Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 892

Количество 55 892

redhat логотип

CVE-2020-21687

больше 6 лет назад

Buffer Overflow vulnerability in scan function in stdscan.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-21686

больше 6 лет назад

A stack-use-after-scope issue discovered in expand_mmac_params function in preproc.c in nasm before 2.15.04 allows remote attackers to cause a denial of service via crafted asm file.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-21685

больше 6 лет назад

Buffer Overflow vulnerability in hash_findi function in hashtbl.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-21684

около 5 лет назад

A global buffer overflow in the put_font in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-21683

около 5 лет назад

A global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-21682

около 5 лет назад

A global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-21681

около 5 лет назад

A global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-21680

около 5 лет назад

A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-2167

больше 6 лет назад

Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2020-21678

около 5 лет назад

A global buffer overflow in the genmp_writefontmacro_latex component in genmp.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into mp format.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-21676

около 5 лет назад

A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-21675

около 5 лет назад

A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ptk format.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-21674

больше 6 лет назад

Heap-based buffer overflow in archive_string_append_from_wcs() (archive_string.c) in libarchive-3.4.1dev allows remote attackers to cause a denial of service (out-of-bounds write in heap memory resulting into a crash) via a crafted archive file. NOTE: this only affects users who downloaded the development code from GitHub. Users of the product's official releases are unaffected.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-2163

больше 6 лет назад

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, resulting in a stored XSS vulnerability exploitable by users able to control column headers.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2020-2162

больше 6 лет назад

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2020-2161

больше 6 лет назад

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2020-2160

больше 6 лет назад

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2020-21583

около 3 лет назад

An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2020-21535

больше 6 лет назад

fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-21534

больше 6 лет назад

fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2020-21687

Buffer Overflow vulnerability in scan function in stdscan.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file.

CVSS3: 5.5
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-21686

A stack-use-after-scope issue discovered in expand_mmac_params function in preproc.c in nasm before 2.15.04 allows remote attackers to cause a denial of service via crafted asm file.

CVSS3: 5.5
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-21685

Buffer Overflow vulnerability in hash_findi function in hashtbl.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file.

CVSS3: 5.5
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-21684

A global buffer overflow in the put_font in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.

CVSS3: 5.5
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-21683

A global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.

CVSS3: 5.5
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-21682

A global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format.

CVSS3: 5.5
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-21681

A global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format.

CVSS3: 5.5
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-21680

A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.

CVSS3: 5.5
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-2167

Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

CVSS3: 8.8
2%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-21678

A global buffer overflow in the genmp_writefontmacro_latex component in genmp.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into mp format.

CVSS3: 5.5
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-21676

A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.

CVSS3: 5.5
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-21675

A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ptk format.

CVSS3: 5.5
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-21674

Heap-based buffer overflow in archive_string_append_from_wcs() (archive_string.c) in libarchive-3.4.1dev allows remote attackers to cause a denial of service (out-of-bounds write in heap memory resulting into a crash) via a crafted archive file. NOTE: this only affects users who downloaded the development code from GitHub. Users of the product's official releases are unaffected.

CVSS3: 7.5
2%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-2163

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, resulting in a stored XSS vulnerability exploitable by users able to control column headers.

CVSS3: 5.4
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-2162

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.

CVSS3: 5.4
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-2161

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.

CVSS3: 5.4
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-2160

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.

CVSS3: 8.8
2%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-21583

An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.

CVSS3: 6.4
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2020-21535

fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c.

CVSS3: 5.5
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-21534

fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c.

CVSS3: 5.5
1%
Низкий
больше 6 лет назад

Уязвимостей на страницу