Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26 087

Количество 26 087

msrc логотип

CVE-2014-9358

около 5 лет назад

Docker before 1.3.3 does not properly validate image IDs which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."

EPSS: Низкий
msrc логотип

CVE-2014-9356

около 5 лет назад

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

CVSS3: 8.6
EPSS: Низкий
msrc логотип

CVE-2014-8991

11 месяцев назад

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

EPSS: Низкий
msrc логотип

CVE-2014-8179

около 5 лет назад

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2014-8178

около 5 лет назад

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2014-8141

почти 6 лет назад

Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2014-8140

почти 6 лет назад

Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2014-8139

почти 6 лет назад

Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2014-7204

около 5 лет назад

jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.

EPSS: Низкий
msrc логотип

CVE-2014-6407

около 5 лет назад

Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.

EPSS: Низкий
msrc логотип

CVE-2014-5461

6 месяцев назад

Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.

EPSS: Средний
msrc логотип

CVE-2014-5282

около 5 лет назад

Docker before 1.3 does not properly validate image IDs which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'.

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2014-5278

около 5 лет назад

A vulnerability exists in Docker before 1.2 via container names which may collide with and override container IDs.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2014-5277

около 5 лет назад

Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic.

EPSS: Низкий
msrc логотип

CVE-2014-4607

11 месяцев назад

Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.

EPSS: Низкий
msrc логотип

CVE-2014-3618

больше 4 лет назад

EPSS: Низкий
msrc логотип

CVE-2014-3185

6 месяцев назад

Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat.c in the Whiteheat USB Serial Driver in the Linux kernel before 3.16.2 allow physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with a bulk response.

EPSS: Низкий
msrc логотип

CVE-2014-1949

6 дней назад

GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.

EPSS: Низкий
msrc логотип

CVE-2014-10402

11 месяцев назад

An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2014-0069

больше 2 лет назад

The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes which allows local users to obtain sensitive information from kernel memory cause a denial of service (memory corruption and system crash) or possibly gain privileges via a writev system call with a crafted pointer.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2014-9358

Docker before 1.3.3 does not properly validate image IDs which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."

3%
Низкий
около 5 лет назад
msrc логотип
CVE-2014-9356

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

CVSS3: 8.6
5%
Низкий
около 5 лет назад
msrc логотип
CVE-2014-8991

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

0%
Низкий
11 месяцев назад
msrc логотип
CVE-2014-8179

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.

CVSS3: 7.5
3%
Низкий
около 5 лет назад
msrc логотип
CVE-2014-8178

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.

CVSS3: 5.5
0%
Низкий
около 5 лет назад
msrc логотип
CVE-2014-8141

Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

CVSS3: 7.8
7%
Низкий
почти 6 лет назад
msrc логотип
CVE-2014-8140

Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

CVSS3: 7.8
7%
Низкий
почти 6 лет назад
msrc логотип
CVE-2014-8139

Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip command.

CVSS3: 7.8
7%
Низкий
почти 6 лет назад
msrc логотип
CVE-2014-7204

jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.

4%
Низкий
около 5 лет назад
msrc логотип
CVE-2014-6407

Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.

5%
Низкий
около 5 лет назад
msrc логотип
CVE-2014-5461

Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.

12%
Средний
6 месяцев назад
msrc логотип
CVE-2014-5282

Docker before 1.3 does not properly validate image IDs which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'.

CVSS3: 8.1
1%
Низкий
около 5 лет назад
msrc логотип
CVE-2014-5278

A vulnerability exists in Docker before 1.2 via container names which may collide with and override container IDs.

CVSS3: 5.3
2%
Низкий
около 5 лет назад
msrc логотип
CVE-2014-5277

Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic.

2%
Низкий
около 5 лет назад
msrc логотип
CVE-2014-4607

Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.

5%
Низкий
11 месяцев назад
msrc логотип
9%
Низкий
больше 4 лет назад
msrc логотип
CVE-2014-3185

Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat.c in the Whiteheat USB Serial Driver in the Linux kernel before 3.16.2 allow physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with a bulk response.

1%
Низкий
6 месяцев назад
msrc логотип
CVE-2014-1949

GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.

0%
Низкий
6 дней назад
msrc логотип
CVE-2014-10402

An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.

CVSS3: 6.1
0%
Низкий
11 месяцев назад
msrc логотип
CVE-2014-0069

The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes which allows local users to obtain sensitive information from kernel memory cause a denial of service (memory corruption and system crash) or possibly gain privileges via a writev system call with a crafted pointer.

0%
Низкий
больше 2 лет назад

Уязвимостей на страницу