Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 24 658

Количество 24 658

msrc логотип

CVE-2018-20346

около 2 лет назад

SQLite before 3.25.3 when the FTS3 extension is enabled encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases) aka Magellan.

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2018-20225

10 месяцев назад

An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2018-20169

больше 2 лет назад

An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.

CVSS3: 6.8
EPSS: Низкий
msrc логотип

CVE-2018-1999024

11 месяцев назад

MathJax version prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability

CVSS3: 5.4
EPSS: Низкий
msrc логотип

CVE-2018-1999023

около 2 лет назад

The Battle for Wesnoth Project contains a Code Injection that can result in code execution outside the sandbox

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2018-19876

почти 6 лет назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2018-19827

8 месяцев назад

In LibSass 3.5.5, a use-after-free vulnerability exists in the SharedPtr class in SharedPtr.cpp (or SharedPtr.hpp) that may cause a denial of service (application crash) or possibly have unspecified other impact.

EPSS: Низкий
msrc логотип

CVE-2018-19797

8 месяцев назад

In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Selector_List::populate_extends in SharedPtr.hpp (used by ast.cpp and ast_selectors.cpp) may cause a Denial of Service (application crash) via a crafted sass input file.

EPSS: Низкий
msrc логотип

CVE-2018-19787

около 5 лет назад

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2018-19758

больше 5 лет назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2018-19665

почти 6 лет назад

CVSS3: 5.7
EPSS: Низкий
msrc логотип

CVE-2018-19662

больше 5 лет назад

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2018-19661

больше 5 лет назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2018-19591

почти 6 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2018-19432

больше 5 лет назад

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2018-19416

11 месяцев назад

An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a memmove call, as demonstrated by sadf.

EPSS: Низкий
msrc логотип

CVE-2018-18384

почти 6 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2018-17828

больше 4 лет назад

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2018-16880

почти 6 лет назад

A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest under specific conditions can trigger an out-of-bounds write in a kmalloc-8 slab on a virtual host which may lead to a kernel memory corruption and a system panic. Due to the nature of the flaw privilege escalation cannot be fully ruled out. Versions from v4.16 and newer are vulnerable.

CVSS3: 7
EPSS: Низкий
msrc логотип

CVE-2018-16866

почти 6 лет назад

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2018-20346

SQLite before 3.25.3 when the FTS3 extension is enabled encounters an integer overflow (and resultant buffer overflow) for FTS3 queries that occur after crafted changes to FTS3 shadow tables allowing remote attackers to execute arbitrary code by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases) aka Magellan.

CVSS3: 8.1
10%
Низкий
около 2 лет назад
msrc логотип
CVE-2018-20225

An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely

CVSS3: 7.8
2%
Низкий
10 месяцев назад
msrc логотип
CVE-2018-20169

An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.

CVSS3: 6.8
1%
Низкий
больше 2 лет назад
msrc логотип
CVE-2018-1999024

MathJax version prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability

CVSS3: 5.4
1%
Низкий
11 месяцев назад
msrc логотип
CVE-2018-1999023

The Battle for Wesnoth Project contains a Code Injection that can result in code execution outside the sandbox

CVSS3: 8.8
2%
Низкий
около 2 лет назад
msrc логотип
CVSS3: 6.5
2%
Низкий
почти 6 лет назад
msrc логотип
CVE-2018-19827

In LibSass 3.5.5, a use-after-free vulnerability exists in the SharedPtr class in SharedPtr.cpp (or SharedPtr.hpp) that may cause a denial of service (application crash) or possibly have unspecified other impact.

2%
Низкий
8 месяцев назад
msrc логотип
CVE-2018-19797

In LibSass 3.5.5, a NULL Pointer Dereference in the function Sass::Selector_List::populate_extends in SharedPtr.hpp (used by ast.cpp and ast_selectors.cpp) may cause a Denial of Service (application crash) via a crafted sass input file.

2%
Низкий
8 месяцев назад
msrc логотип
CVSS3: 6.1
2%
Низкий
около 5 лет назад
msrc логотип
CVSS3: 6.5
2%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 5.7
1%
Низкий
почти 6 лет назад
msrc логотип
CVSS3: 8.1
2%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 6.5
2%
Низкий
больше 5 лет назад
msrc логотип
CVSS3: 7.5
6%
Низкий
почти 6 лет назад
msrc логотип
CVSS3: 6.5
3%
Низкий
больше 5 лет назад
msrc логотип
CVE-2018-19416

An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a memmove call, as demonstrated by sadf.

2%
Низкий
11 месяцев назад
msrc логотип
CVSS3: 5.5
3%
Низкий
почти 6 лет назад
msrc логотип
CVSS3: 5.5
2%
Низкий
больше 4 лет назад
msrc логотип
CVE-2018-16880

A flaw was found in the Linux kernel's handle_rx() function in the [vhost_net] driver. A malicious virtual guest under specific conditions can trigger an out-of-bounds write in a kmalloc-8 slab on a virtual host which may lead to a kernel memory corruption and a system panic. Due to the nature of the flaw privilege escalation cannot be fully ruled out. Versions from v4.16 and newer are vulnerable.

CVSS3: 7
1%
Низкий
почти 6 лет назад
msrc логотип
CVSS3: 3.3
1%
Низкий
почти 6 лет назад

Уязвимостей на страницу