Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 56 222

Количество 56 222

redhat логотип

CVE-2024-32621

больше 2 лет назад

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.

EPSS: Низкий
redhat логотип

CVE-2024-32620

больше 2 лет назад

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.

EPSS: Низкий
redhat логотип

CVE-2024-32619

больше 2 лет назад

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.

EPSS: Низкий
redhat логотип

CVE-2024-32618

больше 2 лет назад

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c, resulting in the corruption of the instruction pointer.

EPSS: Низкий
redhat логотип

CVE-2024-32617

больше 2 лет назад

HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).

EPSS: Низкий
redhat логотип

CVE-2024-32616

больше 2 лет назад

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c.

EPSS: Низкий
redhat логотип

CVE-2024-32615

больше 2 лет назад

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused by the earlier use of an initialized pointer.

EPSS: Низкий
redhat логотип

CVE-2024-32614

больше 2 лет назад

HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.

EPSS: Низкий
redhat логотип

CVE-2024-32613

больше 2 лет назад

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerability than CVE-2024-32612.

EPSS: Низкий
redhat логотип

CVE-2024-32612

больше 2 лет назад

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c, resulting in the corruption of the instruction pointer, a different vulnerability than CVE-2024-32613.

EPSS: Низкий
redhat логотип

CVE-2024-32611

больше 2 лет назад

HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.

EPSS: Низкий
redhat логотип

CVE-2024-32610

больше 2 лет назад

HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer.

EPSS: Низкий
redhat логотип

CVE-2024-32609

больше 2 лет назад

HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c.

EPSS: Низкий
redhat логотип

CVE-2024-32608

больше 2 лет назад

HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2024-32607

больше 2 лет назад

HDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c, resulting in the corruption of the instruction pointer.

EPSS: Низкий
redhat логотип

CVE-2024-32606

больше 2 лет назад

HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).

EPSS: Низкий
redhat логотип

CVE-2024-32605

больше 2 лет назад

HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).

EPSS: Низкий
redhat логотип

CVE-2024-32498

около 2 лет назад

An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2024-3248

больше 2 лет назад

In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow.

CVSS3: 2.9
EPSS: Низкий
redhat логотип

CVE-2024-32487

больше 2 лет назад

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-32621

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.

1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32620

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.

0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32619

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.

0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32618

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c, resulting in the corruption of the instruction pointer.

0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32617

HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).

1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32616

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c.

0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32615

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused by the earlier use of an initialized pointer.

1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32614

HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.

1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32613

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerability than CVE-2024-32612.

0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32612

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c, resulting in the corruption of the instruction pointer, a different vulnerability than CVE-2024-32613.

0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32611

HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.

1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32610

HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer.

0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32609

HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c.

1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32608

HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

CVSS3: 4.8
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32607

HDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c, resulting in the corruption of the instruction pointer.

0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32606

HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).

0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32605

HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).

1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32498

An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
redhat логотип
CVE-2024-3248

In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow.

CVSS3: 2.9
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-32487

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment variable, but this is set by default in many common cases.

CVSS3: 8.6
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу