Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 29 065

Количество 29 065

msrc логотип

CVE-2013-6629

больше 9 лет назад

libjpeg Information Disclosure Vulnerability

CVSS3: 4.7
EPSS: Низкий
msrc логотип

CVE-2013-6418

около 1 года назад

PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.

EPSS: Низкий
msrc логотип

CVE-2013-6381

больше 2 лет назад

Buffer overflow in the qeth_snmp_command function in drivers/s390/net/qeth_core_main.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service or possibly have unspecified other impact via an SNMP ioctl call with a length value that is incompatible with the command-buffer size.

EPSS: Низкий
msrc логотип

CVE-2013-5123

около 1 года назад

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

EPSS: Низкий
msrc логотип

CVE-2013-4420

около 6 лет назад

EPSS: Низкий
msrc логотип

CVE-2013-4416

около 1 года назад

The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdown) via a large message reply.

EPSS: Низкий
msrc логотип

CVE-2013-4342

больше 3 лет назад

xinetd does not enforce the user and group configuration directives for TCPMUX services which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.

EPSS: Низкий
msrc логотип

CVE-2013-3900

больше 4 лет назад

WinVerifyTrust Signature Validation Vulnerability

EPSS: Средний
msrc логотип

CVE-2013-2094

больше 2 лет назад

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type which allows local users to gain privileges via a crafted perf_event_open system call.

CVSS3: 8.4
EPSS: Средний
msrc логотип

CVE-2013-1633

3 месяца назад

easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

EPSS: Низкий
msrc логотип

CVE-2013-0340

почти 5 лет назад

expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function which allows remote attackers to cause a denial of service (resource consumption) send HTTP requests to intranet servers or read arbitrary files via a crafted XML document aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion the responsibility for resolving this issue lies with application developers; according to this argument this entry should be REJECTed and each affected application would need its own CVE.

EPSS: Средний
msrc логотип

CVE-2013-0223

почти 6 лет назад

EPSS: Низкий
msrc логотип

CVE-2013-0222

почти 6 лет назад

EPSS: Низкий
msrc логотип

CVE-2013-0221

почти 6 лет назад

EPSS: Низкий
msrc логотип

CVE-2012-6708

около 2 лет назад

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2012-6687

около 6 лет назад

EPSS: Низкий
msrc логотип

CVE-2012-6655

больше 1 года назад

An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.

CVSS3: 3.3
EPSS: Низкий
msrc логотип

CVE-2012-5627

почти 6 лет назад

Oracle MySQL and MariaDB 5.5.x before 5.5.29 5.3.x before 5.3.12 and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.

EPSS: Средний
msrc логотип

CVE-2012-4575

почти 6 лет назад

EPSS: Низкий
msrc логотип

CVE-2012-3425

больше 1 года назад

The png_push_read_zTXt function allows remote attackers to cause a denial of service

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
msrc логотип
CVE-2013-6629

libjpeg Information Disclosure Vulnerability

CVSS3: 4.7
10%
Низкий
больше 9 лет назад
msrc логотип
CVE-2013-6418

PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.

2%
Низкий
около 1 года назад
msrc логотип
CVE-2013-6381

Buffer overflow in the qeth_snmp_command function in drivers/s390/net/qeth_core_main.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service or possibly have unspecified other impact via an SNMP ioctl call with a length value that is incompatible with the command-buffer size.

1%
Низкий
больше 2 лет назад
msrc логотип
CVE-2013-5123

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

8%
Низкий
около 1 года назад
msrc логотип
3%
Низкий
около 6 лет назад
msrc логотип
CVE-2013-4416

The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdown) via a large message reply.

1%
Низкий
около 1 года назад
msrc логотип
CVE-2013-4342

xinetd does not enforce the user and group configuration directives for TCPMUX services which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.

6%
Низкий
больше 3 лет назад
msrc логотип
CVE-2013-3900

WinVerifyTrust Signature Validation Vulnerability

45%
Средний
больше 4 лет назад
msrc логотип
CVE-2013-2094

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type which allows local users to gain privileges via a crafted perf_event_open system call.

CVSS3: 8.4
48%
Средний
больше 2 лет назад
msrc логотип
CVE-2013-1633

easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

2%
Низкий
3 месяца назад
msrc логотип
CVE-2013-0340

expat 2.1.0 and earlier does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function which allows remote attackers to cause a denial of service (resource consumption) send HTTP requests to intranet servers or read arbitrary files via a crafted XML document aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat already provides the ability to disable external entity expansion the responsibility for resolving this issue lies with application developers; according to this argument this entry should be REJECTed and each affected application would need its own CVE.

19%
Средний
почти 5 лет назад
msrc логотип
1%
Низкий
почти 6 лет назад
msrc логотип
0%
Низкий
почти 6 лет назад
msrc логотип
7%
Низкий
почти 6 лет назад
msrc логотип
CVSS3: 6.1
9%
Низкий
около 2 лет назад
msrc логотип
6%
Низкий
около 6 лет назад
msrc логотип
CVE-2012-6655

An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.

CVSS3: 3.3
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2012-5627

Oracle MySQL and MariaDB 5.5.x before 5.5.29 5.3.x before 5.3.12 and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.

11%
Средний
почти 6 лет назад
msrc логотип
2%
Низкий
почти 6 лет назад
msrc логотип
CVE-2012-3425

The png_push_read_zTXt function allows remote attackers to cause a denial of service

3%
Низкий
больше 1 года назад

Уязвимостей на страницу