Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 713

Количество 79 713

ubuntu логотип

CVE-2017-0375

больше 9 лет назад

The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-0374

больше 9 лет назад

lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working directory, related to use of . with the INC array.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-0373

больше 9 лет назад

The gen_class_pod implementation in lib/Config/Model/Utils/GenClassPod.pm in Config-Model (aka libconfig-model-perl) before 2.102 has a dangerous "use lib" line, which allows remote attackers to have an unspecified impact via a crafted Debian package file.

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2017-0372

больше 8 лет назад

Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2017-0371

больше 4 лет назад

MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-0370

больше 8 лет назад

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2017-0369

больше 8 лет назад

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-0368

больше 8 лет назад

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2017-0367

больше 8 лет назад

Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-0366

больше 8 лет назад

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2017-0365

больше 8 лет назад

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a XSS vulnerability in SearchHighlighter::highlightText() with non-default configurations.

CVSS3: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2017-0364

больше 8 лет назад

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-0363

больше 8 лет назад

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-0362

больше 8 лет назад

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-0361

больше 8 лет назад

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-0360

больше 9 лет назад

file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same root name but with a suffix" attack. NOTE: This vulnerability exists because of an incomplete fix for CVE-2016-1242.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2017-0359

больше 8 лет назад

diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-0358

больше 8 лет назад

Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-0357

больше 8 лет назад

A heap-overflow flaw exists in the -tr loader of iucode-tool starting with v1.4 and before v2.1.1, potentially leading to SIGSEGV, or heap corruption.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-0356

больше 8 лет назад

A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-0375

The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.

CVSS3: 7.5
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2017-0374

lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working directory, related to use of . with the INC array.

CVSS3: 7.8
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2017-0373

The gen_class_pod implementation in lib/Config/Model/Utils/GenClassPod.pm in Config-Model (aka libconfig-model-perl) before 2.102 has a dangerous "use lib" line, which allows remote attackers to have an unspecified impact via a crafted Debian package file.

CVSS3: 7.3
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2017-0372

Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.

CVSS3: 9.8
11%
Средний
больше 8 лет назад
ubuntu логотип
CVE-2017-0371

MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker-controlled URL in the title attribute.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2017-0370

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.

CVSS3: 5.3
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0369

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.

CVSS3: 6.5
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0368

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages.

CVSS3: 5.3
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0367

Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.

CVSS3: 8.8
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0366

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.

CVSS3: 5.4
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0365

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a XSS vulnerability in SearchHighlighter::highlightText() with non-default configurations.

CVSS3: 4.7
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0364

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0363

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0362

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.

CVSS3: 8.8
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0361

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.

CVSS3: 7.8
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0360

file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same root name but with a suffix" attack. NOTE: This vulnerability exists because of an incomplete fix for CVE-2016-1242.

CVSS3: 5.3
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2017-0359

diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.

CVSS3: 9.8
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0358

Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.

CVSS3: 7.8
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0357

A heap-overflow flaw exists in the -tr loader of iucode-tool starting with v1.4 and before v2.1.1, potentially leading to SIGSEGV, or heap corruption.

CVSS3: 9.8
3%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-0356

A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.

CVSS3: 9.8
3%
Низкий
больше 8 лет назад

Уязвимостей на страницу