Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 24 374

Количество 24 374

msrc логотип

CVE-2014-5282

около 5 лет назад

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2014-5278

около 5 лет назад

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2014-5277

около 5 лет назад

EPSS: Низкий
msrc логотип

CVE-2014-4607

11 месяцев назад

Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.

EPSS: Низкий
msrc логотип

CVE-2014-3618

больше 4 лет назад

EPSS: Низкий
msrc логотип

CVE-2014-3185

5 месяцев назад

Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat.c in the Whiteheat USB Serial Driver in the Linux kernel before 3.16.2 allow physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with a bulk response.

EPSS: Низкий
msrc логотип

CVE-2014-10402

11 месяцев назад

An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2014-0069

больше 2 лет назад

The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes which allows local users to obtain sensitive information from kernel memory cause a denial of service (memory corruption and system crash) or possibly gain privileges via a writev system call with a crafted pointer.

EPSS: Низкий
msrc логотип

CVE-2014-0048

около 5 лет назад

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2014-0047

около 5 лет назад

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2013-7381

10 месяцев назад

libnotify before 1.0.4 for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in a call to libnotify.notify.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2013-6629

больше 9 лет назад

libjpeg Information Disclosure Vulnerability

CVSS3: 4.7
EPSS: Средний
msrc логотип

CVE-2013-6418

11 месяцев назад

PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.

EPSS: Низкий
msrc логотип

CVE-2013-6381

больше 2 лет назад

Buffer overflow in the qeth_snmp_command function in drivers/s390/net/qeth_core_main.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service or possibly have unspecified other impact via an SNMP ioctl call with a length value that is incompatible with the command-buffer size.

EPSS: Низкий
msrc логотип

CVE-2013-4420

почти 6 лет назад

EPSS: Низкий
msrc логотип

CVE-2013-4416

11 месяцев назад

The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdown) via a large message reply.

EPSS: Низкий
msrc логотип

CVE-2013-4342

больше 3 лет назад

xinetd does not enforce the user and group configuration directives for TCPMUX services which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.

EPSS: Низкий
msrc логотип

CVE-2013-3900

больше 4 лет назад

WinVerifyTrust Signature Validation Vulnerability

EPSS: Средний
msrc логотип

CVE-2013-2094

больше 2 лет назад

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type which allows local users to gain privileges via a crafted perf_event_open system call.

CVSS3: 8.4
EPSS: Средний
msrc логотип

CVE-2013-1633

около 1 месяца назад

easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVSS3: 8.1
1%
Низкий
около 5 лет назад
msrc логотип
CVSS3: 5.3
2%
Низкий
около 5 лет назад
msrc логотип
2%
Низкий
около 5 лет назад
msrc логотип
CVE-2014-4607

Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.

5%
Низкий
11 месяцев назад
msrc логотип
9%
Низкий
больше 4 лет назад
msrc логотип
CVE-2014-3185

Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat.c in the Whiteheat USB Serial Driver in the Linux kernel before 3.16.2 allow physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with a bulk response.

1%
Низкий
5 месяцев назад
msrc логотип
CVE-2014-10402

An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.

CVSS3: 6.1
0%
Низкий
11 месяцев назад
msrc логотип
CVE-2014-0069

The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes which allows local users to obtain sensitive information from kernel memory cause a denial of service (memory corruption and system crash) or possibly gain privileges via a writev system call with a crafted pointer.

0%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 9.8
7%
Низкий
около 5 лет назад
msrc логотип
CVSS3: 7.8
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2013-7381

libnotify before 1.0.4 for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in a call to libnotify.notify.

CVSS3: 9.8
3%
Низкий
10 месяцев назад
msrc логотип
CVE-2013-6629

libjpeg Information Disclosure Vulnerability

CVSS3: 4.7
10%
Средний
больше 9 лет назад
msrc логотип
CVE-2013-6418

PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.

2%
Низкий
11 месяцев назад
msrc логотип
CVE-2013-6381

Buffer overflow in the qeth_snmp_command function in drivers/s390/net/qeth_core_main.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service or possibly have unspecified other impact via an SNMP ioctl call with a length value that is incompatible with the command-buffer size.

1%
Низкий
больше 2 лет назад
msrc логотип
3%
Низкий
почти 6 лет назад
msrc логотип
CVE-2013-4416

The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdown) via a large message reply.

1%
Низкий
11 месяцев назад
msrc логотип
CVE-2013-4342

xinetd does not enforce the user and group configuration directives for TCPMUX services which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.

6%
Низкий
больше 3 лет назад
msrc логотип
CVE-2013-3900

WinVerifyTrust Signature Validation Vulnerability

45%
Средний
больше 4 лет назад
msrc логотип
CVE-2013-2094

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type which allows local users to gain privileges via a crafted perf_event_open system call.

CVSS3: 8.4
48%
Средний
больше 2 лет назад
msrc логотип
CVE-2013-1633

easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

2%
Низкий
около 1 месяца назад

Уязвимостей на страницу