Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 57 017

Количество 57 017

redhat логотип

CVE-2023-38560

около 3 лет назад

An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2023-38559

около 3 лет назад

A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2023-38552

почти 3 года назад

When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x. Please note that at the time this CVE was issued, the policy mechanism is an experimental feature of Node.js.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-38546

почти 3 года назад

This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application creates "easy handles" that are the individual handles for single transfers. libcurl provides a function call that duplicates en easy handle called [curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html). If a transfer has cookies enabled when the handle is duplicated, the cookie-enable state is also cloned - but without cloning the actual cookies. If the source handle did not read any cookies from a specific file on disk, the cloned version of the handle would instead store the file name as `none` (using the four ASCII letters, no quotes). Subsequent use of the cloned handle that does not explicitly set a source to load cookies from would then inadvertently load cookies from a file named `none` - if such a file exists and is readable in the current directory of the program ...

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2023-38545

почти 3 года назад

This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only. Due to this bug, the local variable that means "let the host resolve the name" could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long host name to the target buffer instead of copying just the resolved address there. The target buffer being a heap based buffer, and the host name coming from the URL that curl has been told to operate with.

CVSS3: 8.1
EPSS: Высокий
redhat логотип

CVE-2023-38497

около 3 лет назад

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2023-38473

больше 3 лет назад

A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2023-38472

больше 3 лет назад

A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2023-38471

больше 3 лет назад

A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2023-38470

больше 3 лет назад

A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2023-38469

больше 3 лет назад

A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2023-38432

около 3 лет назад

An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2023-38427

около 3 лет назад

An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2023-38409

больше 3 лет назад

An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc, the fbcon_registered_fb and fbcon_display arrays can be desynchronized in fbcon_mode_deleted (the con2fb_map points at the old fb_info).

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2023-38408

около 3 лет назад

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

CVSS3: 9.8
EPSS: Высокий
redhat логотип

CVE-2023-38407

больше 3 лет назад

bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-38406

больше 3 лет назад

bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-38403

около 3 лет назад

iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-38325

около 3 лет назад

The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-38285

около 3 лет назад

Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2023-38560

An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-38559

A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-38552

When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x. Please note that at the time this CVE was issued, the policy mechanism is an experimental feature of Node.js.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
redhat логотип
CVE-2023-38546

This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application creates "easy handles" that are the individual handles for single transfers. libcurl provides a function call that duplicates en easy handle called [curl_easy_duphandle](https://curl.se/libcurl/c/curl_easy_duphandle.html). If a transfer has cookies enabled when the handle is duplicated, the cookie-enable state is also cloned - but without cloning the actual cookies. If the source handle did not read any cookies from a specific file on disk, the cloned version of the handle would instead store the file name as `none` (using the four ASCII letters, no quotes). Subsequent use of the cloned handle that does not explicitly set a source to load cookies from would then inadvertently load cookies from a file named `none` - if such a file exists and is readable in the current directory of the program ...

CVSS3: 3.7
6%
Низкий
почти 3 года назад
redhat логотип
CVE-2023-38545

This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only. Due to this bug, the local variable that means "let the host resolve the name" could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long host name to the target buffer instead of copying just the resolved address there. The target buffer being a heap based buffer, and the host name coming from the URL that curl has been told to operate with.

CVSS3: 8.1
78%
Высокий
почти 3 года назад
redhat логотип
CVE-2023-38497

Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user. To prevent existing cached extractions from being exploitable, the Cargo binary version 0.72.2 included in Rust 1.71.1 or later will purge caches generated by older Cargo versions automatically. As a workaround, configure one's system to prevent other local users from accessing the Cargo directory, usually located in `~/.cargo`.

CVSS3: 6.7
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-38473

A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.

CVSS3: 6.2
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-38472

A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.

CVSS3: 6.2
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-38471

A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.

CVSS3: 6.2
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-38470

A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function.

CVSS3: 6.2
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-38469

A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record.

CVSS3: 6.2
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-38432

An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read.

CVSS3: 9.1
3%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-38427

An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-38409

An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc, the fbcon_registered_fb and fbcon_display arrays can be desynchronized in fbcon_mode_deleted (the con2fb_map points at the old fb_info).

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-38408

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

CVSS3: 9.8
80%
Высокий
около 3 лет назад
redhat логотип
CVE-2023-38407

bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-38406

bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-38403

iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.

CVSS3: 7.5
2%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-38325

The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-38285

Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.

CVSS3: 7.5
1%
Низкий
около 3 лет назад

Уязвимостей на страницу