Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 892

Количество 55 892

redhat логотип

CVE-2020-24503

больше 5 лет назад

Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-24502

больше 5 лет назад

Improper input validation in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 and before version 1.4.29.0 for Windows*, may allow an authenticated user to potentially enable a denial of service via local access.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-24490

почти 6 лет назад

Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access. This affects all Linux kernel versions that support BlueZ.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2020-24489

около 5 лет назад

Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2020-24455

почти 6 лет назад

Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.

CVSS3: 4.1
EPSS: Низкий
redhat логотип

CVE-2020-24394

около 6 лет назад

In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current umask is not considered.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2020-24386

больше 5 лет назад

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

CVSS3: 6.8
EPSS: Низкий
redhat логотип

CVE-2020-24372

около 6 лет назад

LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-24371

около 6 лет назад

lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2020-24370

около 6 лет назад

ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2020-24369

около 6 лет назад

ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2020-24352

около 6 лет назад

An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati_2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service.

CVSS3: 2.8
EPSS: Низкий
redhat логотип

CVE-2020-24342

около 6 лет назад

Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2020-24332

около 6 лет назад

An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-24331

около 6 лет назад

An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (which contains various settings related to this daemon).

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2020-24330

около 6 лет назад

An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2020-24303

около 6 лет назад

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2020-24301

около 6 лет назад

Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module, allowing arbitrary JavaScript to be executed in the user's browser. The impact of this vulnerability is believed to be low, as this module is intended for testing and not believed to be widely used for any production purposes.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2020-24242

около 6 лет назад

In Netwide Assembler (NASM) 2.15rc10, SEGV can be triggered in tok_text in asm/preproc.c by accessing READ memory.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-24241

около 6 лет назад

In Netwide Assembler (NASM) 2.15rc10, there is heap use-after-free in saa_wbytes in nasmlib/saa.c.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2020-24503

Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
0%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-24502

Improper input validation in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 and before version 1.4.29.0 for Windows*, may allow an authenticated user to potentially enable a denial of service via local access.

CVSS3: 5.5
0%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-24490

Improper buffer restrictions in BlueZ may allow an unauthenticated user to potentially enable denial of service via adjacent access. This affects all Linux kernel versions that support BlueZ.

CVSS3: 7.1
2%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-24489

Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.8
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-24455

Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.

CVSS3: 4.1
1%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-24394

In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current umask is not considered.

CVSS3: 7.1
0%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-24386

An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).

CVSS3: 6.8
3%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-24372

LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c.

CVSS3: 7.5
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-24371

lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.

CVSS3: 7.3
2%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-24370

ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).

CVSS3: 5.3
4%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-24369

ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.

CVSS3: 7
2%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-24352

An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati_2d.c while handling MMIO write operations through the ati_mm_write() callback. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service.

CVSS3: 2.8
0%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-24342

Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.

CVSS3: 7.8
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-24332

An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack.

CVSS3: 5.5
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-24331

An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (which contains various settings related to this daemon).

CVSS3: 7.8
0%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-24330

An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed.

CVSS3: 7.8
0%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-24303

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

CVSS3: 6.1
2%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-24301

Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module, allowing arbitrary JavaScript to be executed in the user's browser. The impact of this vulnerability is believed to be low, as this module is intended for testing and not believed to be widely used for any production purposes.

CVSS3: 7.3
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-24242

In Netwide Assembler (NASM) 2.15rc10, SEGV can be triggered in tok_text in asm/preproc.c by accessing READ memory.

CVSS3: 5.5
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-24241

In Netwide Assembler (NASM) 2.15rc10, there is heap use-after-free in saa_wbytes in nasmlib/saa.c.

CVSS3: 5.5
1%
Низкий
около 6 лет назад

Уязвимостей на страницу