11 месяцев назад

An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte).

EPSS: Низкий
msrc логотип

CVE-2020-36425

11 месяцев назад

An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.

EPSS: Низкий
msrc логотип

CVE-2020-36424

6 месяцев назад

An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.

EPSS: Низкий
msrc логотип

CVE-2020-36422

11 месяцев назад

An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbedtls_ecp_mul_restartable.

EPSS: Низкий
msrc логотип

CVE-2020-36332

около 5 лет назад

A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-36331

около 5 лет назад

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2020-36330

около 5 лет назад

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2020-36329

около 5 лет назад

A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2020-36328

около 5 лет назад

A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2020-36325

больше 4 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-36323

больше 5 лет назад

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2020-36318

больше 5 лет назад

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2020-36317

больше 5 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-36242

больше 5 лет назад

In the cryptography package before 3.3.2 for Python certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow as demonstrated by the Fernet class.

CVSS3: 9.1
EPSS: Низкий
msrc логотип

CVE-2020-36230

больше 5 лет назад

A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element resulting in denial of service.

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2020-4040

CSRF issue on preview pages in Bolt CMS

CVSS3: 8.6
2%
Низкий
10 месяцев назад
msrc логотип
CVE-2020-36478

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameters do not match in any way, then the certificate should be considered invalid.

1%
Низкий
6 месяцев назад
msrc логотип
CVE-2020-36477

An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certificate name is mishandled: when the subjecAltName extension is present, the expected name is compared to any name in that extension regardless of its type. This means that an attacker could impersonate a 4-byte or 16-byte domain by getting a certificate for the corresponding IPv4 or IPv6 address (this would require the attacker to control that IP address, though).

1%
Низкий
6 месяцев назад
msrc логотип
CVE-2020-36476

An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.

2%
Низкий
11 месяцев назад
msrc логотип
CVE-2020-36475

An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs.

2%
Низкий
6 месяцев назад
msrc логотип
CVE-2020-36426

An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte).

2%
Низкий
11 месяцев назад
msrc логотип
CVE-2020-36425

An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.

1%
Низкий
11 месяцев назад
msrc логотип
CVE-2020-36424

An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.

0%
Низкий
6 месяцев назад
msrc логотип
CVE-2020-36422

An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbedtls_ecp_mul_restartable.

1%
Низкий
11 месяцев назад
msrc логотип
CVE-2020-36332

A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.

CVSS3: 7.5
2%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-36331

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.

CVSS3: 9.1
2%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-36330

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.

CVSS3: 9.1
2%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-36329

A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 9.8
2%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-36328

A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 9.8
3%
Низкий
около 5 лет назад
msrc логотип
CVSS3: 7.5
2%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 8.2
2%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 9.8
2%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 7.5
2%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-36242

In the cryptography package before 3.3.2 for Python certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow as demonstrated by the Fernet class.

CVSS3: 9.1
7%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-36230

A flaw was discovered in OpenLDAP before 2.4.57 leading in an assertion failure in slapd in the X.509 DN parsing in decode.c ber_next_element resulting in denial of service.

CVSS3: 7.5
12%
Средний
больше 5 лет назад

Уязвимостей на страницу