Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 045

Количество 25 045

msrc логотип

CVE-2020-36229

больше 5 лет назад

A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring resulting in denial of service.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-36228

больше 5 лет назад

An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing resulting in denial of service.

CVSS3: 7.5
EPSS: Высокий
msrc логотип

CVE-2020-36227

больше 5 лет назад

A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation resulting in denial of service.

CVSS3: 7.5
EPSS: Высокий
msrc логотип

CVE-2020-36226

больше 5 лет назад

A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing resulting in denial of service.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-36225

больше 5 лет назад

A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing resulting in denial of service.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-36224

больше 5 лет назад

A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing resulting in denial of service.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-36223

больше 5 лет назад

A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling resulting in denial of service (double free and out-of-bounds read).

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-36222

больше 5 лет назад

A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation resulting in denial of service.

CVSS3: 7.5
EPSS: Высокий
msrc логотип

CVE-2020-36221

больше 5 лет назад

An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).

CVSS3: 7.5
EPSS: Высокий
msrc логотип

CVE-2020-36158

больше 5 лет назад

mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value aka CID-5c455c5ab332.

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2020-35538

почти 4 года назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-35524

больше 5 лет назад

A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality integrity as well as system availability.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2020-35523

больше 5 лет назад

An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this vulnerability is to confidentiality integrity as well as system availability.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2020-35522

больше 5 лет назад

In LibTIFF there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-35521

больше 5 лет назад

A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c a crafted TIFF file can lead to an abort resulting in denial of service.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-35508

больше 5 лет назад

A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.

CVSS3: 4.5
EPSS: Низкий
msrc логотип

CVE-2020-35507

больше 5 лет назад

There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-35506

около 5 лет назад

A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0 during the handling of the 'Information Transfer' command (CMD_TI). This flaw allows a privileged guest user to crash the QEMU process on the host resulting in a denial of service or potential code execution with the privileges of the QEMU process.

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2020-35505

около 5 лет назад

A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileged guest user to crash the QEMU process on the host resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 4.4
EPSS: Низкий
msrc логотип

CVE-2020-35504

10 месяцев назад

A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2020-36229

A flaw was discovered in ldap_X509dn2bv in OpenLDAP before 2.4.57 leading to a slapd crash in the X.509 DN parsing in ad_keystring resulting in denial of service.

CVSS3: 7.5
4%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-36228

An integer underflow was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Certificate List Exact Assertion processing resulting in denial of service.

CVSS3: 7.5
83%
Высокий
больше 5 лет назад
msrc логотип
CVE-2020-36227

A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation resulting in denial of service.

CVSS3: 7.5
78%
Высокий
больше 5 лет назад
msrc логотип
CVE-2020-36226

A flaw was discovered in OpenLDAP before 2.4.57 leading to a memch->bv_len miscalculation and slapd crash in the saslAuthzTo processing resulting in denial of service.

CVSS3: 7.5
4%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-36225

A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing resulting in denial of service.

CVSS3: 7.5
4%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-36224

A flaw was discovered in OpenLDAP before 2.4.57 leading to an invalid pointer free and slapd crash in the saslAuthzTo processing resulting in denial of service.

CVSS3: 7.5
4%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-36223

A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling resulting in denial of service (double free and out-of-bounds read).

CVSS3: 7.5
4%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-36222

A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation resulting in denial of service.

CVSS3: 7.5
78%
Высокий
больше 5 лет назад
msrc логотип
CVE-2020-36221

An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing resulting in denial of service (schema_init.c serialNumberAndIssuerCheck).

CVSS3: 7.5
84%
Высокий
больше 5 лет назад
msrc логотип
CVE-2020-36158

mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value aka CID-5c455c5ab332.

CVSS3: 6.7
2%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
почти 4 года назад
msrc логотип
CVE-2020-35524

A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality integrity as well as system availability.

CVSS3: 7.8
2%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-35523

An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this vulnerability is to confidentiality integrity as well as system availability.

CVSS3: 7.8
2%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-35522

In LibTIFF there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack.

CVSS3: 5.5
2%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-35521

A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c a crafted TIFF file can lead to an abort resulting in denial of service.

CVSS3: 5.5
1%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-35508

A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.

CVSS3: 4.5
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-35507

There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability.

CVSS3: 5.5
1%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-35506

A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0 during the handling of the 'Information Transfer' command (CMD_TI). This flaw allows a privileged guest user to crash the QEMU process on the host resulting in a denial of service or potential code execution with the privileges of the QEMU process.

CVSS3: 6.7
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-35505

A NULL pointer dereference flaw was found in the am53c974 SCSI host bus adapter emulation of QEMU in versions before 6.0.0. This issue occurs while handling the 'Information Transfer' command. This flaw allows a privileged guest user to crash the QEMU process on the host resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 4.4
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-35504

A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 6
0%
Низкий
10 месяцев назад

Уязвимостей на страницу