Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 29 065

Количество 29 065

msrc логотип

CVE-2015-3630

около 5 лет назад

Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound (2) /proc/timer_stats (3) /proc/latency_stats and (4) /proc/fs which allows local users to modify the host obtain sensitive information and perform protocol downgrade attacks via a crafted image.

EPSS: Низкий
msrc логотип

CVE-2015-3627

около 5 лет назад

Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot which allows local users to gain privileges via a symlink attack in an image.

EPSS: Низкий
msrc логотип

CVE-2015-3416

около 1 года назад

The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf function call in a SELECT statement.

EPSS: Низкий
msrc логотип

CVE-2015-3310

около 1 года назад

Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to the RADIUS server.

EPSS: Низкий
msrc логотип

CVE-2015-3276

почти 6 лет назад

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2015-2987

около 6 лет назад

EPSS: Низкий
msrc логотип

CVE-2015-2704

12 месяцев назад

realmd allows remote attackers to inject arbitrary configurations in to sssd.conf and smb.conf

EPSS: Низкий
msrc логотип

CVE-2015-2158

больше 1 года назад

Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2015-20107

больше 4 лет назад

In Python (aka CPython) up to 3.10.8 the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7 3.8 3.9

CVSS3: 7.6
EPSS: Низкий
msrc логотип

CVE-2015-1473

больше 1 года назад

The GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service

EPSS: Низкий
msrc логотип

CVE-2015-1029

больше 1 года назад

The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to gain privileges or obtain sensitive information by prepopulating the fact cache.

EPSS: Низкий
msrc логотип

CVE-2014-9940

почти 3 года назад

The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.

EPSS: Низкий
msrc логотип

CVE-2014-9913

около 6 лет назад

CVSS3: 4
EPSS: Низкий
msrc логотип

CVE-2014-9639

почти 5 лет назад

EPSS: Низкий
msrc логотип

CVE-2014-9638

почти 5 лет назад

EPSS: Низкий
msrc логотип

CVE-2014-9636

около 6 лет назад

EPSS: Средний
msrc логотип

CVE-2014-9358

около 5 лет назад

Docker before 1.3.3 does not properly validate image IDs which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."

EPSS: Низкий
msrc логотип

CVE-2014-9356

около 5 лет назад

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

CVSS3: 8.6
EPSS: Низкий
msrc логотип

CVE-2014-8991

около 1 года назад

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

EPSS: Низкий
msrc логотип

CVE-2014-8179

около 5 лет назад

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2015-3630

Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound (2) /proc/timer_stats (3) /proc/latency_stats and (4) /proc/fs which allows local users to modify the host obtain sensitive information and perform protocol downgrade attacks via a crafted image.

1%
Низкий
около 5 лет назад
msrc логотип
CVE-2015-3627

Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot which allows local users to gain privileges via a symlink attack in an image.

1%
Низкий
около 5 лет назад
msrc логотип
CVE-2015-3416

The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions, which allows context-dependent attackers to cause a denial of service (integer overflow and stack-based buffer overflow) or possibly have unspecified other impact via large integers in a crafted printf function call in a SELECT statement.

6%
Низкий
около 1 года назад
msrc логотип
CVE-2015-3310

Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to the RADIUS server.

5%
Низкий
около 1 года назад
msrc логотип
CVSS3: 7.5
5%
Низкий
почти 6 лет назад
msrc логотип
1%
Низкий
около 6 лет назад
msrc логотип
CVE-2015-2704

realmd allows remote attackers to inject arbitrary configurations in to sssd.conf and smb.conf

3%
Низкий
12 месяцев назад
msrc логотип
CVE-2015-2158

Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service

CVSS3: 7.8
3%
Низкий
больше 1 года назад
msrc логотип
CVE-2015-20107

In Python (aka CPython) up to 3.10.8 the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7 3.8 3.9

CVSS3: 7.6
7%
Низкий
больше 4 лет назад
msrc логотип
CVE-2015-1473

The GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service

2%
Низкий
больше 1 года назад
msrc логотип
CVE-2015-1029

The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to gain privileges or obtain sensitive information by prepopulating the fact cache.

2%
Низкий
больше 1 года назад
msrc логотип
CVE-2014-9940

The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.

2%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 4
1%
Низкий
около 6 лет назад
msrc логотип
4%
Низкий
почти 5 лет назад
msrc логотип
4%
Низкий
почти 5 лет назад
msrc логотип
12%
Средний
около 6 лет назад
msrc логотип
CVE-2014-9358

Docker before 1.3.3 does not properly validate image IDs which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."

3%
Низкий
около 5 лет назад
msrc логотип
CVE-2014-9356

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

CVSS3: 8.6
5%
Низкий
около 5 лет назад
msrc логотип
CVE-2014-8991

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

0%
Низкий
около 1 года назад
msrc логотип
CVE-2014-8179

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.

CVSS3: 7.5
3%
Низкий
около 5 лет назад

Уязвимостей на страницу