Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 045

Количество 25 045

msrc логотип

CVE-2020-28374

больше 5 лет назад

In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7 insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request aka CID-2896c93811e3. For example an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2020-28367

больше 5 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-28366

больше 5 лет назад

Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-28362

больше 5 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-28200

больше 4 лет назад

The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption as demonstrated by a situation with a complex regular expression for the regex extension.

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2020-28196

почти 5 лет назад

MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-28163

6 месяцев назад

libdwarf before 20201201 allows a dwarf_print_lines.c NULL pointer dereference and application crash via a DWARF5 line-table header that has an invalid FORM for a pathname.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2020-2801

10 месяцев назад

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. Note: The patch for this issue will address the vulnerability only if the WLS instance is using JDK 1.7.0_191 or later, or JDK 1.8.0_181 or later. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2020-27845

около 2 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-27844

больше 5 лет назад

Chromium CVE-2020-27844: Heap buffer overflow in OpenJPEG

EPSS: Низкий
msrc логотип

CVE-2020-27843

около 2 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-27842

около 2 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-27841

около 2 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-27840

почти 2 года назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-27827

больше 5 лет назад

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-27824

около 2 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-27823

около 2 лет назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2020-27821

больше 5 лет назад

A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.

CVSS3: 6
EPSS: Низкий
msrc логотип

CVE-2020-27815

6 месяцев назад

A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality integrity as well as system availability.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2020-27814

около 2 лет назад

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2020-28374

In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7 insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request aka CID-2896c93811e3. For example an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.

CVSS3: 8.1
6%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 7.5
2%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-28366

Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo

CVSS3: 7.5
2%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 7.5
4%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-28200

The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption as demonstrated by a situation with a complex regular expression for the regex extension.

CVSS3: 4.3
2%
Низкий
больше 4 лет назад
msrc логотип
CVE-2020-28196

MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.

CVSS3: 7.5
4%
Низкий
почти 5 лет назад
msrc логотип
CVE-2020-28163

libdwarf before 20201201 allows a dwarf_print_lines.c NULL pointer dereference and application crash via a DWARF5 line-table header that has an invalid FORM for a pathname.

CVSS3: 6.5
1%
Низкий
6 месяцев назад
msrc логотип
CVE-2020-2801

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. Note: The patch for this issue will address the vulnerability only if the WLS instance is using JDK 1.7.0_191 or later, or JDK 1.8.0_181 or later. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 9.8
3%
Низкий
10 месяцев назад
msrc логотип
CVSS3: 5.5
1%
Низкий
около 2 лет назад
msrc логотип
CVE-2020-27844

Chromium CVE-2020-27844: Heap buffer overflow in OpenJPEG

1%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 5.5
2%
Низкий
около 2 лет назад
msrc логотип
CVSS3: 5.5
1%
Низкий
около 2 лет назад
msrc логотип
CVSS3: 5.5
1%
Низкий
около 2 лет назад
msrc логотип
CVSS3: 7.5
4%
Низкий
почти 2 года назад
msrc логотип
CVE-2020-27827

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
3%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 5.5
2%
Низкий
около 2 лет назад
msrc логотип
CVSS3: 7.8
1%
Низкий
около 2 лет назад
msrc логотип
CVE-2020-27821

A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MMIO operations. A guest user may abuse this flaw to crash the QEMU process on the host resulting in a denial of service. This flaw affects QEMU versions prior to 5.2.0.

CVSS3: 6
0%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-27815

A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality integrity as well as system availability.

CVSS3: 7.8
1%
Низкий
6 месяцев назад
msrc логотип
CVSS3: 7.8
2%
Низкий
около 2 лет назад

Уязвимостей на страницу