Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 57 017

Количество 57 017

redhat логотип

CVE-2023-35829

около 3 лет назад

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2023-35828

около 3 лет назад

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2023-35827

около 3 лет назад

An issue was discovered in the Linux kernel through 6.3.8. A use-after-free was found in ravb_remove in drivers/net/ethernet/renesas/ravb_main.c.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2023-35826

около 3 лет назад

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2023-35825

около 3 лет назад

A race condition was found in the Linux kernel's r592 device driver, when removing the module before cleanup in the r592_remove function. This can result in a use-after-free issue, possibly leading to a system crash or other undefined behaviors.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2023-35824

около 3 лет назад

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remove in drivers/media/pci/dm1105/dm1105.c.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2023-35823

около 3 лет назад

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2023-35790

больше 3 лет назад

An issue was discovered in dec_patch_dictionary.cc in libjxl before 0.8.2. An integer underflow in patch decoding can lead to a denial of service, such as an infinite loop.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-35789

около 3 лет назад

An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments.

CVSS3: 5.1
EPSS: Низкий
redhat логотип

CVE-2023-35788

больше 3 лет назад

An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2023-3576

больше 3 лет назад

A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, which causes this memory leak issue, resulting an application crash, eventually leading to a denial of service.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2023-3567

больше 3 лет назад

A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2023-3550

почти 3 года назад

Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the instance administrator.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2023-35391

около 3 лет назад

ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2023-35390

около 3 лет назад

.NET and Visual Studio Remote Code Execution Vulnerability

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2023-35149

больше 3 лет назад

A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenkins.

CVSS3: 4.2
EPSS: Низкий
redhat логотип

CVE-2023-35148

больше 3 лет назад

A cross-site request forgery (CSRF) vulnerability in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers to connect to an attacker-specified URL, capturing credentials stored in Jenkins.

CVSS3: 4.2
EPSS: Низкий
redhat логотип

CVE-2023-35147

больше 3 лет назад

Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attackers with Item/Read permission to obtain the contents of arbitrary files on the Jenkins controller file system.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2023-35146

больше 3 лет назад

Jenkins Template Workflows Plugin 41.v32d86a_313b_4a and earlier does not escape names of jobs used as buildings blocks for Template Workflow Job, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create jobs.

CVSS3: 8
EPSS: Низкий
redhat логотип

CVE-2023-35145

больше 3 лет назад

Jenkins Sonargraph Integration Plugin 5.0.1 and earlier does not escape the file path and the project name for the Log file field form validation, resulting in a stored cross-site scripting vulnerability exploitable by attackers with Item/Configure permission.

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2023-35829

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c.

CVSS3: 6.4
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-35828

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c.

CVSS3: 6.4
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-35827

An issue was discovered in the Linux kernel through 6.3.8. A use-after-free was found in ravb_remove in drivers/net/ethernet/renesas/ravb_main.c.

CVSS3: 6.4
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-35826

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c.

CVSS3: 6.4
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-35825

A race condition was found in the Linux kernel's r592 device driver, when removing the module before cleanup in the r592_remove function. This can result in a use-after-free issue, possibly leading to a system crash or other undefined behaviors.

CVSS3: 6.4
около 3 лет назад
redhat логотип
CVE-2023-35824

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in dm1105_remove in drivers/media/pci/dm1105/dm1105.c.

CVSS3: 6.4
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-35823

An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c.

CVSS3: 6.7
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-35790

An issue was discovered in dec_patch_dictionary.cc in libjxl before 0.8.2. An integer underflow in patch decoding can lead to a denial of service, such as an infinite loop.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-35789

An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments.

CVSS3: 5.1
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-35788

An issue was discovered in fl_set_geneve_opt in net/sched/cls_flower.c in the Linux kernel before 6.3.7. It allows an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets. This may result in denial of service or privilege escalation.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-3576

A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, which causes this memory leak issue, resulting an application crash, eventually leading to a denial of service.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-3567

A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-3550

Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the instance administrator.

CVSS3: 7.3
1%
Низкий
почти 3 года назад
redhat логотип
CVE-2023-35391

ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability

CVSS3: 7.1
2%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-35390

.NET and Visual Studio Remote Code Execution Vulnerability

CVSS3: 7.8
2%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-35149

A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenkins.

CVSS3: 4.2
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-35148

A cross-site request forgery (CSRF) vulnerability in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers to connect to an attacker-specified URL, capturing credentials stored in Jenkins.

CVSS3: 4.2
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-35147

Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attackers with Item/Read permission to obtain the contents of arbitrary files on the Jenkins controller file system.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-35146

Jenkins Template Workflows Plugin 41.v32d86a_313b_4a and earlier does not escape names of jobs used as buildings blocks for Template Workflow Job, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create jobs.

CVSS3: 8
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-35145

Jenkins Sonargraph Integration Plugin 5.0.1 and earlier does not escape the file path and the project name for the Log file field form validation, resulting in a stored cross-site scripting vulnerability exploitable by attackers with Item/Configure permission.

CVSS3: 8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу