Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 24 178

Количество 24 178

msrc логотип

CVE-2013-4342

больше 3 лет назад

EPSS: Низкий
msrc логотип

CVE-2013-3900

больше 4 лет назад

WinVerifyTrust Signature Validation Vulnerability

EPSS: Средний
msrc логотип

CVE-2013-2094

больше 2 лет назад

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type which allows local users to gain privileges via a crafted perf_event_open system call.

CVSS3: 8.4
EPSS: Средний
msrc логотип

CVE-2013-1633

около 1 месяца назад

easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

EPSS: Низкий
msrc логотип

CVE-2013-0340

больше 4 лет назад

expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function which allows remote attackers to cause a denial of service (resource consumption) send HTTP requests to intranet servers or read arbitrary files via a crafted XML document aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion the responsibility for resolving this issue lies with application developers; according to this argument this entry should be REJECTed and each affected application would need its own CVE.

EPSS: Средний
msrc логотип

CVE-2013-0223

почти 6 лет назад

EPSS: Низкий
msrc логотип

CVE-2013-0222

почти 6 лет назад

EPSS: Низкий
msrc логотип

CVE-2013-0221

почти 6 лет назад

EPSS: Низкий
msrc логотип

CVE-2012-6708

почти 2 года назад

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2012-6687

почти 6 лет назад

EPSS: Низкий
msrc логотип

CVE-2012-6655

больше 1 года назад

An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.

CVSS3: 3.3
EPSS: Низкий
msrc логотип

CVE-2012-5627

почти 6 лет назад

Oracle MySQL and MariaDB 5.5.x before 5.5.29 5.3.x before 5.3.12 and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.

EPSS: Средний
msrc логотип

CVE-2012-4575

почти 6 лет назад

EPSS: Низкий
msrc логотип

CVE-2012-3425

больше 1 года назад

The png_push_read_zTXt function allows remote attackers to cause a denial of service

EPSS: Низкий
msrc логотип

CVE-2012-3381

10 месяцев назад

sfcb in sblim-sfcb places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

EPSS: Низкий
msrc логотип

CVE-2012-2677

больше 1 года назад

EPSS: Низкий
msrc логотип

CVE-2012-2653

10 месяцев назад

arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon.

EPSS: Низкий
msrc логотип

CVE-2012-0883

5 месяцев назад

envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.

EPSS: Низкий
msrc логотип

CVE-2011-5244

10 месяцев назад

Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, different vulnerabilities than CVE-2010-2642 and CVE-2011-0433.

EPSS: Низкий
msrc логотип

CVE-2011-4969

11 месяцев назад

Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
6%
Низкий
больше 3 лет назад
msrc логотип
CVE-2013-3900

WinVerifyTrust Signature Validation Vulnerability

45%
Средний
больше 4 лет назад
msrc логотип
CVE-2013-2094

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type which allows local users to gain privileges via a crafted perf_event_open system call.

CVSS3: 8.4
48%
Средний
больше 2 лет назад
msrc логотип
CVE-2013-1633

easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

2%
Низкий
около 1 месяца назад
msrc логотип
CVE-2013-0340

expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function which allows remote attackers to cause a denial of service (resource consumption) send HTTP requests to intranet servers or read arbitrary files via a crafted XML document aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion the responsibility for resolving this issue lies with application developers; according to this argument this entry should be REJECTed and each affected application would need its own CVE.

20%
Средний
больше 4 лет назад
msrc логотип
1%
Низкий
почти 6 лет назад
msrc логотип
0%
Низкий
почти 6 лет назад
msrc логотип
7%
Низкий
почти 6 лет назад
msrc логотип
CVSS3: 6.1
9%
Низкий
почти 2 года назад
msrc логотип
6%
Низкий
почти 6 лет назад
msrc логотип
CVE-2012-6655

An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.

CVSS3: 3.3
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2012-5627

Oracle MySQL and MariaDB 5.5.x before 5.5.29 5.3.x before 5.3.12 and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.

11%
Средний
почти 6 лет назад
msrc логотип
2%
Низкий
почти 6 лет назад
msrc логотип
CVE-2012-3425

The png_push_read_zTXt function allows remote attackers to cause a denial of service

3%
Низкий
больше 1 года назад
msrc логотип
CVE-2012-3381

sfcb in sblim-sfcb places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

0%
Низкий
10 месяцев назад
msrc логотип
4%
Низкий
больше 1 года назад
msrc логотип
CVE-2012-2653

arpwatch 2.1a15, as used by Red Hat, Debian, Fedora, and possibly others, does not properly drop supplementary groups, which might allow attackers to gain root privileges by leveraging other vulnerabilities in the daemon.

3%
Низкий
10 месяцев назад
msrc логотип
CVE-2012-0883

envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.

1%
Низкий
5 месяцев назад
msrc логотип
CVE-2011-5244

Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, different vulnerabilities than CVE-2010-2642 and CVE-2011-0433.

3%
Низкий
10 месяцев назад
msrc логотип
CVE-2011-4969

Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.

19%
Средний
11 месяцев назад

Уязвимостей на страницу