Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 250

Количество 55 250

redhat логотип

CVE-2018-25091

почти 3 года назад

urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-25079

больше 3 лет назад

A vulnerability was found in Segmentio is-url up to 1.2.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. Upgrading to version 1.2.3 is able to address this issue. The patch is identified as 149550935c63a98c11f27f694a7c4a9479e53794. It is recommended to upgrade the affected component. VDB-220058 is the identifier assigned to this vulnerability.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-25046

больше 3 лет назад

Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2018-25032

больше 8 лет назад

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

CVSS3: 8.2
EPSS: Средний
redhat логотип

CVE-2018-25020

больше 8 лет назад

The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2018-25015

больше 8 лет назад

An issue was discovered in the Linux kernel before 4.14.16. There is a use-after-free in net/sctp/socket.c for a held lock after a peel off, aka CID-a0ff660058b8.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2018-25014

около 8 лет назад

A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2018-25013

около 8 лет назад

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2018-25012

около 8 лет назад

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2018-25011

около 8 лет назад

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2018-25010

около 8 лет назад

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2018-25009

около 8 лет назад

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2018-25008

около 8 лет назад

In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchronization issue can be lead to memory safety issues through race conditions.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-25004

больше 5 лет назад

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.

CVSS3: 4.9
EPSS: Низкий
redhat логотип

CVE-2018-21270

больше 6 лет назад

Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2018-21247

около 6 лет назад

An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-21232

почти 8 лет назад

re2c before 2.0 has uncontrolled recursion that causes stack consumption in find_fixed_tags.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2018-21035

почти 8 лет назад

In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-21029

около 8 лет назад

systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability since hostname validation does not have anything to do with this issue (i.e. there is no hostname to be sent)

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2018-21010

почти 7 лет назад

OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-25091

urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).

CVSS3: 6.1
1%
Низкий
почти 3 года назад
redhat логотип
CVE-2018-25079

A vulnerability was found in Segmentio is-url up to 1.2.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file index.js. The manipulation leads to inefficient regular expression complexity. The attack may be launched remotely. Upgrading to version 1.2.3 is able to address this issue. The patch is identified as 149550935c63a98c11f27f694a7c4a9479e53794. It is recommended to upgrade the affected component. VDB-220058 is the identifier assigned to this vulnerability.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2018-25046

Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

CVSS3: 9.1
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2018-25032

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

CVSS3: 8.2
52%
Средний
больше 8 лет назад
redhat логотип
CVE-2018-25020

The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.

CVSS3: 7.8
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-25015

An issue was discovered in the Linux kernel before 4.14.16. There is a use-after-free in net/sctp/socket.c for a held lock after a peel off, aka CID-a0ff660058b8.

CVSS3: 7.4
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-25014

A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().

CVSS3: 9.8
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-25013

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().

CVSS3: 9.1
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-25012

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().

CVSS3: 9.1
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-25011

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().

CVSS3: 9.8
3%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-25010

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().

CVSS3: 9.1
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-25009

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().

CVSS3: 9.1
2%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-25008

In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchronization issue can be lead to memory safety issues through race conditions.

CVSS3: 5.9
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-25004

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.

CVSS3: 4.9
1%
Низкий
больше 5 лет назад
redhat логотип
CVE-2018-21270

Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).

CVSS3: 6.5
4%
Низкий
больше 6 лет назад
redhat логотип
CVE-2018-21247

An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.

CVSS3: 7.5
2%
Низкий
около 6 лет назад
redhat логотип
CVE-2018-21232

re2c before 2.0 has uncontrolled recursion that causes stack consumption in find_fixed_tags.

CVSS3: 5.5
1%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-21035

In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).

CVSS3: 7.5
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-21029

systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability since hostname validation does not have anything to do with this issue (i.e. there is no hostname to be sent)

CVSS3: 6.3
3%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-21010

OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.

CVSS3: 8.1
2%
Низкий
почти 7 лет назад

Уязвимостей на страницу