Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25 045

Количество 25 045

msrc логотип

CVE-2020-10733

почти 6 лет назад

The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights.

CVSS3: 7.3
EPSS: Низкий
msrc логотип

CVE-2020-1072

около 6 лет назад

Windows Kernel Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-10724

11 месяцев назад

A vulnerability was found in DPDK versions 18.11 and above

CVSS3: 5.1
EPSS: Низкий
msrc логотип

CVE-2020-10723

11 месяцев назад

A memory corruption issue was found in DPDK versions 17.05 and above

CVSS3: 5.1
EPSS: Низкий
msrc логотип

CVE-2020-10722

11 месяцев назад

A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.

CVSS3: 5.1
EPSS: Низкий
msrc логотип

CVE-2020-1071

около 6 лет назад

Windows Remote Access Common Dialog Elevation of Privilege Vulnerability

CVSS3: 6.8
EPSS: Низкий
msrc логотип

CVE-2020-10713

почти 6 лет назад

A flaw was found in grub2 prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an untrusted or modified kernel an attacker would first need to establish access to the system such as gaining physical access obtain the ability to alter a pxe-boot network or have remote access to a networked system with root access. With this access an attacker could then craft a string to cause a buffer overflow by injecting a malicious payload that leads to arbitrary code execution within GRUB. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2020-10711

почти 6 лет назад

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2020-1070

около 6 лет назад

Windows Print Spooler Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2020-10702

почти 6 лет назад

A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw to bypass PAuth protection for all programs running on QEMU.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2020-10701

около 5 лет назад

A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set this flaw can make guest agent commands fail because the agent cannot respond in time. Unprivileged users with a read-only connection could abuse this flaw to set the response timeout for all guest agent messages to zero potentially leading to a denial of service. This flaw affects libvirt versions before 6.2.0.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2020-1069

около 6 лет назад

Microsoft SharePoint Server Remote Code Execution Vulnerability

EPSS: Низкий
msrc логотип

CVE-2020-10690

почти 6 лет назад

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2020-1068

около 6 лет назад

Microsoft Windows Elevation of Privilege Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2020-1067

около 6 лет назад

Windows Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2020-1066

около 6 лет назад

.NET Framework Elevation of Privilege Vulnerability

EPSS: Низкий
msrc логотип

CVE-2020-1065

около 6 лет назад

Scripting Engine Memory Corruption Vulnerability

CVSS3: 4.2
EPSS: Низкий
msrc логотип

CVE-2020-1064

около 6 лет назад

MSHTML Engine Remote Code Execution Vulnerability

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2020-1063

около 6 лет назад

Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability

EPSS: Низкий
msrc логотип

CVE-2020-1062

около 6 лет назад

Internet Explorer Memory Corruption Vulnerability

CVSS3: 6.4
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2020-10733

The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights.

CVSS3: 7.3
1%
Низкий
почти 6 лет назад
msrc логотип
CVE-2020-1072

Windows Kernel Information Disclosure Vulnerability

CVSS3: 5.5
1%
Низкий
около 6 лет назад
msrc логотип
CVE-2020-10724

A vulnerability was found in DPDK versions 18.11 and above

CVSS3: 5.1
0%
Низкий
11 месяцев назад
msrc логотип
CVE-2020-10723

A memory corruption issue was found in DPDK versions 17.05 and above

CVSS3: 5.1
0%
Низкий
11 месяцев назад
msrc логотип
CVE-2020-10722

A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.

CVSS3: 5.1
0%
Низкий
11 месяцев назад
msrc логотип
CVE-2020-1071

Windows Remote Access Common Dialog Elevation of Privilege Vulnerability

CVSS3: 6.8
1%
Низкий
около 6 лет назад
msrc логотип
CVE-2020-10713

A flaw was found in grub2 prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an untrusted or modified kernel an attacker would first need to establish access to the system such as gaining physical access obtain the ability to alter a pxe-boot network or have remote access to a networked system with root access. With this access an attacker could then craft a string to cause a buffer overflow by injecting a malicious payload that leads to arbitrary code execution within GRUB. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS3: 8.2
1%
Низкий
почти 6 лет назад
msrc логотип
CVSS3: 5.9
3%
Низкий
почти 6 лет назад
msrc логотип
CVE-2020-1070

Windows Print Spooler Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
около 6 лет назад
msrc логотип
CVE-2020-10702

A flaw was found in QEMU in the implementation of the Pointer Authentication (PAuth) support for ARM introduced in version 4.0 and fixed in version 5.0.0. A general failure of the signature generation process caused every PAuth-enforced pointer to be signed with the same signature. A local attacker could obtain the signature of a protected pointer and abuse this flaw to bypass PAuth protection for all programs running on QEMU.

CVSS3: 5.5
0%
Низкий
почти 6 лет назад
msrc логотип
CVE-2020-10701

A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set this flaw can make guest agent commands fail because the agent cannot respond in time. Unprivileged users with a read-only connection could abuse this flaw to set the response timeout for all guest agent messages to zero potentially leading to a denial of service. This flaw affects libvirt versions before 6.2.0.

CVSS3: 6.5
1%
Низкий
около 5 лет назад
msrc логотип
CVE-2020-1069

Microsoft SharePoint Server Remote Code Execution Vulnerability

10%
Низкий
около 6 лет назад
msrc логотип
CVSS3: 6.4
0%
Низкий
почти 6 лет назад
msrc логотип
CVE-2020-1068

Microsoft Windows Elevation of Privilege Vulnerability

CVSS3: 7.8
1%
Низкий
около 6 лет назад
msrc логотип
CVE-2020-1067

Windows Remote Code Execution Vulnerability

CVSS3: 7.8
9%
Низкий
около 6 лет назад
msrc логотип
CVE-2020-1066

.NET Framework Elevation of Privilege Vulnerability

2%
Низкий
около 6 лет назад
msrc логотип
CVE-2020-1065

Scripting Engine Memory Corruption Vulnerability

CVSS3: 4.2
8%
Низкий
около 6 лет назад
msrc логотип
CVE-2020-1064

MSHTML Engine Remote Code Execution Vulnerability

CVSS3: 6.4
7%
Низкий
около 6 лет назад
msrc логотип
CVE-2020-1063

Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability

1%
Низкий
около 6 лет назад
msrc логотип
CVE-2020-1062

Internet Explorer Memory Corruption Vulnerability

CVSS3: 6.4
14%
Средний
около 6 лет назад

Уязвимостей на страницу