Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 045

Количество 25 045

msrc логотип

CVE-2020-26570

больше 4 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-26558

больше 4 лет назад

CVSS3: 4.2
EPSS: Низкий
msrc логотип

CVE-2020-26541

почти 6 лет назад

The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protection mechanism. This affects certs/blacklist.c and certs/system_keyring.c.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2020-26160

почти 2 года назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-26159

10 месяцев назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Further investigation showed that it was not a security issue. Notes: none

EPSS: Низкий
msrc логотип

CVE-2020-26154

больше 4 лет назад

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2020-26144

около 5 лет назад

Windows Wireless Networking Spoofing Vulnerability

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2020-26137

больше 5 лет назад

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2020-26116

больше 5 лет назад

http.client in Python 3.x before 3.5.10 3.6.x before 3.6.12 3.7.x before 3.7.9 and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.

CVSS3: 7.2
EPSS: Низкий
msrc логотип

CVE-2020-26088

почти 6 лет назад

A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets bypassing security mechanisms aka CID-26896f01467a.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-25796

почти 6 лет назад

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the InlineArray implementation an unaligned reference may be generated for a type that has a large alignment requirement.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-25795

почти 6 лет назад

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation insert_from can have a memory-safety issue upon a panic.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-25794

почти 6 лет назад

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation clone can have a memory-safety issue upon a panic.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-25793

почти 6 лет назад

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation the array size is not checked when constructed with From<InlineArray<A T>>.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-25792

почти 6 лет назад

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation the array size is not checked when constructed with pair().

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-25791

почти 6 лет назад

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation the array size is not checked when constructed with unit().

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2020-25743

почти 6 лет назад

hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.

CVSS3: 3.2
EPSS: Низкий
msrc логотип

CVE-2020-25742

почти 6 лет назад

pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.

CVSS3: 3.2
EPSS: Низкий
msrc логотип

CVE-2020-25723

больше 5 лет назад

A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse this flaw to send bogus USB requests and crash the QEMU process on the host resulting in a denial of service.

CVSS3: 3.2
EPSS: Низкий
msrc логотип

CVE-2020-25722

почти 2 года назад

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 5.5
0%
Низкий
больше 4 лет назад
msrc логотип
CVSS3: 4.2
1%
Низкий
больше 4 лет назад
msrc логотип
CVE-2020-26541

The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protection mechanism. This affects certs/blacklist.c and certs/system_keyring.c.

CVSS3: 6.5
1%
Низкий
почти 6 лет назад
msrc логотип
CVSS3: 7.5
2%
Низкий
почти 2 года назад
msrc логотип
CVE-2020-26159

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Further investigation showed that it was not a security issue. Notes: none

10 месяцев назад
msrc логотип
CVSS3: 9.8
4%
Низкий
больше 4 лет назад
msrc логотип
CVE-2020-26144

Windows Wireless Networking Spoofing Vulnerability

CVSS3: 6.5
5%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-26137

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.

CVSS3: 6.5
2%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-26116

http.client in Python 3.x before 3.5.10 3.6.x before 3.6.12 3.7.x before 3.7.9 and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.

CVSS3: 7.2
6%
Низкий
больше 5 лет назад
msrc логотип
CVE-2020-26088

A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets bypassing security mechanisms aka CID-26896f01467a.

CVSS3: 5.5
0%
Низкий
почти 6 лет назад
msrc логотип
CVE-2020-25796

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the InlineArray implementation an unaligned reference may be generated for a type that has a large alignment requirement.

CVSS3: 7.5
2%
Низкий
почти 6 лет назад
msrc логотип
CVE-2020-25795

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation insert_from can have a memory-safety issue upon a panic.

CVSS3: 7.5
2%
Низкий
почти 6 лет назад
msrc логотип
CVE-2020-25794

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation clone can have a memory-safety issue upon a panic.

CVSS3: 7.5
2%
Низкий
почти 6 лет назад
msrc логотип
CVE-2020-25793

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation the array size is not checked when constructed with From<InlineArray<A T>>.

CVSS3: 7.5
2%
Низкий
почти 6 лет назад
msrc логотип
CVE-2020-25792

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation the array size is not checked when constructed with pair().

CVSS3: 7.5
3%
Низкий
почти 6 лет назад
msrc логотип
CVE-2020-25791

An issue was discovered in the sized-chunks crate through 0.6.2 for Rust. In the Chunk implementation the array size is not checked when constructed with unit().

CVSS3: 7.5
2%
Низкий
почти 6 лет назад
msrc логотип
CVE-2020-25743

hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.

CVSS3: 3.2
0%
Низкий
почти 6 лет назад
msrc логотип
CVE-2020-25742

pci_change_irq_level in hw/pci/pci.c in QEMU before 5.1.1 has a NULL pointer dereference because pci_get_bus() might not return a valid pointer.

CVSS3: 3.2
0%
Низкий
почти 6 лет назад
msrc логотип
CVE-2020-25723

A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged user within the guest may abuse this flaw to send bogus USB requests and crash the QEMU process on the host resulting in a denial of service.

CVSS3: 3.2
0%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 8.8
2%
Низкий
почти 2 года назад

Уязвимостей на страницу