Report Name: Linux Patch Wednesday May 2024Generated: 2024-06-16 00:43:13
| Product Name | Prevalence | U | C | H | M | L | A | Comment |
|---|---|---|---|---|---|---|---|---|
| Kerberos | 1 | 24 | 31 | 2 | 57 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | ||
| AMD Processor | 0.9 | 2 | 2 | 4 | Processor | |||
| Active Directory | 0.9 | 1 | 1 | Active Directory is a directory service developed by Microsoft for Windows domain networks | ||||
| Apache HTTP Server | 0.9 | 2 | 13 | 14 | 5 | 34 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| GNU Bash | 0.9 | 2 | 2 | Bash is the shell, or command language interpreter, for the GNU operating system | ||||
| GitLab | 0.9 | 4 | 4 | GitLab is a DevOps software package that combines the ability to develop, secure, and operate software in a single application | ||||
| HTTP/2 | 0.9 | 1 | 1 | 4 | 6 | HTTP/2 is a major revision of the HTTP network protocol used by the World Wide Web | ||
| Intel(R) Processor | 0.9 | 2 | 2 | Intel's processors from the pioneering 4-bit 4004 (1971) to the present high-end offerings | ||||
| Linux Kernel | 0.9 | 3 | 43 | 533 | 513 | 1092 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| Microsoft SCOM | 0.9 | 1 | 1 | System Center Operations Manager | ||||
| Sudo | 0.9 | 1 | 2 | 6 | 5 | 14 | Sudo is a program for Unix-like computer operating systems that allows users to run programs with the security privileges of another user | |
| Windows Encrypting File System | 0.9 | 2 | 9 | 5 | 16 | Encrypting File System (EFS) on Microsoft Windows is a feature introduced in version 3.0 of NTFS that provides filesystem-level encryption | ||
| Windows Kernel | 0.9 | 2 | 14 | 32 | 5 | 53 | Windows Kernel | |
| Windows LDAP | 0.9 | 2 | 6 | 33 | 3 | 44 | Windows LDAP (Lightweight Directory Access Protocol) is an open and cross platform protocol used for directory services authentication | |
| nghttp2 | 0.9 | 2 | 2 | 4 | nghttp2 is an implementation of HTTP/2 and its header compression algorithm HPACK in C | |||
| APT | 0.8 | 1 | 8 | 41 | 12 | 62 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| ASP.NET | 0.8 | 3 | 1 | 4 | An open-source, server-side web-application framework designed for web development | |||
| Adobe Reader | 0.8 | 1 | 1 | 2 | Adobe Acrobat is a family of application software and Web services developed by Adobe Inc. to view, create, manipulate, print and manage Portable Document Format files | |||
| Binutils | 0.8 | 1 | 16 | 24 | 41 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | ||
| Chromium | 0.8 | 4 | 7 | 31 | 42 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | ||
| FreeIPA | 0.8 | 1 | 4 | 2 | 7 | FreeIPA is a free and open source identity management system | ||
| GNOME desktop | 0.8 | 8 | 52 | 9 | 69 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | ||
| GNU C Library | 0.8 | 4 | 8 | 28 | 4 | 44 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| Google Chrome | 0.8 | 2 | 10 | 39 | 51 | 102 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| ICMP | 0.8 | 1 | 5 | 6 | The Internet Control Message Protocol (ICMP) is a network layer protocol used by network devices to diagnose network communication issues | |||
| Mozilla Firefox | 0.8 | 4 | 41 | 52 | 9 | 106 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| Netty | 0.8 | 3 | 3 | Netty is a non-blocking I/O client-server framework for the development of Java network applications such as protocol servers and clients | ||||
| Node.js | 0.8 | 3 | 6 | 35 | 7 | 51 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| OpenSSH | 0.8 | 1 | 3 | 12 | 22 | 6 | 44 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture |
| OpenSSL | 0.8 | 1 | 3 | 14 | 38 | 17 | 73 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end |
| PHP | 0.8 | 2 | 8 | 99 | 326 | 42 | 477 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. |
| RPC | 0.8 | 8 | 37 | 5 | 50 | Remote Procedure Call Runtime | ||
| Safari | 0.8 | 26 | 55 | 29 | 110 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | ||
| Samba | 0.8 | 8 | 10 | 21 | 5 | 44 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| Visual Basic for Applications | 0.8 | 1 | 1 | 2 | 4 | Visual Basic for Applications is a computer programming language developed and owned by Microsoft | ||
| Webkit | 0.8 | 2 | 1 | 3 | WebKit is a browser engine developed by Apple and primarily used in its Safari web browser, as well as all web browsers on iOS and iPadOS | |||
| WinRAR | 0.8 | 3 | 1 | 4 | WinRAR is a trialware file archiver utility for Windows, developed by Eugene Roshal of win.rar GmbH | |||
| Windows NTFS | 0.8 | 13 | 1 | 14 | The default file system of the Windows NT family | |||
| Windows Remote Desktop Protocol | 0.8 | 1 | 1 | Windows component | ||||
| Xlib | 0.8 | 1 | 1 | 2 | Xlib (also known as libX11) is an X Window System protocol client library written in the C programming language | |||
| Zoom | 0.8 | 2 | 2 | Zoom is the leader in modern enterprise video communications | ||||
| libvpx | 0.8 | 2 | 6 | 8 | libvpx is a free software video codec library from Google and the Alliance for Open Media (AOMedia) | |||
| libwebp | 0.8 | 2 | 2 | libwebp is a code library used to render and display images in the WebP format | ||||
| .NET | 0.7 | 5 | 5 | .NET | ||||
| .NET and Visual Studio | 0.7 | 1 | 1 | .NET and Visual Studio | ||||
| Apache Tomcat | 0.7 | 1 | 2 | 2 | 1 | 6 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| Apache Traffic Server | 0.7 | 2 | 11 | 13 | The Apache Traffic Server is a modular, high-performance reverse proxy and forward proxy server, generally comparable to Nginx and Squid | |||
| BIND | 0.7 | 1 | 17 | 29 | 8 | 55 | BIND is a suite of software for interacting with the Domain Name System | |
| Babel | 0.7 | 14 | 1 | 3 | 18 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | ||
| Confluence | 0.7 | 1 | 1 | Confluence is a web-based corporate wiki | ||||
| Curl | 0.7 | 5 | 13 | 4 | 22 | Curl is a command-line tool for transferring data specified with URL syntax | ||
| ESXi | 0.7 | 3 | 3 | VMware ESXi (formerly ESX) is an enterprise-class, type-1 hypervisor developed by VMware for deploying and serving virtual computers | ||||
| FFmpeg | 0.7 | 8 | 17 | 100 | 3 | 128 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| Kubernetes | 0.7 | 6 | 4 | 10 | Kubernetes is an open-source container orchestration system for automating software deployment, scaling, and management | |||
| MariaDB | 0.7 | 1 | 1 | 2 | MariaDB is a community-developed, commercially supported fork of the MySQL relational database management system, intended to remain free and open-source software under the GNU General Public License | |||
| MediaWiki | 0.7 | 7 | 81 | 32 | 120 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | ||
| Oracle MySQL | 0.7 | 1 | 1 | MySQL is an open-source relational database management system | ||||
| Point-to-Point Tunneling Protocol | 0.7 | 1 | 1 | 2 | The Point to Point Tunneling Protocol (PPTP) is a network protocol used to create VPN tunnels between public networks | |||
| QEMU | 0.7 | 5 | 32 | 4 | 41 | QEMU is a generic and open source machine & userspace emulator and virtualizer | ||
| SQLite | 0.7 | 5 | 10 | 2 | 17 | SQLite is a database engine written in the C programming language | ||
| Struts | 0.7 | 1 | 1 | Apache Struts is a free, open-source, MVC framework for creating elegant, modern Java web applications. It favors convention over configuration, is extensible using a plugin architecture, and ships with plugins to support REST, AJAX and JSON | ||||
| VMware Tools | 0.7 | 1 | 1 | VMware Tools is a set of services and modules that enable several features in VMware products for better management of, and seamless user interactions with, guests operating systems | ||||
| Windows Security Center | 0.7 | 1 | 1 | Windows Security Center (WSC) is a comprehensive reporting tool that helps users establish and maintain a protective security layer around their computer systems | ||||
| iOS | 0.7 | 17 | 21 | 6 | 44 | iOS is an operating system developed and marketed by Apple Inc | ||
| macOS | 0.7 | 2 | 1 | 3 | macOS is an operating system developed and marketed by Apple Inc | |||
| vim | 0.7 | 6 | 6 | 1 | 13 | Vim is a free and open-source, screen-based text editor program | ||
| Apache ActiveMQ | 0.6 | 1 | 1 | 5 | 3 | 10 | Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client | |
| Bouncy Castle | 0.6 | 3 | 6 | 9 | Bouncy Castle is a collection of APIs used in cryptography | |||
| DirectX | 0.6 | 2 | 2 | DirectX | ||||
| Eclipse Mosquitto | 0.6 | 3 | 2 | 5 | Eclipse Mosquitto provides a lightweight server implementation of the MQTT protocol that is suitable for all situations from full power machines to embedded and low power machines | |||
| Exim | 0.6 | 1 | 12 | 4 | 17 | Exim is a mail transfer agent (MTA) used on Unix-like operating systems | ||
| FreeRDP | 0.6 | 5 | 1 | 7 | 13 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | ||
| ImageMagick | 0.6 | 2 | 62 | 7 | 71 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | ||
| Internet Explorer | 0.6 | 1 | 13 | 1 | 15 | Internet Explorer is a discontinued series of graphical web browsers developed by Microsoft | ||
| Jetty | 0.6 | 1 | 1 | 1 | 3 | Jetty is a Java based web server and servlet engine | ||
| Microsoft Excel | 0.6 | 1 | 1 | MS Office product | ||||
| Microsoft Word | 0.6 | 1 | 1 | Microsoft Word is a widely used commercial word processor developed by Microsoft. It is a component of the Microsoft Office suite of productivity software but can also be purchased as a standalone product. | ||||
| Nokogiri | 0.6 | 2 | 2 | Nokogiri is an open source XML and HTML library for the Ruby programming language | ||||
| Oracle Java SE | 0.6 | 5 | 3 | 8 | Oracle Java SE | |||
| Perl | 0.6 | 1 | 52 | 370 | 194 | 617 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| Puma | 0.6 | 1 | 1 | Puma is a Ruby/Rack web server built for parallelism | ||||
| Python | 0.6 | 22 | 70 | 43 | 135 | Python is a high-level, general-purpose programming language | ||
| ReadyMedia | 0.6 | 4 | 4 | ReadyMedia (formerly known as MiniDLNA) is a simple media server software, with the aim of being fully compliant with DLNA/UPnP-AV clients | ||||
| Redis | 0.6 | 2 | 1 | 7 | 5 | 15 | Redis is an open-source in-memory storage, used as a distributed, in-memory key–value database, cache and message broker, with optional durability | |
| Roundcube | 0.6 | 1 | 6 | 17 | 6 | 30 | Roundcube is a web-based IMAP email client | |
| Wireshark | 0.6 | 14 | 139 | 43 | 196 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | ||
| libxml2 | 0.6 | 3 | 2 | 5 | libxml2 is an XML toolkit implemented in C, originally developed for the GNOME Project | |||
| ownCloud | 0.6 | 2 | 1 | 3 | ownCloud is an open-source software product for sharing and syncing of files in distributed and federated enterprise scenarios | |||
| pgAdmin | 0.6 | 1 | 1 | pgAdmin is the most popular and feature rich Open Source administration and development platform for PostgreSQL, the most advanced Open Source database in the world | ||||
| tiffcrop | 0.6 | 2 | 2 | 4 | Tiffcrop processes one or more files created according to the Tag Image File Format, Revision 6.0, specification into one or more TIFF file(s) | |||
| wpa_supplicant | 0.6 | 1 | 4 | 1 | 6 | wpa_supplicant is a free software implementation of an IEEE 802.11i supplicant for Linux, FreeBSD, NetBSD, QNX, AROS, Microsoft Windows, Solaris, OS/2 (including ArcaOS and eComStation) and Haiku | ||
| 7-Zip | 0.5 | 4 | 4 | KeePass is a free open source password manager, which helps you to manage your passwords in a secure way | ||||
| CNG | 0.5 | 1 | 1 | CNG | ||||
| Cacti | 0.5 | 19 | 30 | 32 | 81 | Cacti is an open source operational monitoring and fault management framework | ||
| DNSSEC | 0.5 | 4 | 6 | 10 | The Domain Name System Security Extensions (DNSSEC) is a feature of the Domain Name System (DNS) that authenticates responses to domain name lookups | |||
| Docker | 0.5 | 1 | 8 | 7 | 16 | Docker | ||
| FRRouting | 0.5 | 3 | 4 | 7 | Free Range Routing or FRRouting or FRR is a network routing software suite running on Unix-like platforms, particularly Linux, Solaris, OpenBSD, FreeBSD and NetBSD | |||
| Flask | 0.5 | 2 | 2 | 4 | Flask is a lightweight WSGI web application framework | |||
| GDI | 0.5 | 1 | 5 | 2 | 8 | GDI | ||
| Group Policy | 0.5 | 1 | 1 | Group Policy | ||||
| HID | 0.5 | 3 | 7 | 13 | 23 | HID | ||
| KeePass | 0.5 | 2 | 1 | 3 | 7-Zip is a file archiver with a high compression ratio | |||
| LNK | 0.5 | 3 | 3 | 6 | LNK | |||
| Layer 2 Tunneling Protocol | 0.5 | 1 | 1 | Layer 2 Tunneling Protocol | ||||
| Libarchive | 0.5 | 1 | 10 | 1 | 12 | Multi-format archive and compression library | ||
| NetBIOS | 0.5 | 1 | 1 | NetBIOS (Network Basic Input/Output System) is a network service that enables applications on different computers to communicate with each other across a local area network (LAN) | ||||
| NumPy | 0.5 | 1 | 2 | 3 | NumPy is a library for the Python programming language, adding support for large, multi-dimensional arrays and matrices, along with a large collection of high-level mathematical functions | |||
| Openfire | 0.5 | 1 | 1 | Openfire is a real time collaboration (RTC) server licensed under the Open Source Apache License | ||||
| Scripting Engine | 0.5 | 1 | 1 | 2 | Scripting Engine | |||
| TLS | 0.5 | 10 | 37 | 50 | 97 | TLS | ||
| TLS/SSL | 0.5 | 2 | 2 | TLS/SSL | ||||
| TRIE | 0.5 | 1 | 33 | 12 | 46 | TRIE | ||
| VBScript | 0.5 | 1 | 1 | VBScript | ||||
| WEBDAV | 0.5 | 1 | 1 | WEBDAV | ||||
| Werkzeug | 0.5 | 1 | 1 | Werkzeug is a comprehensive WSGI web application library | ||||
| Word PDF | 0.5 | 1 | 1 | Word PDF | ||||
| Xrdp | 0.5 | 4 | 4 | xrdp is an open source remote desktop protocol server | ||||
| libjpeg | 0.5 | 13 | 7 | 20 | libjpeg | |||
| nginx | 0.5 | 7 | 5 | 1 | 13 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | ||
| ntopng | 0.5 | 2 | 3 | 1 | 6 | ntopng is an open-source computer software for monitoring traffic on a computer network | ||
| spip | 0.5 | 2 | 2 | 4 | SPIP is an open-source software content management system designed for web site publishing, oriented towards online collaborative editing | |||
| Azure | 0.4 | 3 | 3 | Azure | ||||
| Flatpak | 0.4 | 1 | 1 | 2 | Flatpak is a utility for software deployment and package management for Linux | |||
| GPAC | 0.4 | 26 | 73 | 36 | 135 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | ||
| Git | 0.4 | 13 | 60 | 37 | 110 | Git | ||
| LLDP | 0.4 | 1 | 1 | LLDP is an industry standard protocol designed to supplant proprietary Link-Layer protocols such as Extreme's EDP (Extreme Discovery Protocol) and CDP (Cisco Discovery Protocol) | ||||
| Artifex Ghostscript | 0.3 | 8 | 1 | 9 | Artifex Ghostscript is an interpreter for the PostScript® language and PDF files | |||
| Visual Studio | 0.3 | 1 | 1 | Integrated development environment | ||||
| Unknown Product | 0 | 10 | 406 | 2489 | 3537 | 6442 | Unknown Product |
| Vulnerability Type | Criticality | U | C | H | M | L | A |
|---|---|---|---|---|---|---|---|
| Remote Code Execution | 1.0 | 5 | 88 | 415 | 1048 | 36 | 1592 |
| Authentication Bypass | 0.98 | 1 | 4 | 22 | 67 | 2 | 96 |
| Code Injection | 0.97 | 2 | 2 | 21 | 20 | 45 | |
| Command Injection | 0.97 | 2 | 30 | 47 | 79 | ||
| XXE Injection | 0.97 | 1 | 5 | 23 | 29 | ||
| Arbitrary File Writing | 0.95 | 12 | 188 | 43 | 243 | ||
| Security Feature Bypass | 0.9 | 1 | 5 | 45 | 146 | 3 | 200 |
| Elevation of Privilege | 0.85 | 2 | 8 | 82 | 3 | 95 | |
| Arbitrary File Reading | 0.83 | 7 | 49 | 12 | 68 | ||
| Information Disclosure | 0.83 | 43 | 283 | 53 | 379 | ||
| Cross Site Scripting | 0.8 | 92 | 458 | 135 | 685 | ||
| Open Redirect | 0.75 | 14 | 2 | 16 | |||
| Denial of Service | 0.7 | 7 | 228 | 1531 | 825 | 2591 | |
| Path Traversal | 0.7 | 1 | 17 | 52 | 36 | 106 | |
| Incorrect Calculation | 0.5 | 1 | 3 | 49 | 27 | 80 | |
| Memory Corruption | 0.5 | 17 | 98 | 588 | 420 | 1123 | |
| Spoofing | 0.4 | 2 | 5 | 5 | 12 | ||
| Unknown Vulnerability Type | 0 | 2 | 81 | 740 | 3214 | 4037 |
| Source | U | C | H | M | L | A |
|---|---|---|---|---|---|---|
| almalinux | 5 | 8 | 43 | 58 | 114 | |
| debian | 9 | 131 | 1125 | 5371 | 4802 | 11438 |
| oraclelinux | 5 | 8 | 48 | 62 | 123 | |
| redhat | 5 | 9 | 52 | 65 | 131 | |
| redos | 7 | 15 | 57 | 24 | 103 | |
| ubuntu | 11 | 9 | 180 | 213 | 413 |
1.
Remote Code Execution - Apache HTTP Server (CVE-2021-42013) - Urgent [864]
Description: It was found that the fix for CVE-2021-41773 in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object) website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-42013 was patched at 2024-05-15
2.
Code Injection - PHP (CVE-2017-9841) - Urgent [842]
Description: {'vulners_cve_data_all': 'Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object), BDU websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-9841 was patched at 2024-05-15
3.
Remote Code Execution - Apache HTTP Server (CVE-2021-41773) - Urgent [840]
Description: A flaw was found in a change made to path normalization in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, AttackerKB object, CISA object) website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-41773 was patched at 2024-05-15
4.
Remote Code Execution - Google Chrome (CVE-2021-30632) - Urgent [835]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object), BDU websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30632 was patched at 2024-05-15
5.
Remote Code Execution - Apache Tomcat (CVE-2022-22965) - Urgent [830]
Description: A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (cisa_kev object), BDU websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-22965 was patched at 2024-05-15
6.
Remote Code Execution - OpenSSL (CVE-2010-0742) - Urgent [823]
Description: The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object) website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenSSL CMS结构处理内存破坏漏洞, [seebug] OpenSSL Cryptographic Message Syntax "OriginatorInfo" Vulnerability) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-0742 was patched at 2024-05-15
7.
Code Injection - PHP (CVE-2009-1151) - Urgent [818]
Description: Static
debian: CVE-2009-1151 was patched at 2024-05-15
8.
Security Feature Bypass - Google Chrome (CVE-2021-21220) - Urgent [817]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object) website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Google Chrome XOR Typer Out-Of-Bounds Access / Remote Code Execution, [githubexploit] Exploit for Out-of-bounds Write in Google Chrome, [zdt] Google Chrome XOR Typer Out-Of-Bounds Access / Remote Code Execution Exploit, [seebug] Chrome 远程代码执行漏洞(CVE-2021-21220)) | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-21220 was patched at 2024-05-15
9.
Authentication Bypass - OpenSSH (CVE-2019-6110) - Urgent [808]
Description: {'vulners_cve_data_all': 'In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object) website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] OpenSSH SCP Client - Write Arbitrary Files Exploit, [zdt] OpenSSH 7.6p1 SCP Client - Multiple Vulnerabilities (SSHtranger Things) Exploit, [packetstorm] SSHtranger Things SCP Client File Issue, [exploitpack] OpenSSH SCP Client - Write Arbitrary Files, [exploitpack] SCP Client - Multiple Vulnerabilities (SSHtranger Things), [exploitdb] SCP Client - Multiple Vulnerabilities (SSHtranger Things), [exploitdb] OpenSSH SCP Client - Write Arbitrary Files) | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-6110 was patched at 2024-05-15
10.
Security Feature Bypass - Apache ActiveMQ (CVE-2016-3088) - Critical [796]
Description: {'vulners_cve_data_all': 'The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object) website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-3088 was patched at 2024-05-15
11.
Security Feature Bypass - Google Chrome (CVE-2021-30533) - Critical [794]
Description: Insufficient policy enforcement in PopupBlocker in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (cisa_kev object) website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30533 was patched at 2024-05-15
12.
Elevation of Privilege - BIND (CVE-2020-0041) - Critical [780]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object, cisa_kev object, cisa_kev object) website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Improper Input Validation in Google Android) | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-0041 was patched at 2024-05-15
13.
Denial of Service - Node.js (CVE-2015-8858) - Critical [770]
Description: The uglify-js package before 2.6.0 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-8858 was patched at 2024-05-15
14.
Memory Corruption - Google Chrome (CVE-2021-30633) - Critical [758]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object), BDU websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30633 was patched at 2024-05-15
15.
Memory Corruption - nghttp2 (CVE-2024-27983) - Critical [751]
Description: An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for CVE-2024-27983) | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | nghttp2 is an implementation of HTTP/2 and its header compression algorithm HPACK in C | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2024-27983 was patched at 2024-05-09, 2024-05-15, 2024-05-20
debian: CVE-2024-27983 was patched at 2024-05-15
oraclelinux: CVE-2024-27983 was patched at 2024-05-09, 2024-05-10, 2024-05-14, 2024-05-16, 2024-05-22
redhat: CVE-2024-27983 was patched at 2024-05-09, 2024-05-15, 2024-05-20, 2024-05-21, 2024-05-29, 2024-06-03
redos: CVE-2024-27983 was patched at 2024-04-25
16.
Memory Corruption - Google Chrome (CVE-2021-21206) - Critical [746]
Description: Use after free in Blink in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object), BDU websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-21206 was patched at 2024-05-15
17.
Memory Corruption - Google Chrome (CVE-2021-30551) - Critical [746]
Description: Type confusion in V8 in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object) website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Type Confusion in Google Chrome) | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30551 was patched at 2024-05-15
18.
Memory Corruption - Google Chrome (CVE-2021-30563) - Critical [746]
Description: Type Confusion in V8 in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object), BDU websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30563 was patched at 2024-05-15
19.
Path Traversal - Openfire (CVE-2023-32315) - Critical [720]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object) website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Openfire is a real time collaboration (RTC) server licensed under the Open Source Apache License | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
redos: CVE-2023-32315 was patched at 2024-05-03
20.
Memory Corruption - Babel (CVE-2022-26127) - Critical [717]
Description: A
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-26127 was patched at 2024-05-15
ubuntu: CVE-2022-26127 was patched at 2024-06-05
21.
Memory Corruption - Babel (CVE-2022-26128) - Critical [717]
Description: A
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-26128 was patched at 2024-05-15
ubuntu: CVE-2022-26128 was patched at 2024-06-05
22.
Memory Corruption - Babel (CVE-2022-26129) - Critical [717]
Description: {'vulners_cve_data_all': 'Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-26129 was patched at 2024-05-15
ubuntu: CVE-2022-26129 was patched at 2024-06-05
23.
Denial of Service - HTTP/2 (CVE-2023-45288) - Critical [691]
Description: {'vulners_cve_data_all': 'An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state requires parsing and processing all HEADERS and CONTINUATION frames on a connection. When a request's headers exceed MaxHeaderBytes, no memory is allocated to store the excess headers, but they are still parsed. This permits an attacker to cause an HTTP/2 endpoint to read arbitrary amounts of header data, all associated with a request which is going to be rejected. These headers can include Huffman-encoded data which is significantly more expensive for the receiver to decode than for an attacker to send. The fix sets a limit on the amount of excess header frames we will process before closing a connection.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for CVE-2023-45288) | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | HTTP/2 is a major revision of the HTTP network protocol used by the World Wide Web | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2023-45288 was patched at 2024-04-23, 2024-04-29, 2024-04-30, 2024-05-06, 2024-05-07, 2024-05-22, 2024-05-23
debian: CVE-2023-45288 was patched at 2024-05-15
oraclelinux: CVE-2023-45288 was patched at 2024-04-23, 2024-05-07, 2024-05-08, 2024-05-29
redhat: CVE-2023-45288 was patched at 2024-04-23, 2024-04-26, 2024-04-29, 2024-04-30, 2024-05-02, 2024-05-06, 2024-05-07, 2024-05-09, 2024-05-20, 2024-05-21, 2024-05-22, 2024-05-23, 2024-05-29
redos: CVE-2023-45288 was patched at 2024-04-22
24.
Remote Code Execution - Unknown Product (CVE-2016-4437) - Critical [690]
Description: {'vulners_cve_data_all': 'Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (cisa_kev object) website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Apache Shiro 1.2.4 Remote Code Execution, [zdt] Apache Shiro 1.2.4 Remote Code Execution Exploit) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-4437 was patched at 2024-05-15
25.
Remote Code Execution - Unknown Product (CVE-2019-17558) - Critical [690]
Description: {'vulners_cve_data_all': 'Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity template can be provided through Velocity templates in a configset `velocity/` directory or as a parameter. A user defined configset could contain renderable, potentially malicious, templates. Parameter provided templates are disabled by default, but can be enabled by setting `params.resource.loader.enabled` by defining a response writer with that setting set to `true`. Defining a response writer requires configuration API access. Solr 8.4 removed the params resource loader entirely, and only enables the configset-provided template rendering when the configset is `trusted` (has been uploaded by an authenticated user).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (cisa_kev object) website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Injection in Apache Solr, [githubexploit] Exploit for Injection in Apache Solr, [githubexploit] Exploit for Injection in Apache Solr, [zdt] Apache Solr 8.3.0 Velocity Template Remote Code Execution Exploit, [packetstorm] Apache Solr 8.3.0 Velocity Template Remote Code Execution) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-17558 was patched at 2024-05-15
26.
Remote Code Execution - Unknown Product (CVE-2021-33035) - Critical [690]
Description: {'vulners_cve_data_all': 'Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data the size of certain fields is not checked: the data is just copied into local variables. A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by altering the contents of the program stack. This issue affects Apache OpenOffice up to and including version 4.1.10', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-33035 was patched at 2024-05-15
27.
Remote Code Execution - Unknown Product (CVE-2022-25942) - Critical [690]
Description: {'vulners_cve_data_all': 'An out-of-bounds read vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-25942 was patched at 2024-05-15
28.
Remote Code Execution - Unknown Product (CVE-2022-25972) - Critical [690]
Description: {'vulners_cve_data_all': 'An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-25972 was patched at 2024-05-15
29.
Remote Code Execution - Unknown Product (CVE-2022-26061) - Critical [690]
Description: {'vulners_cve_data_all': 'A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-26061 was patched at 2024-05-15
30.
Security Feature Bypass - Chromium (CVE-2024-3838) - Critical [680]
Description: {'vulners_cve_data_all': 'Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed an attacker who convinced a user to install a malicious app to perform UI spoofing via a crafted app. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-3838 was patched at 2024-04-20, 2024-05-15
redos: CVE-2024-3838 was patched at 2024-05-03
31.
Denial of Service - GNU C Library (CVE-2024-2961) - Critical [675]
Description: The iconv() function in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for CVE-2024-2961, [githubexploit] Exploit for CVE-2024-2961, [githubexploit] Exploit for CVE-2024-2961) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2024-2961 was patched at 2024-05-07, 2024-05-22, 2024-05-23
debian: CVE-2024-2961 was patched at 2024-04-23, 2024-05-15
oraclelinux: CVE-2024-2961 was patched at 2024-05-08, 2024-05-29, 2024-06-05
redhat: CVE-2024-2961 was patched at 2024-05-07, 2024-05-09, 2024-05-22, 2024-05-23, 2024-05-28, 2024-05-29, 2024-06-04
redos: CVE-2024-2961 was patched at 2024-05-03
ubuntu: CVE-2024-2961 was patched at 2024-04-18, 2024-04-29, 2024-05-02
32.
Security Feature Bypass - Unknown Product (CVE-2020-35380) - Critical [672]
Description: {'vulners_cve_data_all': 'GJSON before 1.6.4 allows attackers to cause a denial of service via crafted JSON.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-35380 was patched at 2024-05-15
33.
Denial of Service - Binutils (CVE-2017-16829) - Critical [669]
Description: The _bfd_elf_parse_gnu_properties function in elf-properties.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-16829 was patched at 2024-05-15
34.
Unknown Vulnerability Type - Node.js (CVE-2015-8857) - Critical [669]
Description: {'vulners_cve_data_all': 'The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improperly rewritten Javascript.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-8857 was patched at 2024-05-15
35.
Denial of Service - nghttp2 (CVE-2024-28182) - Critical [650]
Description: {'vulners_cve_data_all': 'nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2 v1.61.0 mitigates this vulnerability by limiting the number of CONTINUATION frames it accepts per stream. There is no workaround for this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | nghttp2 is an implementation of HTTP/2 and its header compression algorithm HPACK in C | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2024-28182 was patched at 2024-05-09, 2024-05-15, 2024-05-20, 2024-05-30
debian: CVE-2024-28182 was patched at 2024-05-15
oraclelinux: CVE-2024-28182 was patched at 2024-05-09, 2024-05-10, 2024-05-14, 2024-05-16, 2024-05-22
redhat: CVE-2024-28182 was patched at 2024-05-09, 2024-05-15, 2024-05-20, 2024-05-21, 2024-05-30, 2024-06-03, 2024-06-06
redos: CVE-2024-28182 was patched at 2024-05-07
ubuntu: CVE-2024-28182 was patched at 2024-04-25, 2024-05-07
36.
Unknown Vulnerability Type - Linux Kernel (CVE-2013-6282) - Critical [650]
Description: {'vulners_cve_data_all': 'The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (cisa_kev object) website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Linux ARM - Local Root Exploit, [zdt] Android get_user/put_user Exploit, [packetstorm] Android get_user/put_user Exploit, [metasploit] Android get_user/put_user Exploit, [exploitpack] Linux Kernel 3.4.5 (Android 4.2.24.4 ARM) - Local Privilege Escalation, [exploitdb] Google Android - get_user/put_user (Metasploit), [exploitdb] Linux Kernel < 3.4.5 (Android 4.2.2/4.4 ARM) - Local Privilege Escalation) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-6282 was patched at 2024-05-15
37.
Memory Corruption - Chromium (CVE-2024-3834) - Critical [645]
Description: Use after free in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-3834 was patched at 2024-04-20, 2024-05-15
redos: CVE-2024-3834 was patched at 2024-05-03
38.
Memory Corruption - Google Chrome (CVE-2021-30549) - Critical [645]
Description: Use after free in Spell check in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30549 was patched at 2024-05-15
39.
Memory Corruption - Google Chrome (CVE-2021-30554) - Critical [645]
Description: Use after free in WebGL in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object), BDU websites | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30554 was patched at 2024-05-15
40.
Memory Corruption - Chromium (CVE-2024-4671) - Critical [639]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-4671 was patched at 2024-05-10, 2024-05-15
41.
Remote Code Execution - Windows Kernel (CVE-2008-2430) - Critical [638]
Description: Integer overflow in the Open function in modules/demux/wav.c in VLC Media Player 0.8.6h on
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] VLC Media Player WAV文件缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows Kernel | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-2430 was patched at 2024-05-15
42.
Denial of Service - Unknown Product (CVE-2020-36066) - Critical [636]
Description: {'vulners_cve_data_all': 'GJSON <1.6.5 allows attackers to cause a denial of service (remote) via crafted JSON.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-36066 was patched at 2024-05-15
43.
Remote Code Execution - GNU C Library (CVE-2002-0391) - Critical [633]
Description: Integer overflow in xdr_array function in RPC servers for operating systems that use libc,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([canvas] Immunity Canvas: TTDB_XDRARRAY, [canvas] Immunity Canvas: CMSD_XDRARRAY) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-0391 was patched at 2024-05-15
44.
Remote Code Execution - GNU C Library (CVE-2014-9984) - Critical [633]
Description: nscd in the GNU C Library (aka
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Cisco Device Hardcoded Credentials / GNU glibc / BusyBox, [packetstorm] WAGO 852 Industrial Managed Switch Series Code Execution / Hardcoded Credentials) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-9984 was patched at 2024-05-15
ubuntu: CVE-2014-9984 was patched at 2024-05-02
45.
Remote Code Execution - Google Chrome (CVE-2012-2864) - Critical [633]
Description: Mesa, as used in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Google Chrome OS 远程代码执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-2864 was patched at 2024-05-15
46.
Remote Code Execution - Google Chrome (CVE-2020-6572) - Critical [633]
Description: Use after free in Media in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object) website | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-6572 was patched at 2024-05-15
47.
Remote Code Execution - Mozilla Firefox (CVE-2009-3377) - Critical [633]
Description: Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Mozilla Firefox多个内存破坏漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3377 was patched at 2024-05-15
48.
Remote Code Execution - OpenSSL (CVE-2022-2274) - Critical [633]
Description: The
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Out-of-bounds Write in Openssl) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-2274 was patched at 2024-05-15
49.
Remote Code Execution - PHP (CVE-2021-32708) - Critical [633]
Description: Flysystem is an open source file storage library for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([srcincite] SRC-2021-0021 : League flysystem removeFunkyWhiteSpace Time-Of-Check Time-Of-Use File Write Remote Code Execution Vulnerability) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32708 was patched at 2024-05-15
50.
Remote Code Execution - PHP (CVE-2023-24813) - Critical [633]
Description: Dompdf is an HTML to PDF converter written in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Incorrect Authorization in Dompdf Project Dompdf, [githubexploit] Exploit for Incorrect Authorization in Dompdf Project Dompdf) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-24813 was patched at 2024-05-15
51.
Remote Code Execution - PHP (CVE-2023-28115) - Critical [633]
Description: Snappy is a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-28115 was patched at 2024-05-15
52.
Remote Code Execution - Samba (CVE-2002-1318) - Critical [633]
Description: Buffer overflow in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Samba 2.2.2 < 2.2.6 - nttrans Buffer Overflow Exploit) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-1318 was patched at 2024-05-15
53.
Remote Code Execution - Samba (CVE-2003-0085) - Critical [633]
Description: Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([canvas] Immunity Canvas: SAMBA_NTTRANS, [packetstorm] Samba nttrans Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0085 was patched at 2024-05-15
54.
Remote Code Execution - Samba (CVE-2003-0196) - Critical [633]
Description: Multiple buffer overflows in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([saint] Samba call_trans2open buffer overflow, [saint] Samba call_trans2open buffer overflow, [saint] Samba call_trans2open buffer overflow, [saint] Samba call_trans2open buffer overflow, [packetstorm] Samba trans2open Overflow (Solaris SPARC), [packetstorm] Samba trans2open Overflow, [packetstorm] Samba trans2open Overflow (Mac OS X), [canvas] Immunity Canvas: SAMBA_TRANS2) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0196 was patched at 2024-05-15
55.
Remote Code Execution - Samba (CVE-2003-0201) - Critical [633]
Description: Buffer overflow in the call_trans2open function in trans2.c for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([saint] Samba call_trans2open buffer overflow, [saint] Samba call_trans2open buffer overflow, [saint] Samba call_trans2open buffer overflow, [saint] Samba call_trans2open buffer overflow, [packetstorm] Samba trans2open Overflow (Solaris SPARC), [packetstorm] Samba trans2open Overflow, [packetstorm] Samba trans2open Overflow (Mac OS X), [canvas] Immunity Canvas: SAMBA_TRANS2) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0201 was patched at 2024-05-15
56.
Remote Code Execution - Samba (CVE-2004-0600) - Critical [633]
Description: Buffer overflow in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] sambaPoC.txt) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0600 was patched at 2024-05-15
57.
Command Injection - Node.js (CVE-2019-10061) - Critical [627]
Description: utils/find-opencv.js in node-opencv (aka OpenCV bindings for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for OS Command Injection in Node-Opencv Project Node-Opencv) | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-10061 was patched at 2024-05-15
58.
Remote Code Execution - Linux Kernel (CVE-2008-4395) - Critical [626]
Description: Multiple buffer overflows in the ndiswrapper module 1.53 for the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Linux Kernel ndiswrapper模块远程溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-4395 was patched at 2024-05-15
59.
Remote Code Execution - Windows Kernel (CVE-2021-40826) - Critical [626]
Description: Clementine Music Player through 1.3.1 is vulnerable to a User Mode Write Access Violation, affecting the MP3 file parsing functionality at clementine+0x3aa207. The vulnerability is triggered when the user opens a crafted MP3 file or loads a remote stream URL that is mishandled by Clementine. Attackers could exploit this issue to cause a crash (DoS) of the clementine.exe process or achieve arbitrary
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows Kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-40826 was patched at 2024-05-15
60.
Remote Code Execution - Windows LDAP (CVE-2006-3747) - Critical [626]
Description: Off-by-one error in the
debian: CVE-2006-3747 was patched at 2024-05-15
61.
Memory Corruption - Unknown Product (CVE-2023-47212) - Critical [625]
Description: {'vulners_cve_data_all': 'A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-47212 was patched at 2024-05-15
62.
Memory Corruption - FreeRDP (CVE-2024-32041) - Critical [623]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-32041 was patched at 2024-05-15
ubuntu: CVE-2024-32041 was patched at 2024-04-24
63.
Memory Corruption - FreeRDP (CVE-2024-32458) - Critical [623]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-32458 was patched at 2024-05-15
ubuntu: CVE-2024-32458 was patched at 2024-04-24
64.
Memory Corruption - FreeRDP (CVE-2024-32459) - Critical [623]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-32459 was patched at 2024-05-15
ubuntu: CVE-2024-32459 was patched at 2024-04-24
65.
Remote Code Execution - Google Chrome (CVE-2021-30526) - Critical [621]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30526 was patched at 2024-05-15
66.
Remote Code Execution - Mozilla Firefox (CVE-2009-3378) - Critical [621]
Description: The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Mozilla Firefox多个内存破坏漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3378 was patched at 2024-05-15
67.
Remote Code Execution - Mozilla Firefox (CVE-2010-1028) - Critical [621]
Description: Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Mozilla Firefox 3.6 - Integer Overflow Exploit, [seebug] Mozilla Firefox 3.6 WOFF解码器整数溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-1028 was patched at 2024-05-15
68.
Remote Code Execution - PHP (CVE-2018-14857) - Critical [621]
Description: Unrestricted file upload (with
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] OCS Inventory NG Webconsole Shell Upload, [zdt] OCS Inventory NG Webconsole Shell Upload Vulnerability) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-14857 was patched at 2024-05-15
69.
Remote Code Execution - Safari (CVE-2008-2307) - Critical [621]
Description: Unspecified vulnerability in WebKit in Apple
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari内存破坏漏洞, [seebug] Apple Safari WebKit JavaScript数组远程溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-2307 was patched at 2024-05-15
70.
Remote Code Execution - Safari (CVE-2009-1686) - Critical [621]
Description: WebKit in Apple
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1686 was patched at 2024-05-15
71.
Remote Code Execution - Safari (CVE-2009-1701) - Critical [621]
Description: Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1701 was patched at 2024-05-15
72.
Remote Code Execution - Safari (CVE-2009-1711) - Critical [621]
Description: WebKit in Apple
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1711 was patched at 2024-05-15
73.
Remote Code Execution - Safari (CVE-2009-1712) - Critical [621]
Description: WebKit in Apple
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1712 was patched at 2024-05-15
74.
Remote Code Execution - Safari (CVE-2017-2505) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] WebKit JSC BindingNode::bindValue Failed Reference Count Increase, [seebug] WebKit: JSC: BindingNode::bindValue doesn't increase the scope's reference count(CVE-2017-2505)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2505 was patched at 2024-05-15
75.
Remote Code Execution - Safari (CVE-2017-2514) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] WebKit WebCore::FrameView::scheduleRelayout Use-After-Free, [zdt] Apple WebKit / Safari 10.0.3(12602.4.8) - WebCore::FrameView::scheduleRelayout Use-After-Free Exploi, [seebug] WebKit WebCore::FrameView::scheduleRelayout Use-After-Free(CVE-2017-2514)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2514 was patched at 2024-05-15
76.
Remote Code Execution - Safari (CVE-2017-2515) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] WebKit - Stealing Variables via Page Navigation in FrameLoader::clear Exploit, [packetstorm] WebKit FrameLoader::clear Variable Theft) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2515 was patched at 2024-05-15
77.
Remote Code Execution - Safari (CVE-2017-2521) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] WebKit JSC JSObject::ensureLength Failure Check Vulnerability, [seebug] WebKit Unspecified Memory Corruption Vulnerability(CVE-2017-2521), [packetstorm] WebKit JSC JSObject::ensureLength Failure Check) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2521 was patched at 2024-05-15
78.
Remote Code Execution - Safari (CVE-2017-2531) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] WebKit JSC emitPutDerivedConstructorToArrowFunctionContextScope Incorrect Check(CVE-2017-2531), [packetstorm] WebKit JSC emitPutDerivedConstructorToArrowFunctionContextScope Incorrect Check, [zdt] WebKit JSC emitPutDerivedConstructorToArrowFunctionContextScope Incorrect Check Vulnerability) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2531 was patched at 2024-05-15
79.
Remote Code Execution - Safari (CVE-2017-2536) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Apple Safari 10.1 - Spread Operator Integer Overflow Remote Code Execution Exploit, [seebug] Exploiting an integer overflow with array spreading (WebKit)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2536 was patched at 2024-05-15
80.
Remote Code Execution - Safari (CVE-2017-2547) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] WebKit JSC Jit Optimization Check Failure, [zdt] WebKit JSC - JIT Optimization Check Failed in IntegerCheckCombiningPhase::handleBlock Exploit) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2547 was patched at 2024-05-15
81.
Remote Code Execution - Safari (CVE-2017-6980) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] WebKit JSC - arrayProtoFuncSplice does not Initialize all Indices Exploit, [packetstorm] WebKit JSC arrayProtoFuncSplice Initialization Fail) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-6980 was patched at 2024-05-15
82.
Remote Code Execution - Safari (CVE-2017-6984) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] WebKit JSC - Heap Buffer Overflow in Intl.getCanonicalLocales Exploit, [packetstorm] WebKit JSC Intl.getCanonicalLocales Heap Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-6984 was patched at 2024-05-15
83.
Remote Code Execution - Safari (CVE-2017-7040) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] WebKit: use-after-free in WebCore::getCachedWrapper(CVE-2017-7040), [packetstorm] WebKit WebCore::getCachedWrapper Use-After-Free, [zdt] WebKit - WebCore::getCachedWrapper Use-After-Free Exploit) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-7040 was patched at 2024-05-15
84.
Remote Code Execution - Safari (CVE-2017-7041) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] WebKit - WebCore::Node::getFlag Use-After-Free Exploit, [seebug] WebKit: use-after-free in WebCore::Node::getFlag(CVE-2017-7041), [packetstorm] WebKit WebCore::Node::getFlag Use-After-Free) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-7041 was patched at 2024-05-15
85.
Remote Code Execution - Safari (CVE-2017-7042) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] WebKit - WebCore::InputType::element Use-After-Free Exploit, [seebug] WebKit: use-after-free in WebCore::InputType::element(CVE-2017-7042), [packetstorm] WebKit WebCore::InputType::element Use-After-Free) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-7042 was patched at 2024-05-15
86.
Remote Code Execution - Safari (CVE-2017-7043) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] WebKit WebCore::AccessibilityRenderObject::handleAriaExpandedChanged Use-After-Free, [zdt] WebKit - WebCore::AccessibilityRenderObject::handleAriaExpandedChanged Use-After-Free Exploit, [seebug] WebKit: use-after-free in WebCore::AccessibilityRenderObject::handleAriaExpandedChanged(CVE-2017-7043)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-7043 was patched at 2024-05-15
87.
Remote Code Execution - Safari (CVE-2017-7049) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] WebKit - WebCore::RenderSearchField::addSearchResult Heap Buffer Overflow Exploit, [seebug] WebKit: heap-buffer-overflow in WebCore::RenderSearchField::addSearchResult(CVE-2017-7049), [packetstorm] WebKit WebCore::RenderSearchField::addSearchResult Heap Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-7049 was patched at 2024-05-15
88.
Remote Code Execution - Safari (CVE-2017-7081) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 11 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] WebKitGTK+ Code Execution / Cookie Handling / Memory Corruption Vulnerabilities) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-7081 was patched at 2024-05-15
89.
Remote Code Execution - Safari (CVE-2017-7094) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 11 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] WebKitGTK+ Code Execution / Cookie Handling / Memory Corruption Vulnerabilities) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-7094 was patched at 2024-05-15
90.
Remote Code Execution - Safari (CVE-2017-7099) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 11 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] WebKitGTK+ Code Execution / Cookie Handling / Memory Corruption Vulnerabilities) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-7099 was patched at 2024-05-15
91.
Remote Code Execution - Safari (CVE-2018-4089) - Critical [621]
Description: An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] WebKit - detachWrapper Use-After-Free Exploit, [zdt] WebKitGTK+ Memory Corruption / Spoofing / Code Execution Vulnerabilities) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-4089 was patched at 2024-05-15
92.
Remote Code Execution - Samba (CVE-2009-1886) - Critical [621]
Description: Multiple format string vulnerabilities in client/client.c in smbclient in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Samba格式串和安全绕过漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1886 was patched at 2024-05-15
93.
Remote Code Execution - Windows Remote Desktop Protocol (CVE-2008-1802) - Critical [621]
Description: Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 allows remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] rdesktoppdu-overflow.txt, [seebug] rdesktop多个缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1802 was patched at 2024-05-15
94.
Authentication Bypass - OpenSSH (CVE-2006-5794) - Critical [617]
Description: Unspecified vulnerability in the sshd Privilege Separation Monitor in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object) website | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-5794 was patched at 2024-05-15
95.
Remote Code Execution - Babel (CVE-2022-41793) - Critical [616]
Description: An out-of-bounds write vulnerability exists in the CSR format title functionality of Open
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-41793 was patched at 2024-05-15
96.
Remote Code Execution - Babel (CVE-2022-42885) - Critical [616]
Description: A use of uninitialized pointer vulnerability exists in the GRO format res functionality of Open
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-42885 was patched at 2024-05-15
97.
Remote Code Execution - Babel (CVE-2022-43467) - Critical [616]
Description: An out-of-bounds write vulnerability exists in the PQS format coord_file functionality of Open
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-43467 was patched at 2024-05-15
98.
Remote Code Execution - Babel (CVE-2022-44451) - Critical [616]
Description: A use of uninitialized pointer vulnerability exists in the MSI format atom functionality of Open
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-44451 was patched at 2024-05-15
99.
Remote Code Execution - Babel (CVE-2022-46280) - Critical [616]
Description: A use of uninitialized pointer vulnerability exists in the PQS format pFormat functionality of Open
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-46280 was patched at 2024-05-15
100.
Remote Code Execution - Babel (CVE-2022-46289) - Critical [616]
Description: Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-46289 was patched at 2024-05-15
101.
Remote Code Execution - Babel (CVE-2022-46290) - Critical [616]
Description: Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-46290 was patched at 2024-05-15
102.
Remote Code Execution - Babel (CVE-2022-46292) - Critical [616]
Description: Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-46292 was patched at 2024-05-15
103.
Remote Code Execution - Babel (CVE-2022-46293) - Critical [616]
Description: Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-46293 was patched at 2024-05-15
104.
Remote Code Execution - Babel (CVE-2022-46294) - Critical [616]
Description: Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-46294 was patched at 2024-05-15
105.
Remote Code Execution - Babel (CVE-2022-46295) - Critical [616]
Description: Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-46295 was patched at 2024-05-15
106.
Remote Code Execution - FFmpeg (CVE-2009-4633) - Critical [616]
Description: vorbis_dec.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg多个媒体文件解析拒绝服务和代码执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4633 was patched at 2024-05-15
107.
Remote Code Execution - FFmpeg (CVE-2009-4634) - Critical [616]
Description: Multiple integer underflows in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg多个媒体文件解析拒绝服务和代码执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4634 was patched at 2024-05-15
108.
Remote Code Execution - FFmpeg (CVE-2009-4637) - Critical [616]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg多个媒体文件解析拒绝服务和代码执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4637 was patched at 2024-05-15
109.
Remote Code Execution - FFmpeg (CVE-2016-10192) - Critical [616]
Description: Heap-based buffer overflow in ffserver.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg Heap Overflow vulnerability (CVE-2016-10190)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-10192 was patched at 2024-05-15
110.
Security Feature Bypass - PHP (CVE-2021-43617) - Critical [615]
Description: {'vulners_cve_data_all': 'Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated to any reports concerning incorrectly written user applications for image upload.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-43617 was patched at 2024-05-15
111.
Remote Code Execution - Sudo (CVE-2012-0809) - Critical [614]
Description: Format string vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] sudo 1.8.0 1.8.3p1 - sudo_debug glibc FORTIFY_SOURCE Bypass + Privilege Escalation, [zdt] Sudo v1.8.0-1.8.3p1 (sudo_debug) - Root Exploit, [seebug] sudo 1.8.0-1.8.3p1 (sudo_debug) - Root Exploit + glibc FORTIFY_SOURCE Bypass, [exploitdb] sudo 1.8.0 < 1.8.3p1 - 'sudo_debug' glibc FORTIFY_SOURCE Bypass + Privilege Escalation) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Sudo is a program for Unix-like computer operating systems that allows users to run programs with the security privileges of another user | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-0809 was patched at 2024-05-15
112.
Remote Code Execution - Windows LDAP (CVE-2021-42550) - Critical [614]
Description: In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows LDAP (Lightweight Directory Access Protocol) is an open and cross platform protocol used for directory services authentication | |
| 0.7 | 10 | CVSS Base Score is 6.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-42550 was patched at 2024-05-15
113.
Denial of Service - Unknown Product (CVE-2024-0911) - Critical [613]
Description: {'vulners_cve_data_all': 'A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-0911 was patched at 2024-05-15
114.
Elevation of Privilege - Linux Kernel (CVE-2022-1043) - Critical [611]
Description: A flaw was found in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] io_uring Same Type Object Reuse Privilege Escalation Exploit, [metasploit] io_uring Same Type Object Reuse Priv Esc, [packetstorm] io_uring Same Type Object Reuse Privilege Escalation) | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-1043 was patched at 2024-05-15
115.
Remote Code Execution - APT (CVE-2007-4629) - Critical [609]
Description: Buffer overflow in the processLine function in m
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MapServer远程栈溢出及跨站脚本漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-4629 was patched at 2024-05-15
116.
Remote Code Execution - Adobe Reader (CVE-2006-3459) - Critical [609]
Description: Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Adobe Reader和Acrobat TIFF图像处理缓冲区溢出漏洞, [seebug] Libtiff图形库多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Adobe Acrobat is a family of application software and Web services developed by Adobe Inc. to view, create, manipulate, print and manage Portable Document Format files | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3459 was patched at 2024-05-15
117.
Remote Code Execution - GNU C Library (CVE-2003-0028) - Critical [609]
Description: Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([canvas] Immunity Canvas: CMSD_XDRARRAY, [canvas] Immunity Canvas: TTDB_XDRARRAY) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0028 was patched at 2024-05-15
118.
Remote Code Execution - Mozilla Firefox (CVE-2006-4253) - Critical [609]
Description: Concurrency vulnerability in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4253 was patched at 2024-05-15
119.
Remote Code Execution - OpenSSH (CVE-2019-16905) - Critical [609]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-16905 was patched at 2024-05-15
120.
Remote Code Execution - OpenSSL (CVE-2002-0656) - Critical [609]
Description: Buffer overflows in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitdb] OpenSSL SSLv2 - Malformed Client Key Remote Buffer Overflow Vulnerability 2, [canvas] Immunity Canvas: OPENSSL_KEYLEN) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-0656 was patched at 2024-05-15
121.
Remote Code Execution - PHP (CVE-2011-4899) - Critical [609]
Description: wp-admin/setup-config.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Elipse E3 Scada PLC Denial Of Service, [packetstorm] WordPress 3.3.1 Code Execution / Cross Site Scripting, [seebug] wordpress <= 3.3.1 - Multiple Vulnerabilities, [seebug] WordPress 3.3.1 Code Execution / Cross Site Scripting, [exploitpack] WordPress 3.3.1 - Multiple Vulnerabilities, [exploitdb] WordPress Core 3.3.1 - Multiple Vulnerabilities) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4899 was patched at 2024-05-15
122.
Remote Code Execution - Safari (CVE-2018-4192) - Critical [609]
Description: An issue was discovered in certain Apple products. iOS before 11.4 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] JavaScript Core - Arbitrary Code Execution Exploit, [packetstorm] JavaScript Core Arbitrary Code Execution) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-4192 was patched at 2024-05-15
123.
Remote Code Execution - Safari (CVE-2020-15138) - Critical [609]
Description: Prism is vulnerable to Cross-Site Scripting. The easing preview of the Previewers plugin has an XSS vulnerability that allows attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Cross-site Scripting in Prismjs Previewers) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-15138 was patched at 2024-05-15
124.
Remote Code Execution - Samba (CVE-2007-0454) - Critical [609]
Description: Format string vulnerability in the afsacl.so VFS module in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Samba服务器VFS插件afsacl.so远程格式串处理漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-0454 was patched at 2024-05-15
125.
Authentication Bypass - Chromium (CVE-2021-30617) - Critical [605]
Description: {'vulners_cve_data_all': 'Chromium: CVE-2021-30617 Policy bypass in Blink', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object) website | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30617 was patched at 2024-05-15
126.
Authentication Bypass - OpenSSL (CVE-2016-7054) - Critical [605]
Description: {'vulners_cve_data_all': 'In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue is not considered to be exploitable beyond a DoS.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] OpenSSL 1.1.0a/1.1.0b - Denial of Service Exploit, [exploitpack] OpenSSL 1.1.0a1.1.0b - Denial of Service, [exploitdb] OpenSSL 1.1.0a/1.1.0b - Denial of Service) | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-7054 was patched at 2024-05-15
127.
Authentication Bypass - Samba (CVE-2022-32743) - Critical [605]
Description: {'vulners_cve_data_all': 'Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-32743 was patched at 2024-05-15
128.
Code Injection - PHP (CVE-2005-2612) - Critical [604]
Description: Direct
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] WordPress cache_lastpostdate Arbitrary Code Execution, [packetstorm] WordPress cache_lastpostdate Arbitrary Code Execution) | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-2612 was patched at 2024-05-15
129.
Code Injection - PHP (CVE-2009-1285) - Critical [604]
Description: Static
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin配置文件PHP代码注入漏洞, [seebug] CVE-2009-1285: phpMyAdmin Code Injection) | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1285 was patched at 2024-05-15
130.
Command Injection - OpenSSH (CVE-2020-15778) - Critical [604]
Description: scp in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for OS Command Injection in Openbsd Openssh, [githubexploit] Exploit for OS Command Injection in Openbsd Openssh) | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2020-15778 was patched at 2024-05-22
debian: CVE-2020-15778 was patched at 2024-05-15
oraclelinux: CVE-2020-15778 was patched at 2024-05-23
redhat: CVE-2020-15778 was patched at 2024-05-22
131.
Remote Code Execution - FFmpeg (CVE-2008-3162) - Critical [604]
Description: Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3162 was patched at 2024-05-15
132.
Remote Code Execution - FFmpeg (CVE-2009-0385) - Critical [604]
Description: Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg 4xm文件解析内存破坏漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0385 was patched at 2024-05-15
133.
Remote Code Execution - FFmpeg (CVE-2009-4631) - Critical [604]
Description: Off-by-one error in the VP3 decoder (vp3.c) in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg多个媒体文件解析拒绝服务和代码执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4631 was patched at 2024-05-15
134.
Remote Code Execution - FFmpeg (CVE-2009-4635) - Critical [604]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg多个媒体文件解析拒绝服务和代码执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4635 was patched at 2024-05-15
135.
XXE Injection - Safari (CVE-2009-1699) - Critical [604]
Description: The XSL stylesheet implementation in WebKit in Apple
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([canvas] Immunity Canvas: SAFARI_FILE_STEALING2, [seebug] Apple Safari 4.0多个安全漏洞) | |
| 0.97 | 15 | XXE Injection | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1699 was patched at 2024-05-15
136.
Incorrect Calculation - FreeRDP (CVE-2024-32040) - Critical [600]
Description: {'vulners_cve_data_all': 'FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 and have connections to servers using the `NSC` codec are vulnerable to integer underflow. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use the NSC codec (e.g. use `-nsc`).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-32040 was patched at 2024-05-15
ubuntu: CVE-2024-32040 was patched at 2024-04-24
137.
Memory Corruption - FreeRDP (CVE-2024-32460) - Critical [600]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-32460 was patched at 2024-05-15
ubuntu: CVE-2024-32460 was patched at 2024-04-24
138.
Remote Code Execution - Perl (CVE-2011-2764) - Critical [600]
Description: The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Quake 3 Shell Injection / Code Execution) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-2764 was patched at 2024-05-15
139.
Remote Code Execution - Redis (CVE-2016-8339) - Critical [600]
Description: A buffer overflow in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Redis CONFIG SET client-output-buffer-limit command Code Execution Vulnerability(CVE-2016-8339)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Redis is an open-source in-memory storage, used as a distributed, in-memory key–value database, cache and message broker, with optional durability | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-8339 was patched at 2024-05-15
140.
Remote Code Execution - Redis (CVE-2021-33026) - Critical [600]
Description: The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Deserialization of Untrusted Data in Flask-Caching Project Flask-Caching) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Redis is an open-source in-memory storage, used as a distributed, in-memory key–value database, cache and message broker, with optional durability | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-33026 was patched at 2024-05-15
141.
Remote Code Execution - Roundcube (CVE-2008-5619) - Critical [600]
Description: html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (
debian: CVE-2008-5619 was patched at 2024-05-15
142.
Remote Code Execution - GNOME desktop (CVE-2008-5987) - High [597]
Description: Untrusted search path vulnerability in the Python interface in Eye of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] XChat PySys_SetArgv函数命令执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5987 was patched at 2024-05-15
143.
Remote Code Execution - PHP (CVE-2007-1001) - High [597]
Description: Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Mac OS X 2007-007更新修复多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-1001 was patched at 2024-05-15
144.
Path Traversal - Windows Kernel (CVE-2009-0841) - High [596]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MapServer mapserv程序多个远程安全漏洞) | |
| 0.7 | 15 | Path Traversal | |
| 0.9 | 14 | Windows Kernel | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0841 was patched at 2024-05-15
145.
Security Feature Bypass - Linux Kernel (CVE-2018-14656) - High [596]
Description: {'vulners_cve_data_all': 'A missing address check in the callers of the show_opcodes() in the Linux kernel allows an attacker to dump the kernel memory at an arbitrary kernel address into the dmesg log.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([canvas] Immunity Canvas: DMESG_LEAK) | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-14656 was patched at 2024-05-15
146.
Authentication Bypass - OpenSSH (CVE-2023-51767) - High [594]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-51767 was patched at 2024-05-15
147.
Command Injection - Python (CVE-2017-2810) - High [594]
Description: {'vulners_cve_data_all': 'An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Tablib Yaml Load Code Execution Vulnerability(CVE-2017-2810)) | |
| 0.97 | 15 | Command Injection | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2810 was patched at 2024-05-15
148.
Remote Code Execution - Apache Tomcat (CVE-2007-0774) - High [592]
Description: Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([d2] DSquare Exploit Pack: D2SEC_MOD_JK, [saint] Apache Tomcat JK Web Server Connector URI worker map buffer overflow, [saint] Apache Tomcat JK Web Server Connector URI worker map buffer overflow, [saint] Apache Tomcat JK Web Server Connector URI worker map buffer overflow, [saint] Apache Tomcat JK Web Server Connector URI worker map buffer overflow, [packetstorm] apache_modjk_overflow.rb.txt) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-0774 was patched at 2024-05-15
149.
Remote Code Execution - Curl (CVE-2013-0249) - High [592]
Description: Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] cURL Buffer Overflow, [seebug] cURL Buffer Overflow Vulnerability, [zdt] cURL Buffer Overflow Vulnerability, [exploitpack] cURL - Buffer Overflow (PoC), [exploitdb] cURL - Buffer Overflow (PoC)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Curl is a command-line tool for transferring data specified with URL syntax | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-0249 was patched at 2024-05-15
150.
Remote Code Execution - iOS (CVE-2012-6096) - High [592]
Description: Multiple stack-based buffer overflows in the get_history function in history.cgi in Nag
debian: CVE-2012-6096 was patched at 2024-05-15
151.
Security Feature Bypass - BIND (CVE-2024-3044) - High [592]
Description: {'vulners_cve_data_all': 'Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.\n', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-3044 was patched at 2024-05-15
redos: CVE-2024-3044 was patched at 2024-05-29
ubuntu: CVE-2024-3044 was patched at 2024-05-28
152.
XXE Injection - PHP (CVE-2011-4107) - High [592]
Description: The simplexml_load_string function in the XML import plug-in (libraries/import/xml.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] phpMyAdmin 3.3.x / 3.4.x Local File Inclusion Via XXE Injection, [exploitpack] phpMyAdmin 3.3.x3.4.x - Local File Inclusion via XML External Entity Injection (Metasploit), [seebug] phpMyAdmin 3.3.X and 3.4.X - Local File Inclusion via XXE Injection, [seebug] phpMyAdmin 3.3.x & 3.4.x - Local File Inclusion via XXE Injection, [exploitdb] phpMyAdmin 3.3.x/3.4.x - Local File Inclusion via XML External Entity Injection (Metasploit)) | |
| 0.97 | 15 | XXE Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4107 was patched at 2024-05-15
153.
Remote Code Execution - Linux Kernel (CVE-2012-3364) - High [590]
Description: Multiple stack-based buffer overflows in the Near Field Communication Controller Interface (NCI) in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Linux Kernel NCI多个远程栈缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-3364 was patched at 2024-05-15
154.
Remote Code Execution - Unknown Product (CVE-2023-44452) - High [589]
Description: {'vulners_cve_data_all': 'Linux Mint Xreader CBT File Parsing Argument Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of CBT files. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22132.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
redos: CVE-2023-44452 was patched at 2024-04-18
155.
Remote Code Execution - DirectX (CVE-2010-3275) - High [588]
Description: lib
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] VLC AMV Dangling Pointer Vulnerability, [seebug] VLC Media Player ".AMV"和".NSV"多个远程缓冲区溢出漏洞, [packetstorm] VLC AMV Dangling Pointer Vulnerability, [metasploit] VLC AMV Dangling Pointer Vulnerability, [exploitdb] VideoLAN VLC Media Player 1.1.4 - 'AMV' Dangling Pointer (Metasploit)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | DirectX | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-3275 was patched at 2024-05-15
156.
Remote Code Execution - DirectX (CVE-2010-3276) - High [588]
Description: lib
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] VLC Media Player ".AMV"和".NSV"多个远程缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | DirectX | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-3276 was patched at 2024-05-15
157.
Remote Code Execution - ImageMagick (CVE-2007-4987) - High [588]
Description: Off-by-one error in the ReadBlobString function in blob.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ImageMagick blob.c文件单字节缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-4987 was patched at 2024-05-15
158.
Remote Code Execution - Perl (CVE-2008-2363) - High [588]
Description: The PartsBatch class in Pan 0.132 and earlier does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Pan .nzb文件解析堆溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-2363 was patched at 2024-05-15
159.
Remote Code Execution - Python (CVE-2009-3850) - High [588]
Description: Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Blender 2.342.35a2.42.49b - .blend Command Injection, [packetstorm] Core Security Technologies Advisory 2009.0912, [seebug] Blender 2.34 2.35a 2.4 2.49b .blend File Command Injection, [seebug] Blender 2.34, 2.35a, 2.4, 2.49b .blend File Command Injection, [seebug] Blender 2.34 2.35a 2.4 2.49b .blend File Command Injection, [exploitdb] Blender 2.34/2.35a/2.4/2.49b - '.blend' Command Injection) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3850 was patched at 2024-05-15
160.
Remote Code Execution - Redis (CVE-2022-31144) - High [588]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Out-of-bounds Write in Redis) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Redis is an open-source in-memory storage, used as a distributed, in-memory key–value database, cache and message broker, with optional durability | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-31144 was patched at 2024-05-15
161.
Remote Code Execution - Wireshark (CVE-2009-4376) - High [588]
Description: Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Wireshark 1.2.5版本修复多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4376 was patched at 2024-05-15
162.
Remote Code Execution - Wireshark (CVE-2011-1591) - High [588]
Description: Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in
debian: CVE-2011-1591 was patched at 2024-05-15
163.
Authentication Bypass - Unknown Product (CVE-2023-22602) - High [585]
Description: {'vulners_cve_data_all': 'When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass.\n\nThe authentication bypass occurs when Shiro and Spring Boot are using different pattern-matching techniques. Both Shiro and Spring Boot < 2.6 default to Ant style pattern matching.\nMitigation: Update to Apache Shiro 1.11.0, or set the following Spring Boot configuration value: `spring.mvc.pathmatch.matching-strategy = ant_path_matcher`\n\n\n', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-22602 was patched at 2024-05-15
164.
Denial of Service - Linux Kernel (CVE-2011-2189) - High [584]
Description: net/core/net_namespace.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object) website | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-2189 was patched at 2024-05-15
165.
Security Feature Bypass - Linux Kernel (CVE-2021-4148) - High [584]
Description: {'vulners_cve_data_all': 'A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity check may allow a local attacker with user privilege to cause a denial of service (DOS) problem.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-4148 was patched at 2024-05-15
166.
Code Injection - PHP (CVE-2022-23808) - High [580]
Description: An issue was discovered in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Cross-site Scripting in Phpmyadmin) | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-23808 was patched at 2024-05-15
167.
Remote Code Execution - BIND (CVE-2009-0317) - High [580]
Description: Untrusted search path vulnerability in the Python language
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] XChat PySys_SetArgv函数命令执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0317 was patched at 2024-05-15
168.
Remote Code Execution - FFmpeg (CVE-2010-3429) - High [580]
Description: flicvideo.c in libavcodec 0.6 and earlier in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg libavcodec "vmd decode()"堆缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-3429 was patched at 2024-05-15
169.
Remote Code Execution - FFmpeg (CVE-2010-3908) - High [580]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg畸形".wmv"文件解析内存破坏远程代码执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-3908 was patched at 2024-05-15
170.
Remote Code Execution - FFmpeg (CVE-2011-0722) - High [580]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg Real Media文件解析内存破坏远程代码执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-0722 was patched at 2024-05-15
171.
Remote Code Execution - FFmpeg (CVE-2011-0723) - High [580]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg畸形"VC1"文件解析内存破坏远程代码执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-0723 was patched at 2024-05-15
172.
Remote Code Execution - FFmpeg (CVE-2012-0859) - High [580]
Description: The render_line function in the vorbis codec (vorbis.c) in libavcodec in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Google Chrome 15.x MKV和Vorbis媒体处理漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-0859 was patched at 2024-05-15
173.
Remote Code Execution - vim (CVE-2009-0316) - High [580]
Description: Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Vim PySys_SetArgv函数本地命令执行漏洞, [seebug] XChat PySys_SetArgv函数命令执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Vim is a free and open-source, screen-based text editor program | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0316 was patched at 2024-05-15
174.
Security Feature Bypass - Google Chrome (CVE-2021-30531) - High [579]
Description: Insufficient policy enforcement in Content Security Policy in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30531 was patched at 2024-05-15
175.
Security Feature Bypass - Google Chrome (CVE-2021-30534) - High [579]
Description: Insufficient policy enforcement in iFrameSandbox in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30534 was patched at 2024-05-15
176.
Security Feature Bypass - Google Chrome (CVE-2021-30540) - High [579]
Description: {'vulners_cve_data_all': 'Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafted HTML page.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30540 was patched at 2024-05-15
177.
Remote Code Execution - Perl (CVE-2004-1388) - High [576]
Description: Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7 allows remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Berlios GPSD Format String Vulnerability, [canvas] Immunity Canvas: GPSD) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-1388 was patched at 2024-05-15
178.
Remote Code Execution - Perl (CVE-2008-2371) - High [576]
Description: Heap-based buffer overflow in pcre_compile.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] PCRE pcre_compile.c文件堆溢出漏洞, [seebug] PCRE 规则表达式堆缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-2371 was patched at 2024-05-15
179.
Remote Code Execution - Perl (CVE-2013-0333) - High [576]
Description: lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not pro
debian: CVE-2013-0333 was patched at 2024-05-15
180.
Remote Code Execution - Perl (CVE-2013-1800) - High [576]
Description: The crack gem 0.3.1 and earlier for Ruby does not pro
debian: CVE-2013-1800 was patched at 2024-05-15
181.
Remote Code Execution - Perl (CVE-2013-1802) - High [576]
Description: The extlib gem 0.9.15 and earlier for Ruby does not pro
debian: CVE-2013-1802 was patched at 2024-05-15
182.
Remote Code Execution - Roundcube (CVE-2016-9920) - High [576]
Description: steps/mail/sendmail.inc in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Roundcube 1.2.2: Command Execution via Email) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Roundcube is a web-based IMAP email client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-9920 was patched at 2024-05-15
183.
Unknown Vulnerability Type - Jetty (CVE-2021-34429) - High [576]
Description: {'vulners_cve_data_all': 'For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Jetty is a Java based web server and servlet engine | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-34429 was patched at 2024-05-15
184.
Code Injection - QEMU (CVE-2017-8284) - High [575]
Description: {'vulners_cve_data_all': 'The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the instruction size, which allows local users to gain privileges by creating a modified basic block that injects code into a setuid program, as demonstrated by procmail. NOTE: the vendor has stated "this bug does not violate any security guarantees QEMU makes.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | Code Injection | |
| 0.7 | 14 | QEMU is a generic and open source machine & userspace emulator and virtualizer | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-8284 was patched at 2024-05-15
185.
Security Feature Bypass - iOS (CVE-2014-2913) - High [575]
Description: {'vulners_cve_data_all': 'Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character in the -a option to libexec/check_nrpe. NOTE: this issue is disputed by multiple parties. It has been reported that the vendor allows newlines as "expected behavior." Also, this issue can only occur when the administrator enables the "dont_blame_nrpe" option in nrpe.conf despite the "HIGH security risk" warning within the comments', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] NRPE 2.15 Remote Command Execution, [seebug] NRPE 2.15 - Remote Code Execution Vulnerability, [exploitpack] NRPE 2.15 - Remote Code Execution, [zdt] NRPE 2.15 - Remote Code Execution Vulnerability, [exploitdb] NRPE 2.15 - Remote Code Execution) | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-2913 was patched at 2024-05-15
186.
Remote Code Execution - Mozilla Firefox (CVE-2006-0295) - High [573]
Description: Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Firefox location.QueryInterface() Code Execution, [packetstorm] firefox_queryinterface_mac.pm.txt, [packetstorm] firefox_queryinterface.pm.txt, [saint] Mozilla Firefox QueryInterface method memory corruption, [saint] Mozilla Firefox QueryInterface method memory corruption, [saint] Mozilla Firefox QueryInterface method memory corruption, [saint] Mozilla Firefox QueryInterface method memory corruption) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-0295 was patched at 2024-05-15
187.
Authentication Bypass - Apache ActiveMQ (CVE-2014-3612) - High [572]
Description: The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Apache ActiveMQ 5.0.0 - 5.10.0 JAAS LDAPLoginModule empty password authentication Vulnerability) | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-3612 was patched at 2024-05-15
188.
Authentication Bypass - Python (CVE-2013-1895) - High [572]
Description: The py-bcrypt module before 0.3 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Python 'py-bcrypt' 模块身份验证绕过漏洞(CVE-2013-1895)) | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-1895 was patched at 2024-05-15
189.
Denial of Service - Linux Kernel (CVE-2017-16996) - High [572]
Description: kernel/bpf/verifier.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Linux Kernel >= 4.9 eBPF memory corruption bugs Vulnerability) | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-16996 was patched at 2024-05-15
190.
Denial of Service - Linux Kernel (CVE-2017-5972) - High [572]
Description: The TCP stack in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Linux Kernel 3.10.0 (CentOS7) Denial Of Service Exploit, [packetstorm] CentOS7 Kernel Denial Of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-5972 was patched at 2024-05-15
191.
Information Disclosure - Linux Kernel (CVE-2018-7273) - High [572]
Description: {'vulners_cve_data_all': 'In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the function show_floppy in drivers/block/floppy.c. An attacker can read this information from dmesg and use the addresses to find the locations of kernel code and data and bypass kernel security protections such as KASLR.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Linux Kernel show_floppy KASLR Address Leak, [zdt] Linux Kernel < 4.15.4 - show_floppy KASLR Address Leak Exploit) | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-7273 was patched at 2024-05-15
192.
Information Disclosure - Linux Kernel (CVE-2022-4543) - High [572]
Description: {'vulners_cve_data_all': 'A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Linux Linux Kernel) | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-4543 was patched at 2024-05-15
193.
Remote Code Execution - Cacti (CVE-2023-39358) - High [571]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-39358 was patched at 2024-05-15
194.
Remote Code Execution - Cacti (CVE-2024-31445) - High [571]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-31445 was patched at 2024-05-15
195.
Remote Code Execution - TRIE (CVE-2022-2566) - High [571]
Description: A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all en
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | TRIE | |
| 0.9 | 10 | CVSS Base Score is 9.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-2566 was patched at 2024-05-15
196.
Code Injection - Perl (CVE-2011-2506) - High [570]
Description: setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not pro
debian: CVE-2011-2506 was patched at 2024-05-15
197.
Arbitrary File Reading - PHP (CVE-2014-2383) - High [567]
Description: dompdf.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([wpexploit] Multiple plugins - Unauthenticated Dompdf Local File Inclusion (LFI), [exploitpack] dompdf 0.6.0 - dompdf.php?read Arbitrary File Read, [zdt] dompdf 0.6.0 Arbitrary File Read Vulnerability, [packetstorm] dompdf 0.6.0 Arbitrary File Read, [seebug] dompdf 0.6.0 (dompdf.php, read param) - Arbitrary File Read, [exploitdb] dompdf 0.6.0 - 'dompdf.php?read' Arbitrary File Read) | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-2383 was patched at 2024-05-15
198.
Information Disclosure - Safari (CVE-2009-1718) - High [567]
Description: WebKit in Apple
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1718 was patched at 2024-05-15
199.
Elevation of Privilege - BIND (CVE-2019-2025) - High [566]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Android - binder Use-After-Free via racy Initialization of ->allow_user_free Exploit) | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-2025 was patched at 2024-05-15
200.
Remote Code Execution - Perl (CVE-2012-4409) - High [564]
Description: Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] mcrypt 2.5.8 Stack Based Overflow, [exploitpack] mcrypt 2.5.8 - Local Stack Overflow, [seebug] mcrypt <= 2.5.8 Stack Based Overflow, [exploitdb] mcrypt 2.5.8 - Local Stack Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-4409 was patched at 2024-05-15
201.
Remote Code Execution - Python (CVE-2008-5984) - High [564]
Description: Untrusted search path vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Dia Python插件使用不安全搜索路径漏洞, [seebug] XChat PySys_SetArgv函数命令执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5984 was patched at 2024-05-15
202.
Remote Code Execution - Python (CVE-2008-5985) - High [564]
Description: Untrusted search path vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Epiphany PySys_SetArgv函数命令执行漏, [seebug] XChat PySys_SetArgv函数命令执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5985 was patched at 2024-05-15
203.
Remote Code Execution - Python (CVE-2008-5986) - High [564]
Description: Untrusted search path vulnerability in the (1) "VST plugin with
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] XChat PySys_SetArgv函数命令执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5986 was patched at 2024-05-15
204.
Remote Code Execution - Python (CVE-2009-0314) - High [564]
Description: Untrusted search path vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] gedit PySys_SetArgv函数代码执行漏洞, [seebug] XChat PySys_SetArgv函数命令执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0314 was patched at 2024-05-15
205.
Remote Code Execution - Python (CVE-2009-0315) - High [564]
Description: Untrusted search path vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] XChat PySys_SetArgv函数命令执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0315 was patched at 2024-05-15
206.
Remote Code Execution - Python (CVE-2009-0318) - High [564]
Description: Untrusted search path vulnerability in the GObject
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] XChat PySys_SetArgv函数命令执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0318 was patched at 2024-05-15
207.
Remote Code Execution - Python (CVE-2013-5093) - High [564]
Description: The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Graphite Web Unsafe Pickle Handling, [zdt] Graphite Web Unsafe Pickle Handling Exploit) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-5093 was patched at 2024-05-15
208.
Remote Code Execution - Python (CVE-2013-5942) - High [564]
Description: Graphite 0.9.5 through 0.9.10 uses the pickle
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Graphite Web Unsafe Pickle Handling, [zdt] Graphite Web Unsafe Pickle Handling Exploit) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-5942 was patched at 2024-05-15
209.
Security Feature Bypass - iOS (CVE-2023-45857) - High [563]
Description: {'vulners_cve_data_all': 'An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-45857 was patched at 2024-05-15
210.
Information Disclosure - SQLite (CVE-2021-42523) - High [562]
Description: There are two
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0.7 | 14 | SQLite is a database engine written in the C programming language | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-42523 was patched at 2024-05-15
211.
Denial of Service - Windows Kernel (CVE-2008-4609) - High [560]
Description: The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Windows 2000 TCP/IP窗口大小拒绝服务漏洞(MS09-048)) | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | Windows Kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-4609 was patched at 2024-05-15
212.
Remote Code Execution - Cacti (CVE-2024-31459) - High [559]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-31459 was patched at 2024-05-15
213.
Remote Code Execution - GDI (CVE-2006-0106) - High [559]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([saint] Windows WMF handling vulnerability, [saint] Windows WMF handling vulnerability, [saint] Windows WMF handling vulnerability, [saint] Windows WMF handling vulnerability, [canvas] Immunity Canvas: WMF_SETABORT, [packetstorm] Windows XP/2003/Vista Metafile Escape() SetAbortProc Code Execution) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | GDI | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-0106 was patched at 2024-05-15
214.
Remote Code Execution - Libarchive (CVE-2016-4301) - High [559]
Description: Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Libarchive mtree parse_device Code Execution Vulnerability(CVE-2016-4301)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Multi-format archive and compression library | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-4301 was patched at 2024-05-15
215.
Remote Code Execution - NetBIOS (CVE-2014-9377) - High [559]
Description: Heap-based buffer overflow in the nbns_spoof function in plug-ins/nbns_spoof/nbns_spoof.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service or possibly
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Ettercap 0.8.0 / 0.8.1 Denial Of Service, [exploitpack] Ettercap 0.8.0 0.8.1 - Multiple Denial of Service Vulnerabilities, [exploitdb] Ettercap 0.8.0 < 0.8.1 - Multiple Denial of Service Vulnerabilities) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | NetBIOS (Network Basic Input/Output System) is a network service that enables applications on different computers to communicate with each other across a local area network (LAN) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-9377 was patched at 2024-05-15
216.
Remote Code Execution - TLS (CVE-2006-6170) - High [559]
Description: Buffer overflow in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] vd_proftpd.pm.txt, [packetstorm] ProFTPD 1.2 - 1.3.0 sreplace Buffer Overflow (Linux)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | TLS | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-6170 was patched at 2024-05-15
217.
Remote Code Execution - TLS (CVE-2017-2784) - High [559]
Description: An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ARM Mbedtls x509 ECDSA invalid public key Remote Code Execution Vulnerability(CVE-2017-2784)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | TLS | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2784 was patched at 2024-05-15
218.
Remote Code Execution - TLS (CVE-2021-21374) - High [559]
Description: Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, "nimble refresh" fetches a list of Nimble packages over HTTPS without full verification of the SSL/
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | TLS | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-21374 was patched at 2024-05-15
219.
Remote Code Execution - nginx (CVE-2009-2629) - High [559]
Description: Buffer underflow in src/http/ngx_http_parse.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] nginx HTTP请求远程缓冲区溢出漏洞, [canvas] Immunity Canvas: NGINX) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2629 was patched at 2024-05-15
220.
Remote Code Execution - nginx (CVE-2014-0133) - High [559]
Description: Heap-based buffer overflow in the SPDY implementation in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Nginx SPDY缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-0133 was patched at 2024-05-15
221.
Security Feature Bypass - Unknown Product (CVE-2023-24023) - High [559]
Description: {'vulners_cve_data_all': 'Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-in-the-middle attacks that force a short key length, and might lead to discovery of the encryption key and live injection, aka BLUFFS.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2023-24023 was patched at 2024-05-22
debian: CVE-2023-24023 was patched at 2024-05-15
oraclelinux: CVE-2023-24023 was patched at 2024-05-02, 2024-05-23
redhat: CVE-2023-24023 was patched at 2024-05-22
ubuntu: CVE-2023-24023 was patched at 2024-04-19, 2024-04-23
222.
Command Injection - Python (CVE-2024-23829) - High [558]
Description: aiohttp is an asynchronous HTTP client/server framework for asyncio and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | Command Injection | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-23829 was patched at 2024-05-15
redos: CVE-2024-23829 was patched at 2024-04-23
223.
Information Disclosure - Unknown Product (CVE-2021-40402) - High [558]
Description: {'vulners_cve_data_all': 'An out-of-bounds read vulnerability exists in the RS-274X aperture macro multiple outline primitives functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.7.1 and 2.8.0. A specially-crafted Gerber file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-40402 was patched at 2024-05-15
224.
Security Feature Bypass - Perl (CVE-2018-6829) - High [558]
Description: {'vulners_cve_data_all': 'cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-6829 was patched at 2024-05-15
225.
Security Feature Bypass - Perl (CVE-2024-1135) - High [558]
Description: {'vulners_cve_data_all': 'Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security restrictions and access restricted endpoints. This issue is due to Gunicorn's handling of Transfer-Encoding headers, where it incorrectly processes requests with multiple, conflicting Transfer-Encoding headers, treating them as chunked regardless of the final encoding specified. This vulnerability allows for a range of attacks including cache poisoning, session manipulation, and data exposure.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-1135 was patched at 2024-05-15
redhat: CVE-2024-1135 was patched at 2024-05-22
226.
XXE Injection - Perl (CVE-2013-0340) - High [558]
Description: expat 2.1.0 and earlier does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | XXE Injection | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-0340 was patched at 2024-05-15
227.
XXE Injection - Perl (CVE-2024-23525) - High [558]
Description: The Spreadsheet::ParseXLSX package before 0.30 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | XXE Injection | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-23525 was patched at 2024-05-15
ubuntu: CVE-2024-23525 was patched at 2024-05-09
228.
Denial of Service - Binutils (CVE-2017-16830) - High [555]
Description: The print_gnu_property_note function in readelf.c in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-16830 was patched at 2024-05-15
229.
Denial of Service - Binutils (CVE-2017-17126) - High [555]
Description: The load_debug_section function in readelf.c in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-17126 was patched at 2024-05-15
230.
Denial of Service - Binutils (CVE-2022-47673) - High [555]
Description: An issue was discovered in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-47673 was patched at 2024-05-15
231.
Denial of Service - Binutils (CVE-2022-47696) - High [555]
Description: An issue was discovered
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-47696 was patched at 2024-05-15
232.
Denial of Service - GNOME desktop (CVE-2018-11396) - High [555]
Description: ephy-session.c in libephymain.so in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Epiphany 3.28.2.1 - Denial of Service, [exploitdb] Epiphany 3.28.2.1 - Denial of Service, [packetstorm] Epiphany 3.28.2.1 Denial Of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-11396 was patched at 2024-05-15
233.
Denial of Service - ICMP (CVE-2016-1879) - High [555]
Description: The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, when the kernel is configured for IPv6, allows remote attackers to cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] FreeBSD SCTP ICMPv6 - Error Processing, [packetstorm] FreeBSD SCTP ICMPv6 Denial Of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | The Internet Control Message Protocol (ICMP) is a network layer protocol used by network devices to diagnose network communication issues | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-1879 was patched at 2024-05-15
234.
Denial of Service - OpenSSL (CVE-2006-2937) - High [555]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2006-007存在多个安全漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-2937 was patched at 2024-05-15
235.
Denial of Service - OpenSSL (CVE-2006-2940) - High [555]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2006-007存在多个安全漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-2940 was patched at 2024-05-15
236.
Denial of Service - OpenSSL (CVE-2016-7052) - High [555]
Description: crypto/x509/x509_vfy.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Orion Elite Hidden IP Browser Pro 7.9 OpenSSL / Tor / Man-In-The-Middle) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-7052 was patched at 2024-05-15
237.
Denial of Service - OpenSSL (CVE-2017-3730) - High [555]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-3730 was patched at 2024-05-15
238.
Denial of Service - PHP (CVE-2018-6389) - High [555]
Description: In WordPress through 4.9.2, unauthenticated attackers can cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] WordPress Core Denial Of Service, [packetstorm] WordPress Core load-scripts.php Denial Of Service, [zdt] WordPress Core - load-scripts.php Denial of Service Exploit, [seebug] WordPress Core - 'load-scripts.php' Denial of Service(CVE-2018-6389)) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-6389 was patched at 2024-05-15
239.
Denial of Service - Samba (CVE-2008-4314) - High [555]
Description: smbd in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Samba smbd远程信息泄露漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 0.8 | 10 | CVSS Base Score is 8.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-4314 was patched at 2024-05-15
240.
Denial of Service - Webkit (CVE-2018-11646) - High [555]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] WebKitGTK+ 2.21.3 - Crash (PoC), [exploitpack] WebKitGTK+ 2.21.3 - WebKitFaviconDatabase Denial of Service (Metasploit), [packetstorm] WebKitGTK+ 2.21.3 pageURL Mishandling Denial Of Service, [packetstorm] WebKitGTK+ WebKitFaviconDatabase Denial Of Service, [zdt] WebKitGTK+ < 2.21.3 - pageURL Mishandling Crash (PoC) Exploit, [zdt] WebKitGTK+ < 2.21.3 - #WebKitFaviconDatabase DoS Exploit, [metasploit] WebKitGTK+ WebKitFaviconDatabase DoS, [exploitdb] WebKitGTK+ < 2.21.3 - 'WebKitFaviconDatabase' Denial of Service (Metasploit), [exploitdb] WebKitGTK+ < 2.21.3 - Crash (PoC)) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | WebKit is a browser engine developed by Apple and primarily used in its Safari web browser, as well as all web browsers on iOS and iPadOS | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-11646 was patched at 2024-05-15
241.
Information Disclosure - OpenSSH (CVE-2018-15919) - High [555]
Description: {'vulners_cve_data_all': 'Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or "oracle") as a vulnerability.'', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object) website | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-15919 was patched at 2024-05-15
242.
Security Feature Bypass - Google Chrome (CVE-2021-30539) - High [555]
Description: Insufficient policy enforcement in content security policy in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30539 was patched at 2024-05-15
243.
Denial of Service - Kerberos (CVE-2009-3295) - High [553]
Description: The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MIT Kerberos KDC跨域Referral空指针引用拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3295 was patched at 2024-05-15
244.
Remote Code Execution - Perl (CVE-2008-1333) - High [552]
Description: Format string vulnerability in Asterisk Open Source 1.6.x before 1.6.0-beta6 might allow remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Asterisk日志函数及管理器远程格式串处理漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1333 was patched at 2024-05-15
245.
Cross Site Scripting - PHP (CVE-2017-5367) - High [550]
Description: Multiple reflected
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] ZoneMinder - Multiple Vulnerabilities, [packetstorm] ZoneMinder XSS / CSRF / File Disclosure / Authentication Bypass) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-5367 was patched at 2024-05-15
246.
Cross Site Scripting - PHP (CVE-2019-12094) - High [550]
Description: Horde Groupware Webmail Edition through 5.2.22 allows
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitdb] Horde Webmail 5.2.22 - Multiple Vulnerabilities, [packetstorm] Horde Webmail 5.2.22 XSS / CSRF / SQL Injection / Code Execution, [zdt] Horde Webmail 5.2.22 - Multiple Vulnerabilities, [zdt] Horde Webmail 5.2.22 XSS / CSRF / SQL Injection / Code Execution Exploit, [exploitpack] Horde Webmail 5.2.22 - Multiple Vulnerabilities) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-12094 was patched at 2024-05-15
247.
Cross Site Scripting - PHP (CVE-2019-8937) - High [550]
Description: HotelDruid 2.3.0 has
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] HotelDruid 2.3 - Cross-Site Scripting Vulnerability, [exploitpack] HotelDruid 2.3 - Cross-Site Scripting, [packetstorm] HotelDruid 2.3 Cross Site Scripting, [exploitdb] HotelDruid 2.3 - Cross-Site Scripting) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-8937 was patched at 2024-05-15
248.
Cross Site Scripting - Safari (CVE-2017-2504) - High [550]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] WebKit Editor::Command::execute Universal Cross Site Scripting, [zdt] Apple WebKit / Safari 10.0.3(12602.4.8) - Editor::Command::execute Universal Cross-Site Scripting Ex, [seebug] WebKit: UXSS via Editor::Command::execute(CVE-2017-2504)) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2504 was patched at 2024-05-15
249.
Cross Site Scripting - Safari (CVE-2017-2508) - High [550]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] WebKit - ContainerNode::parserInsertBefore Universal Cross-Site Scripting Exploit, [seebug] WebKit: UXSS via ContainerNode::parserInsertBefore(CVE-2017-2508)) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2508 was patched at 2024-05-15
250.
Cross Site Scripting - Safari (CVE-2017-2528) - High [550]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] WebKit CachedFrame Universal Cross Site Scripting, [seebug] WebKit: UXSS: CachedFrame doesn't detach openers(CVE-2017-2528), [zdt] WebKit CachedFrame Universal Cross Site Scripting Vulnerability) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2528 was patched at 2024-05-15
251.
Remote Code Execution - Cacti (CVE-2024-31460) - High [547]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-31460 was patched at 2024-05-15
252.
Remote Code Execution - nginx (CVE-2012-2089) - High [547]
Description: Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] nginx 'ngx_http_mp4_module.c'缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-2089 was patched at 2024-05-15
253.
Information Disclosure - Roundcube (CVE-2018-19205) - High [545]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenPGP、S/MIME information disclosure (CVE-2017-17688,CVE-2017-17689)) | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | Roundcube is a web-based IMAP email client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-19205 was patched at 2024-05-15
254.
Remote Code Execution - FFmpeg (CVE-2009-4638) - High [545]
Description: Integer overflow in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg多个媒体文件解析拒绝服务和代码执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4638 was patched at 2024-05-15
255.
Remote Code Execution - FFmpeg (CVE-2009-4640) - High [545]
Description: Array index error in vorbis_dec.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg多个媒体文件解析拒绝服务和代码执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4640 was patched at 2024-05-15
256.
Denial of Service - PHP (CVE-2016-6896) - High [544]
Description: Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([metasploit] WordPress Traversal Directory DoS, [exploitpack] WordPress 4.5.3 - Directory Traversal Denial of Service, [zdt] WordPress 4.5.3 - Directory Traversal / Denial of Service, [exploitdb] WordPress Core 4.5.3 - Directory Traversal / Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-6896 was patched at 2024-05-15
257.
Denial of Service - Safari (CVE-2009-1692) - High [544]
Description: WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] ECMAScript Denial Of Service, [seebug] Multiple Web Browsers Denial of Service Exploit (1 bug to rule them all), [exploitpack] Multiple Browsers - Denial of Service, [exploitdb] Multiple Browsers - Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1692 was patched at 2024-05-15
258.
Denial of Service - Samba (CVE-2007-0452) - High [544]
Description: smbd in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Samba延迟CIFS文件打开拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-0452 was patched at 2024-05-15
259.
Memory Corruption - APT (CVE-2009-1177) - High [544]
Description: Multiple stack-based
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MapServer mapserv程序多个远程安全漏洞) | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1177 was patched at 2024-05-15
260.
Memory Corruption - Google Chrome (CVE-2019-5866) - High [544]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-5866 was patched at 2024-05-15
261.
Memory Corruption - Safari (CVE-2023-32409) - High [544]
Description: {'vulners_cve_data_all': 'The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been actively exploited.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (cisa_kev object) website | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-32409 was patched at 2024-05-15
262.
Path Traversal - PHP (CVE-2005-3347) - High [544]
Description: Multiple
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Hardened-PHP Project Security Advisory 2005-21.81) | |
| 0.7 | 15 | Path Traversal | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-3347 was patched at 2024-05-15
263.
Path Traversal - PHP (CVE-2014-8959) - High [544]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin 4.2.12 /gis_data_editor.php 本地文件包含漏洞) | |
| 0.7 | 15 | Path Traversal | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-8959 was patched at 2024-05-15
264.
Security Feature Bypass - Google Chrome (CVE-2021-30532) - High [544]
Description: Insufficient policy enforcement in Content Security Policy in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30532 was patched at 2024-05-15
265.
Security Feature Bypass - Google Chrome (CVE-2021-30537) - High [544]
Description: Insufficient policy enforcement in cookies in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30537 was patched at 2024-05-15
266.
Security Feature Bypass - Google Chrome (CVE-2021-30538) - High [544]
Description: Insufficient policy enforcement in content security policy in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30538 was patched at 2024-05-15
267.
Security Feature Bypass - Google Chrome (CVE-2021-30596) - High [544]
Description: {'vulners_cve_data_all': 'Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30596 was patched at 2024-05-15
268.
Arbitrary File Reading - PHP (CVE-2008-0196) - High [543]
Description: Multiple directory traversal vulnerabilities in WordPress 2.0.11 and earlier allow remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] WordPress Core MU Plugins - admin.php Privileges Unchecked Multiple Information Disclosures, [packetstorm] Core Security Technologies Advisory 2009.0515, [seebug] WordPress Privileges Unchecked in admin.php and Multiple Information Disclosures, [seebug] WordPress Privileges Unchecked in admin.php and Multiple Information, [exploitdb] WordPress Core / MU / Plugins - '/admin.php' Privileges Unchecked / Multiple Information Disclosures) | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-0196 was patched at 2024-05-15
269.
Information Disclosure - Mozilla Firefox (CVE-2019-13075) - High [543]
Description: Tor Browser through 8.5.3 has an
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-13075 was patched at 2024-05-15
270.
Information Disclosure - OpenSSH (CVE-2016-20012) - High [543]
Description: {'vulners_cve_data_all': 'OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-20012 was patched at 2024-05-15
271.
Information Disclosure - PHP (CVE-2009-2334) - High [543]
Description: wp-admin/admin.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] WordPress wp-admin/admin.php模块错误权限检查漏洞, [seebug] WordPress Privileges Unchecked in admin.php and Multiple Information Disclosures, [seebug] WordPress Privileges Unchecked in admin.php and Multiple Information, [exploitpack] WordPress Core MU Plugins - admin.php Privileges Unchecked Multiple Information Disclosures, [packetstorm] Core Security Technologies Advisory 2009.0515, [exploitdb] WordPress Core / MU / Plugins - '/admin.php' Privileges Unchecked / Multiple Information Disclosures) | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2334 was patched at 2024-05-15
272.
Information Disclosure - PHP (CVE-2012-4219) - High [543]
Description: show_config_errors.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin 'show_config_errors.php'完整路径信息泄露漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-4219 was patched at 2024-05-15
273.
Cross Site Scripting - Apache HTTP Server (CVE-2006-3918) - High [542]
Description: http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2)
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] ProCheckUp Security Advisory 2007.37, [packetstorm] Oracle HTTP Server Header Cross Site Scripting, [exploitpack] Oracle HTTP Server - Cross-Site Scripting Header Injection, [seebug] Oracle HTTP Server - XSS Header Injection, [exploitdb] Oracle HTTP Server - Cross-Site Scripting Header Injection) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3918 was patched at 2024-05-15
274.
Cross Site Scripting - Apache HTTP Server (CVE-2007-6203) - High [542]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] ProCheckUp Security Advisory 2007.37, [packetstorm] Oracle HTTP Server Header Cross Site Scripting, [exploitpack] Oracle HTTP Server - Cross-Site Scripting Header Injection, [seebug] Oracle HTTP Server - XSS Header Injection, [exploitdb] Oracle HTTP Server - Cross-Site Scripting Header Injection) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-6203 was patched at 2024-05-15
275.
Remote Code Execution - Flatpak (CVE-2024-32462) - High [542]
Description: Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app could
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | Flatpak is a utility for software deployment and package management for Linux | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-32462 was patched at 2024-04-19, 2024-05-15
redos: CVE-2024-32462 was patched at 2024-05-07
276.
Remote Code Execution - GPAC (CVE-2021-32136) - High [542]
Description: Heap buffer overflow in the print_udta function in MP4Box in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32136 was patched at 2024-05-15
277.
Remote Code Execution - GPAC (CVE-2021-32268) - High [542]
Description: Buffer overflow vulnerability in function gf_fprintf in os_file.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32268 was patched at 2024-05-15
278.
Remote Code Execution - GPAC (CVE-2021-32439) - High [542]
Description: Buffer overflow in the stbl_AppendSize function in MP4Box in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32439 was patched at 2024-05-15
279.
Remote Code Execution - GPAC (CVE-2021-33362) - High [542]
Description: Stack buffer overflow in the hevc_parse_vps_extension function in MP4Box in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-33362 was patched at 2024-05-15
280.
Denial of Service - Kerberos (CVE-2009-0847) - High [541]
Description: The asn1buf_imbed function in the ASN.1 decoder in MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MIT Kerberos SPNEGO和ASN.1多个拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0847 was patched at 2024-05-15
281.
Security Feature Bypass - TLS (CVE-2021-29495) - High [541]
Description: {'vulners_cve_data_all': 'Nim is a statically typed compiled systems programming language. In Nim standard library before 1.4.2, httpClient SSL/TLS certificate verification was disabled by default. Users can upgrade to version 1.4.2 to receive a patch or, as a workaround, set "verifyMode = CVerifyPeer" as documented.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | TLS | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-29495 was patched at 2024-05-15
282.
Security Feature Bypass - TLS (CVE-2021-34825) - High [541]
Description: {'vulners_cve_data_all': 'Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | TLS | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-34825 was patched at 2024-05-15
283.
Remote Code Execution - Perl (CVE-2005-3962) - High [540]
Description: Integer overflow in the format string functionality (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Perl格式串处理整数溢出漏洞, [seebug] Apple Mac OS X 2006-007存在多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-3962 was patched at 2024-05-15
284.
Remote Code Execution - Perl (CVE-2011-4089) - High [540]
Description: The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] bzexe /tmp Race Condition) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4089 was patched at 2024-05-15
285.
Denial of Service - BIND (CVE-2006-4095) - High [539]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2007-005多个安全漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4095 was patched at 2024-05-15
286.
Denial of Service - Curl (CVE-2023-38039) - High [539]
Description: {'vulners_cve_data_all': 'When curl retrieves an HTTP response, it stores the incoming headers so that\nthey can be accessed later via the libcurl headers API.\n\nHowever, curl did not have a limit in how many or how large headers it would\naccept in a response, allowing a malicious server to stream an endless series\nof headers and eventually cause curl to run out of heap memory.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | Curl is a command-line tool for transferring data specified with URL syntax | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-38039 was patched at 2024-05-15
287.
Denial of Service - Point-to-Point Tunneling Protocol (CVE-2003-0213) - High [539]
Description: ctrlpacket.c in PoPToP
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Poptop Negative Read Overflow) | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | The Point to Point Tunneling Protocol (PPTP) is a network protocol used to create VPN tunnels between public networks | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0213 was patched at 2024-05-15
288.
Denial of Service - QEMU (CVE-2019-20175) - High [539]
Description: An issue was discovered in ide_dma_cb() in hw/ide/core.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | QEMU is a generic and open source machine & userspace emulator and virtualizer | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-20175 was patched at 2024-05-15
289.
Denial of Service - SQLite (CVE-2021-31239) - High [539]
Description: An issue found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | SQLite is a database engine written in the C programming language | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-31239 was patched at 2024-05-15
290.
Denial of Service - iOS (CVE-2019-10742) - High [539]
Description: Ax
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Improper Handling of Exceptional Conditions in Axios) | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-10742 was patched at 2024-05-15
291.
Cross Site Scripting - PHP (CVE-2021-38603) - High [538]
Description: PluXML 5.8.7 allows core/admin/profil.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-38603 was patched at 2024-05-15
292.
Memory Corruption - Chromium (CVE-2024-3832) - High [538]
Description: {'vulners_cve_data_all': 'Object corruption in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-3832 was patched at 2024-04-20, 2024-05-15
redos: CVE-2024-3832 was patched at 2024-05-07
293.
Memory Corruption - Chromium (CVE-2024-3833) - High [538]
Description: {'vulners_cve_data_all': 'Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-3833 was patched at 2024-04-20, 2024-05-15
redos: CVE-2024-3833 was patched at 2024-05-07
294.
Memory Corruption - Chromium (CVE-2024-4331) - High [538]
Description: Use after free in Picture In Picture in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-4331 was patched at 2024-05-02, 2024-05-15
295.
Memory Corruption - Chromium (CVE-2024-4368) - High [538]
Description: Use after free in Dawn in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-4368 was patched at 2024-05-02, 2024-05-15
296.
Memory Corruption - Mozilla Firefox (CVE-2024-3855) - High [538]
Description: In certain cases the JIT incorrectly optimized MSubstr operations, which led to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
ubuntu: CVE-2024-3855 was patched at 2024-04-24
297.
Memory Corruption - Mozilla Firefox (CVE-2024-3856) - High [538]
Description: A
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
ubuntu: CVE-2024-3856 was patched at 2024-04-24
298.
Denial of Service - Apache HTTP Server (CVE-2013-2765) - High [536]
Description: The ModSecurity module before 2.7.4 for the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] ModSecurity Remote Null Pointer Dereference Vulnerability, [packetstorm] ModSecurity Remote Null Pointer Dereference, [seebug] ModSecurity 空指针间接引用远程拒绝服务漏洞(CVE-2013-2765)) | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-2765 was patched at 2024-05-15
299.
Denial of Service - Linux Kernel (CVE-2014-0102) - High [536]
Description: The keyring_detect_cycle_iterator function in security/keys/keyring.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Linux Kernel 'keyring_detect_cycle_iterator()'函数本地拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.5 | 10 | CVSS Base Score is 5.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-0102 was patched at 2024-05-15
300.
Denial of Service - Linux Kernel (CVE-2019-20794) - High [536]
Description: {'vulners_cve_data_all': 'An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user can create their own PID namespace, and mount a FUSE filesystem. Upon interaction with this FUSE filesystem, if the userspace component is terminated via a kill of the PID namespace's pid 1, it will result in a hung task, and resources being permanently locked up until system reboot. This can result in resource exhaustion.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-20794 was patched at 2024-05-15
301.
Information Disclosure - Linux Kernel (CVE-2014-0131) - High [536]
Description: Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Linux Kernel vhost-net分段内存泄露漏洞, [seebug] Linux kernel skb_segment函数释放后使用漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.3 | 10 | CVSS Base Score is 2.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-0131 was patched at 2024-05-15
302.
Memory Corruption - Linux Kernel (CVE-2019-19378) - High [536]
Description: In the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-19378 was patched at 2024-05-15
303.
Path Traversal - Apache HTTP Server (CVE-2007-1860) - High [536]
Description: mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] SA-20070314-0.txt, [seebug] Mac OS X 2007-007更新修复多个安全漏洞) | |
| 0.7 | 15 | Path Traversal | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-1860 was patched at 2024-05-15
304.
Denial of Service - Unknown Product (CVE-2020-36067) - High [535]
Description: {'vulners_cve_data_all': 'GJSON <=v1.6.5 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a crafted GET call.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-36067 was patched at 2024-05-15
305.
Cross Site Scripting - MediaWiki (CVE-2012-4378) - High [533]
Description: Multiple cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MediaWiki 1.x userlang参数跨站脚本漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-4378 was patched at 2024-05-15
306.
Cross Site Scripting - MediaWiki (CVE-2020-35474) - High [533]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-35474 was patched at 2024-05-15
307.
Denial of Service - Binutils (CVE-2020-16591) - High [532]
Description: A
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-16591 was patched at 2024-05-15
308.
Denial of Service - Binutils (CVE-2020-16593) - High [532]
Description: A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-16593 was patched at 2024-05-15
309.
Denial of Service - Binutils (CVE-2020-16599) - High [532]
Description: A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-16599 was patched at 2024-05-15
310.
Denial of Service - GNOME desktop (CVE-2017-14108) - High [532]
Description: libgedit.a in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] libgedit.a 3.22.1 Denial Of Service Vulnerability, [packetstorm] libgedit.a 3.22.1 Denial Of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-14108 was patched at 2024-05-15
311.
Memory Corruption - Chromium (CVE-2021-30623) - High [532]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Out-of-bounds Write in Google Chrome) | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30623 was patched at 2024-05-15
312.
Memory Corruption - Google Chrome (CVE-2021-30521) - High [532]
Description: Heap
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30521 was patched at 2024-05-15
313.
Memory Corruption - Google Chrome (CVE-2021-30522) - High [532]
Description: Use after free in WebAudio in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30522 was patched at 2024-05-15
314.
Memory Corruption - Google Chrome (CVE-2021-30523) - High [532]
Description: Use after free in WebRTC in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30523 was patched at 2024-05-15
315.
Memory Corruption - Google Chrome (CVE-2021-30524) - High [532]
Description: Use after free in TabStrip in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30524 was patched at 2024-05-15
316.
Memory Corruption - Google Chrome (CVE-2021-30525) - High [532]
Description: Use after free in TabGroups in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30525 was patched at 2024-05-15
317.
Memory Corruption - Google Chrome (CVE-2021-30527) - High [532]
Description: Use after free in WebUI in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30527 was patched at 2024-05-15
318.
Memory Corruption - Google Chrome (CVE-2021-30528) - High [532]
Description: Use after free in WebAuthentication in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30528 was patched at 2024-05-15
319.
Memory Corruption - Google Chrome (CVE-2021-30529) - High [532]
Description: Use after free in Bookmarks in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30529 was patched at 2024-05-15
320.
Memory Corruption - Google Chrome (CVE-2021-30530) - High [532]
Description: Out of bounds memory access in WebAudio in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30530 was patched at 2024-05-15
321.
Memory Corruption - Google Chrome (CVE-2021-30544) - High [532]
Description: Use after free in BFCache in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30544 was patched at 2024-05-15
322.
Memory Corruption - Google Chrome (CVE-2021-30545) - High [532]
Description: Use after free in Extensions in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30545 was patched at 2024-05-15
323.
Memory Corruption - Google Chrome (CVE-2021-30546) - High [532]
Description: Use after free in Autofill in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30546 was patched at 2024-05-15
324.
Memory Corruption - Google Chrome (CVE-2021-30548) - High [532]
Description: Use after free in Loader in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30548 was patched at 2024-05-15
325.
Memory Corruption - Google Chrome (CVE-2021-30550) - High [532]
Description: Use after free in Accessibility in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30550 was patched at 2024-05-15
326.
Memory Corruption - Google Chrome (CVE-2021-30552) - High [532]
Description: Use after free in Extensions in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30552 was patched at 2024-05-15
327.
Memory Corruption - Google Chrome (CVE-2021-30553) - High [532]
Description: Use after free in Network service in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30553 was patched at 2024-05-15
328.
Memory Corruption - Google Chrome (CVE-2021-30561) - High [532]
Description: Type Confusion in V8 in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Chrome JS WasmJs::InstallConditionalFeatures Object Corruption) | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30561 was patched at 2024-05-15
329.
Memory Corruption - Google Chrome (CVE-2021-30573) - High [532]
Description: Use after free in GPU in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Use After Free in Google Chrome, [githubexploit] Exploit for Use After Free in Google Chrome, [githubexploit] Exploit for Use After Free in Google Chrome) | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30573 was patched at 2024-05-15
330.
Memory Corruption - Google Chrome (CVE-2021-30602) - High [532]
Description: Use after free in WebRTC in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30602 was patched at 2024-05-15
331.
Memory Corruption - Safari (CVE-2018-4382) - High [532]
Description: Multiple
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] WebKit JSC JIT - ByteCodeParser::handleIntrinsicCall Type Confusion Exploit, [packetstorm] WebKit JIT ByteCodeParser::handleIntrinsicCall Type Confusion) | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-4382 was patched at 2024-05-15
332.
Memory Corruption - Safari (CVE-2018-4416) - High [532]
Description: Multiple
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] WebKit JSC JIT - JSPropertyNameEnumerator Type Confusion Exploit, [packetstorm] WebKit JSC JIT JSPropertyNameEnumerator Type Confusion) | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-4416 was patched at 2024-05-15
333.
Memory Corruption - Safari (CVE-2018-4438) - High [532]
Description: A logic issue existed resulting in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] WebKit JIT Proxy Object Issue, [zdt] WebKit JIT - Int32/Double Arrays can have Proxy Objects in the Prototype Chains Exploit) | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-4438 was patched at 2024-05-15
334.
Memory Corruption - Safari (CVE-2018-4441) - High [532]
Description: A
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] WebKit JSC JSArray::shiftCountWithArrayStorage Out-Of-Band Read / Write, [zdt] WebKit JSC JSArray::shiftCountWithArrayStorage Out-Of-Band Read / Write Exploit, [zdt] SonyPlaystation 4 (PS4) < 6.20 - WebKit Code Execution Exploit, [exploitpack] Sony Playstation 4 (PS4) 6.20 - WebKit Code Execution (PoC), [exploitdb] Sony Playstation 4 (PS4) < 6.20 - WebKit Code Execution (PoC)) | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-4441 was patched at 2024-05-15
335.
Memory Corruption - Safari (CVE-2018-4442) - High [532]
Description: A
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] WebKit JSC JIT - GetIndexedPropertyStorage Use-After-Free Exploit, [packetstorm] WebKit JSC JIT Use-After-Free) | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-4442 was patched at 2024-05-15
336.
Memory Corruption - Safari (CVE-2018-4443) - High [532]
Description: A
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] WebKit JSC AbstractValue::set Use-After-Free Exploit, [packetstorm] WebKit JSC AbstractValue::set Use-After-Free) | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-4443 was patched at 2024-05-15
337.
Path Traversal - PHP (CVE-2011-2508) - High [532]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin 3.x 多个安全漏洞, [seebug] phpMyAdmin 3.x Multiple Remote Code Executions, [packetstorm] phpMyAdmin 3.x Remote Code Execution) | |
| 0.7 | 15 | Path Traversal | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-2508 was patched at 2024-05-15
338.
Arbitrary File Reading - PHP (CVE-2003-0536) - High [531]
Description: Directory traversal vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Hardened-PHP Project Security Advisory 2005-21.81) | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 3.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0536 was patched at 2024-05-15
339.
Information Disclosure - OpenSSL (CVE-2016-0701) - High [531]
Description: {'vulners_cve_data_all': 'The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for remote attackers to discover a private DH exponent by making multiple handshakes with a peer that chose an inappropriate number, as demonstrated by a number in an X9.42 file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Orion Elite Hidden IP Browser Pro 7.9 OpenSSL / Tor / Man-In-The-Middle) | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-0701 was patched at 2024-05-15
340.
Information Disclosure - PHP (CVE-2012-1902) - High [531]
Description: show_config_errors.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin 3.x 'show_config_errors.php'完整路径信息泄露漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1902 was patched at 2024-05-15
341.
Cross Site Scripting - Apache HTTP Server (CVE-2009-0796) - High [530]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apache mod_perl 'Apache::Status'和'Apache2::Status'跨站脚本漏洞, [packetstorm] Mod-Perl Perl-Status Cross Site Scripting) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.3 | 10 | CVSS Base Score is 2.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0796 was patched at 2024-05-15
342.
Information Disclosure - nginx (CVE-2013-0337) - High [529]
Description: The default configuration of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Nginx 'access.log'不安全文件权限漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-0337 was patched at 2024-05-15
343.
Denial of Service - BIND (CVE-2011-0414) - High [527]
Description: ISC
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Bind 9 竞争条件远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-0414 was patched at 2024-05-15
344.
Elevation of Privilege - Git (CVE-2022-38065) - High [527]
Description: A
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.4 | 14 | Git | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-38065 was patched at 2024-05-15
345.
Cross Site Scripting - APT (CVE-2007-4542) - High [526]
Description: Multiple cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MapServer远程栈溢出及跨站脚本漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-4542 was patched at 2024-05-15
346.
Cross Site Scripting - APT (CVE-2014-2538) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Ruby rack-ssl Gem错误页面跨站脚本漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-2538 was patched at 2024-05-15
347.
Cross Site Scripting - PHP (CVE-2006-0806) - High [526]
Description: Multiple cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] ADOdb 4.71 - Cross Site Scripting, [exploitdb] ADOdb < 4.71 - Cross Site Scripting) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-0806 was patched at 2024-05-15
348.
Cross Site Scripting - PHP (CVE-2008-1502) - High [526]
Description: The _bad_protocol_once function in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([dsquare] Moodle <= 1.8.4 RCE, [d2] DSquare Exploit Pack: D2SEC_MOODLE_REXEC) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1502 was patched at 2024-05-15
349.
Cross Site Scripting - PHP (CVE-2009-2284) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin SQL书签HTML注入漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2284 was patched at 2024-05-15
350.
Cross Site Scripting - PHP (CVE-2009-3696) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin SQL注入和跨站脚本漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3696 was patched at 2024-05-15
351.
Cross Site Scripting - PHP (CVE-2010-3263) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin 3.x setup脚本远程跨站脚本漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-3263 was patched at 2024-05-15
352.
Cross Site Scripting - PHP (CVE-2010-4329) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin数据库搜索跨站脚本执行漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-4329 was patched at 2024-05-15
353.
Cross Site Scripting - PHP (CVE-2011-3181) - High [526]
Description: Multiple cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin跟踪功能多个跨站脚本漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-3181 was patched at 2024-05-15
354.
Cross Site Scripting - PHP (CVE-2011-4064) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin Setup接口跨站脚本漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4064 was patched at 2024-05-15
355.
Cross Site Scripting - PHP (CVE-2011-4634) - High [526]
Description: Multiple cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin 3.4.8之前版本多个跨站脚本执行漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4634 was patched at 2024-05-15
356.
Cross Site Scripting - PHP (CVE-2011-4780) - High [526]
Description: Multiple cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin 3.4.9之前版本多个跨站脚本执行漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4780 was patched at 2024-05-15
357.
Cross Site Scripting - PHP (CVE-2011-4782) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin '$host'变量HTML注入漏洞, [packetstorm] phpMyAdmin 3.4.8 Cross Site Scripting) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4782 was patched at 2024-05-15
358.
Cross Site Scripting - PHP (CVE-2012-0782) - High [526]
Description: Multiple cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] wordpress <= 3.3.1 - Multiple Vulnerabilities, [seebug] WordPress 3.3.1 Code Execution / Cross Site Scripting, [packetstorm] WordPress 3.3.1 Code Execution / Cross Site Scripting, [exploitpack] WordPress 3.3.1 - Multiple Vulnerabilities, [exploitdb] WordPress Core 3.3.1 - Multiple Vulnerabilities) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-0782 was patched at 2024-05-15
359.
Cross Site Scripting - PHP (CVE-2012-1190) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin 3.x 数据库名称跨站脚本执行漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1190 was patched at 2024-05-15
360.
Cross Site Scripting - PHP (CVE-2014-2570) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] php-font-lib 'name'参数跨站脚本漏洞, [packetstorm] php-font-lib 0.3 Cross Site Scripting) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-2570 was patched at 2024-05-15
361.
Cross Site Scripting - PHP (CVE-2014-6070) - High [526]
Description: Multiple cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Syslog LogAnalyzer 3.6.5 - Persistent Cross-Site Scripting (Python), [packetstorm] LogAnalyzer 3.6.5 Cross Site Scripting, [zdt] LogAnalyzer 3.6.5 Cross Site Scripting Vulnerability, [exploitdb] Syslog LogAnalyzer 3.6.5 - Persistent Cross-Site Scripting ) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-6070 was patched at 2024-05-15
362.
Cross Site Scripting - PHP (CVE-2015-6584) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] DataTables 1.10.8 Cross Site Scripting) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-6584 was patched at 2024-05-15
363.
Cross Site Scripting - Safari (CVE-2009-1684) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1684 was patched at 2024-05-15
364.
Cross Site Scripting - Safari (CVE-2009-1685) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1685 was patched at 2024-05-15
365.
Cross Site Scripting - Safari (CVE-2009-1688) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1688 was patched at 2024-05-15
366.
Cross Site Scripting - Safari (CVE-2009-1689) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1689 was patched at 2024-05-15
367.
Cross Site Scripting - Safari (CVE-2009-1691) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1691 was patched at 2024-05-15
368.
Cross Site Scripting - Safari (CVE-2009-1695) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1695 was patched at 2024-05-15
369.
Cross Site Scripting - Safari (CVE-2009-1697) - High [526]
Description: CRLF injection vulnerability in WebKit in Apple
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1697 was patched at 2024-05-15
370.
Cross Site Scripting - Safari (CVE-2009-1702) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1702 was patched at 2024-05-15
371.
Cross Site Scripting - Safari (CVE-2009-1714) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1714 was patched at 2024-05-15
372.
Cross Site Scripting - Safari (CVE-2009-1715) - High [526]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1715 was patched at 2024-05-15
373.
Cross Site Scripting - Webkit (CVE-2014-8600) - High [526]
Description: Multiple cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] IO Slaves KDE Insufficient Input Validation) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | WebKit is a browser engine developed by Apple and primarily used in its Safari web browser, as well as all web browsers on iOS and iPadOS | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-8600 was patched at 2024-05-15
374.
Command Injection - Git (CVE-2021-43809) - High [525]
Description: `Bundler` is a package for managing application dependencies in Ruby. In `bundler` versions before 2.2.33, when working with untrusted and apparently harmless `Gemfile`'s, it is not expected that they lead to execution of external code, unless that's explicit in the ruby code inside the `Gemfile` itself. However, if the `Gemfile` includes `gem` entries that use the `
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | Command Injection | |
| 0.4 | 14 | Git | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-43809 was patched at 2024-05-15
375.
Denial of Service - Linux Kernel (CVE-2013-5634) - High [525]
Description: arch/arm/kvm/arm.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Linux Kernel空指针引用本地拒绝服务漏洞(CVE-2013-5634)) | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-5634 was patched at 2024-05-15
376.
Security Feature Bypass - Git (CVE-2021-29499) - High [525]
Description: {'vulners_cve_data_all': 'SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable UUID identifiers due to insecure randomness in the version of the `github.com/satori/go.uuid` module used as a dependency. A patch is available in version >= v1.2.3 of the module. Users are encouraged to upgrade. As a workaround, users passing CreateInfo struct should ensure the `ID` field is generated using a version of `github.com/satori/go.uuid` that is not vulnerable to this issue.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.4 | 14 | Git | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-29499 was patched at 2024-05-15
377.
Information Disclosure - Linux Kernel (CVE-2014-1444) - High [524]
Description: The fst_get_iface function in drivers/net/wan/farsync.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Linux Kernel 'farsync.c'本地信息泄露漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.2 | 10 | CVSS Base Score is 1.7. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-1444 was patched at 2024-05-15
378.
Information Disclosure - Linux Kernel (CVE-2014-1445) - High [524]
Description: The wanxl_ioctl function in drivers/net/wan/wanxl.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Linux Kernel 'wanxl.c'本地信息泄露漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.2 | 10 | CVSS Base Score is 2.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-1445 was patched at 2024-05-15
379.
Information Disclosure - Linux Kernel (CVE-2014-1446) - High [524]
Description: The yam_ioctl function in drivers/net/hamradio/yam.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Linux Kernel 'hamradio/yam.c'本地信息泄露漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.2 | 10 | CVSS Base Score is 1.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-1446 was patched at 2024-05-15
380.
Denial of Service - Unknown Product (CVE-2022-34503) - High [523]
Description: {'vulners_cve_data_all': 'QPDF v8.4.2 was discovered to contain a heap buffer overflow via the function QPDF::processXRefStream. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-34503 was patched at 2024-05-15
381.
Unknown Vulnerability Type - Unknown Product (CVE-2004-2687) - High [523]
Description: {'vulners_cve_data_all': 'distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization checks.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object) website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitdb] DistCC Daemon Command Execution, [packetstorm] DistCC Daemon Command Execution) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-2687 was patched at 2024-05-15
382.
Denial of Service - ImageMagick (CVE-2012-1610) - High [522]
Description: Integer overflow in the GetEXIFProperty function in magick/property.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ImageMagick 拒绝服务漏洞(CVE-2012-0259)) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1610 was patched at 2024-05-15
383.
Denial of Service - Perl (CVE-2013-7488) - High [522]
Description: {'vulners_cve_data_all': 'perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2013-7488 was patched at 2024-05-22
debian: CVE-2013-7488 was patched at 2024-05-15
oraclelinux: CVE-2013-7488 was patched at 2024-05-23
redhat: CVE-2013-7488 was patched at 2024-05-22
384.
Denial of Service - Wireshark (CVE-2009-3241) - High [522]
Description: Unspecified vulnerability in the OpcUa (OPC UA) dissector in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Wireshark: Multiple vulnerabilities) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3241 was patched at 2024-05-15
385.
Information Disclosure - Perl (CVE-2013-2256) - High [522]
Description: OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenStack Nova安全绕过漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-2256 was patched at 2024-05-15
386.
Path Traversal - Python (CVE-2024-23334) - High [522]
Description: aiohttp is an asynchronous HTTP client/server framework for asyncio and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Path Traversal | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-23334 was patched at 2024-05-15
redos: CVE-2024-23334 was patched at 2024-04-23
387.
Security Feature Bypass - Perl (CVE-2011-4613) - High [522]
Description: The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Xorg 1.4 to 1.11.2 File Permission Change PoC, [exploitpack] X.Org xorg 1.4 1.11.2 - File Permission Change, [exploitdb] X.Org xorg 1.4 < 1.11.2 - File Permission Change) | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4613 was patched at 2024-05-15
388.
Authentication Bypass - Cacti (CVE-2022-48538) - High [520]
Description: In Cacti 1.2.19, there is an
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-48538 was patched at 2024-05-15
389.
Denial of Service - GNU C Library (CVE-2009-4880) - High [520]
Description: Multiple integer overflows in the strfmon implementation in the GNU C Library (aka
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] 多个BSD平台'strfmon()'函数整数溢出漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4880 was patched at 2024-05-15
390.
Denial of Service - GNU C Library (CVE-2009-4881) - High [520]
Description: Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] 多个BSD平台'strfmon()'函数整数溢出漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4881 was patched at 2024-05-15
391.
Denial of Service - GNU C Library (CVE-2010-4051) - High [520]
Description: The regcomp implementation in the GNU C Library (aka
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-4051 was patched at 2024-05-15
392.
Denial of Service - GNU C Library (CVE-2010-4052) - High [520]
Description: Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka
debian: CVE-2010-4052 was patched at 2024-05-15
393.
Denial of Service - Google Chrome (CVE-2011-3893) - High [520]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Google Chrome 15.x MKV和Vorbis媒体处理漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-3893 was patched at 2024-05-15
394.
Denial of Service - Node.js (CVE-2021-32640) - High [520]
Description: {'vulners_cve_data_all': 'ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server. The vulnerability has been fixed in ws@7.4.6 (https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff). In vulnerable versions of ws, the issue can be mitigated by reducing the maximum allowed length of the request headers using the [`--max-http-header-size=size`](https://nodejs.org/api/cli.html#cli_max_http_header_size_size) and/or the [`maxHeaderSize`](https://nodejs.org/api/http.html#http_http_createserver_options_requestlistener) options.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32640 was patched at 2024-05-15
395.
Denial of Service - OpenSSL (CVE-2002-0659) - High [520]
Description: The ASN1 library in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] opensslrv.txt) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-0659 was patched at 2024-05-15
396.
Denial of Service - OpenSSL (CVE-2010-0740) - High [520]
Description: The ssl3_get_record function in ssl/s3_pkt.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenSSL - Remote DoS, [seebug] OpenSSL TLS连接记录处理拒绝服务漏洞, [exploitpack] OpenSSL - Remote Denial of Service, [exploitdb] OpenSSL - Remote Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-0740 was patched at 2024-05-15
397.
Denial of Service - PHP (CVE-2012-0937) - High [520]
Description: wp-admin/setup-config.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] WordPress 3.3.1 - Multiple Vulnerabilities, [seebug] wordpress <= 3.3.1 - Multiple Vulnerabilities, [seebug] WordPress 3.3.1 Code Execution / Cross Site Scripting, [packetstorm] WordPress 3.3.1 Code Execution / Cross Site Scripting, [exploitdb] WordPress Core 3.3.1 - Multiple Vulnerabilities) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-0937 was patched at 2024-05-15
398.
Denial of Service - Samba (CVE-2006-3403) - High [520]
Description: The smdb daemon (smbd/service.c) in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2006-007存在多个安全漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3403 was patched at 2024-05-15
399.
Incorrect Calculation - GNOME desktop (CVE-2020-35457) - High [520]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-35457 was patched at 2024-05-15
400.
Memory Corruption - Binutils (CVE-2021-20294) - High [520]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-20294 was patched at 2024-05-15
401.
Memory Corruption - Google Chrome (CVE-2021-30536) - High [520]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30536 was patched at 2024-05-15
402.
Memory Corruption - Google Chrome (CVE-2021-30593) - High [520]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30593 was patched at 2024-05-15
403.
Arbitrary File Writing - Perl (CVE-2012-2451) - High [519]
Description: The Config::IniFiles module before 2.71 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Perl Config::IniFiles Module不安全临时文件创建漏洞) | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.4 | 10 | CVSS Base Score is 3.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-2451 was patched at 2024-05-15
404.
Remote Code Execution - GPAC (CVE-2021-32137) - High [519]
Description: Heap buffer overflow in the URL_GetProtocolType function in MP4Box in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32137 was patched at 2024-05-15
405.
Code Injection - Cacti (CVE-2024-31458) - High [518]
Description: {'vulners_cve_data_all': 'Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not thoroughly checked and is used to concatenate the SQL statement in `draw_nontemplated_fields_graph_item()` function from `lib/html_form_templates.php` , finally resulting in SQL injection. Version 1.2.27 contains a patch for the issue.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | Code Injection | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-31458 was patched at 2024-05-15
406.
Information Disclosure - HID (CVE-2021-32747) - High [517]
Description: {'vulners_cve_data_all': 'Icinga Web 2 is an open source monitoring web interface, framework, and command-line interface. A vulnerability in which custom variables are exposed to unauthorized users exists between versions 2.0.0 and 2.8.2. Custom variables are user-defined keys and values on configuration objects in Icinga 2. These are commonly used to reference secrets in other configurations such as check commands to be able to authenticate with a service being checked. Icinga Web 2 displays these custom variables to logged in users with access to said hosts or services. In order to protect the secrets from being visible to anyone, it's possible to setup protection rules and blacklists in a user's role. Protection rules result in `***` being shown instead of the original value, the key will remain. Backlists will hide a custom variable entirely from the user. Besides using the UI, custom variables can also be accessed differently by using an undocumented URL parameter. By adding a parameter to the affected routes, Icinga Web 2 will show these columns additionally in the respective list. This parameter is also respected when exporting to JSON or CSV. Protection rules and blacklists however have no effect in this case. Custom variables are shown as-is in the result. The issue has been fixed in the 2.9.0, 2.8.3, and 2.7.5 releases. As a workaround, one may set up a restriction to hide hosts and services with the custom variable in question.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | HID | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32747 was patched at 2024-05-15
407.
Security Feature Bypass - Docker (CVE-2021-41091) - High [517]
Description: {'vulners_cve_data_all': 'Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirectories with insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bits (such as `setuid`), unprivileged Linux users could discover and execute those programs. When the UID of an unprivileged Linux user on the host collided with the file owner or group inside a container, the unprivileged Linux user on the host could discover, read, and modify those files. This bug has been fixed in Moby (Docker Engine) 20.10.9. Users should update to this version as soon as possible. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade limit access to the host to trusted users. Limit access to host volumes to trusted containers.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Improper Preservation of Permissions in Mobyproject Moby, [githubexploit] Exploit for Improper Preservation of Permissions in Mobyproject Moby) | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Docker | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-41091 was patched at 2024-05-15
408.
Cross Site Scripting - Internet Explorer (CVE-2022-25869) - High [516]
Description: All versions of package angular are vulnerable to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Internet Explorer is a discontinued series of graphical web browsers developed by Microsoft | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-25869 was patched at 2024-05-15
409.
Cross Site Scripting - Perl (CVE-2020-10688) - High [516]
Description: A cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-10688 was patched at 2024-05-15
410.
Denial of Service - FFmpeg (CVE-2009-4632) - High [515]
Description: oggparsevorbis.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg多个媒体文件解析拒绝服务和代码执行漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4632 was patched at 2024-05-15
411.
Denial of Service - iOS (CVE-2018-13441) - High [515]
Description: qh_help in Nag
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Nagios Core 4.4.1 - Denial of Service Vulnerability, [packetstorm] Nagios Core 4.4.1 Local Denial Of Service, [exploitpack] Nagios Core 4.4.1 - Denial of Service, [exploitdb] Nagios Core 4.4.1 - Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-13441 was patched at 2024-05-15
412.
Denial of Service - iOS (CVE-2018-13457) - High [515]
Description: qh_echo in Nag
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Nagios Core 4.4.1 - Denial of Service Vulnerability, [packetstorm] Nagios Core 4.4.1 Local Denial Of Service, [exploitpack] Nagios Core 4.4.1 - Denial of Service, [exploitdb] Nagios Core 4.4.1 - Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-13457 was patched at 2024-05-15
413.
Denial of Service - iOS (CVE-2018-13458) - High [515]
Description: qh_core in Nag
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Nagios Core 4.4.1 - Denial of Service Vulnerability, [packetstorm] Nagios Core 4.4.1 Local Denial Of Service, [exploitpack] Nagios Core 4.4.1 - Denial of Service, [exploitdb] Nagios Core 4.4.1 - Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-13458 was patched at 2024-05-15
414.
Denial of Service - vim (CVE-2021-3236) - High [515]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | Vim is a free and open-source, screen-based text editor program | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-3236 was patched at 2024-05-15
415.
Cross Site Scripting - Mozilla Firefox (CVE-2012-4600) - High [514]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] OTRS Open Technology Real Services 3.1.8 / 3.1.9 XSS) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.3 | 10 | CVSS Base Score is 2.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-4600 was patched at 2024-05-15
416.
Cross Site Scripting - PHP (CVE-2007-5977) - High [514]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin DB_Create.PHP多个输入验证漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.3 | 10 | CVSS Base Score is 3.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-5977 was patched at 2024-05-15
417.
Cross Site Scripting - PHP (CVE-2007-6100) - High [514]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin登录页面跨站脚本漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.3 | 10 | CVSS Base Score is 2.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-6100 was patched at 2024-05-15
418.
Cross Site Scripting - PHP (CVE-2008-2960) - High [514]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin远程跨站脚本漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.3 | 10 | CVSS Base Score is 2.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-2960 was patched at 2024-05-15
419.
Cross Site Scripting - PHP (CVE-2008-3457) - High [514]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin setup.php文件跨站脚本执行漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.3 | 10 | CVSS Base Score is 2.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3457 was patched at 2024-05-15
420.
Cross Site Scripting - PHP (CVE-2008-4775) - High [514]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin DB_Create.PHP多个输入验证漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.3 | 10 | CVSS Base Score is 2.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-4775 was patched at 2024-05-15
421.
Cross Site Scripting - PHP (CVE-2012-4345) - High [514]
Description: Multiple cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin 3.4.x 多个HTML注入漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.3 | 10 | CVSS Base Score is 3.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-4345 was patched at 2024-05-15
422.
Cross Site Scripting - PHP (CVE-2012-4579) - High [514]
Description: Multiple cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin 3.4.x 多个HTML注入漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.3 | 10 | CVSS Base Score is 3.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-4579 was patched at 2024-05-15
423.
Memory Corruption - Linux Kernel (CVE-2019-19815) - High [513]
Description: {'vulners_cve_data_all': 'In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a NULL pointer dereference in f2fs_recover_fsync_data in fs/f2fs/recovery.c. This is related to F2FS_P_SB in fs/f2fs/f2fs.h.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-19815 was patched at 2024-05-15
424.
Memory Corruption - Linux Kernel (CVE-2019-19927) - High [513]
Description: In the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-19927 was patched at 2024-05-15
425.
Memory Corruption - Linux Kernel (CVE-2020-27194) - High [513]
Description: {'vulners_cve_data_all': 'An issue was discovered in the Linux kernel before 5.8.15. scalar32_min_max_or in kernel/bpf/verifier.c mishandles bounds tracking during use of 64-bit values, aka CID-5b9fbeb75b6a.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Incorrect Conversion between Numeric Types in Linux Linux Kernel, [githubexploit] Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Linux Linux Kernel) | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-27194 was patched at 2024-05-15
426.
Memory Corruption - Linux Kernel (CVE-2022-3113) - High [513]
Description: {'vulners_cve_data_all': 'An issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_init in drivers/media/platform/mtk-vcodec/mtk_vcodec_fw_vpu.c lacks check of the return value of devm_kzalloc() and will cause the null pointer dereference.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([metasploit] Roxy-WI Prior to 6.1.1.0 Unauthenticated Command Injection RCE, [packetstorm] Roxy-WI Remote Command Execution, [zdt] Roxy-WI Remote Command Execution Exploit) | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-3113 was patched at 2024-05-15
427.
Memory Corruption - Linux Kernel (CVE-2023-31081) - High [513]
Description: {'vulners_cve_data_all': 'An issue was discovered in drivers/media/test-drivers/vidtv/vidtv_bridge.c in the Linux kernel 6.2. There is a NULL pointer dereference in vidtv_mux_stop_thread. In vidtv_stop_streaming, after dvb->mux=NULL occurs, it executes vidtv_mux_stop_thread(dvb->mux).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-31081 was patched at 2024-05-15
428.
Memory Corruption - Linux Kernel (CVE-2023-31082) - High [513]
Description: {'vulners_cve_data_all': 'An issue was discovered in drivers/tty/n_gsm.c in the Linux kernel 6.2. There is a sleeping function called from an invalid context in gsmld_write, which will block the kernel. Note: This has been disputed by 3rd parties as not a valid vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-31082 was patched at 2024-05-15
429.
Memory Corruption - Linux Kernel (CVE-2023-37454) - High [513]
Description: An issue was discovered in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-37454 was patched at 2024-05-15
430.
Information Disclosure - Git (CVE-2022-24975) - High [512]
Description: {'vulners_cve_data_all': 'The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0.4 | 14 | Git | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-24975 was patched at 2024-05-15
431.
Arbitrary File Reading - Exim (CVE-2009-2944) - High [510]
Description: Incomplete blacklist vulnerability in the t
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ikiwiki teximg插件不安全TeX命令信息泄露漏洞) | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.6 | 14 | Exim is a mail transfer agent (MTA) used on Unix-like operating systems | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2944 was patched at 2024-05-15
432.
Denial of Service - Perl (CVE-2009-1391) - High [510]
Description: Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] 'Compress::Raw::Zlib' Perl模块远程代码执行漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1391 was patched at 2024-05-15
433.
Denial of Service - Perl (CVE-2014-2241) - High [510]
Description: The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FreeType 'src/cff/cf2ft.c'远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-2241 was patched at 2024-05-15
434.
Denial of Service - Perl (CVE-2017-11552) - High [510]
Description: mpg321.c in mpg321 0.3.2-1 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] libmad 0.15.1b - mp3 Memory Corruption Exploit, [exploitpack] libmad 0.15.1b - mp3 Memory Corruption, [exploitdb] libmad 0.15.1b - 'mp3' Memory Corruption) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-11552 was patched at 2024-05-15
435.
Denial of Service - Python (CVE-2010-1666) - High [510]
Description: Buffer overflow in Dan Pascu
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Python-cjson Unicode字符编码缓冲区溢出漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-1666 was patched at 2024-05-15
436.
Denial of Service - Python (CVE-2023-36807) - High [510]
Description: {'vulners_cve_data_all': 'pypdf is a pure-python PDF library capable of splitting, merging, cropping, and transforming the pages of PDF files. In version 2.10.5 an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This infinite loop blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage. That is, for example, the case if the user extracted metadata from such a malformed PDF. Versions prior to 2.10.5 throw an error, but do not hang forever. This issue was fixed with https://github.com/py-pdf/pypdf/pull/1331 which has been included in release 2.10.6. Users are advised to upgrade. Users unable to upgrade should modify `PyPDF2/generic/_data_structures.py::read_object` to an an error throwing case. See GHSA-hm9v-vj3r-r55m for details. ', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-36807 was patched at 2024-05-15
437.
Denial of Service - Python (CVE-2024-28102) - High [510]
Description: JWCrypto implements JWK, JWS, and JWE specifications using
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2024-28102 was patched at 2024-04-30
debian: CVE-2024-28102 was patched at 2024-05-15
oraclelinux: CVE-2024-28102 was patched at 2024-05-07, 2024-05-29
redhat: CVE-2024-28102 was patched at 2024-04-30, 2024-05-22
438.
Incorrect Calculation - FreeRDP (CVE-2024-22211) - High [510]
Description: FreeRDP is a set of free and open source remote desktop protocol library and clients. In affected versions an
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-22211 was patched at 2024-05-15
ubuntu: CVE-2024-22211 was patched at 2024-04-24
439.
Information Disclosure - Perl (CVE-2017-5487) - High [510]
Description: wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Wordpress 4.7.1 - Username Enumeration Exploit, [wpexploit] WordPress 4.7 - User Information Disclosure via REST API, [packetstorm] WordPress Username Enumeration, [seebug] Wordpress < 4.7.1 - Username Enumeration (CVE-2017-5487)) | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-5487 was patched at 2024-05-15
440.
Security Feature Bypass - Perl (CVE-2007-5965) - High [510]
Description: QSslSocket in Trolltech Qt 4.3.0 through 4.3.2 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Trolltech Qt QSslSocket类证书验证绕过安全限制漏洞) | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-5965 was patched at 2024-05-15
441.
Cross Site Scripting - MediaWiki (CVE-2014-2242) - High [509]
Description: includes/upload/UploadBase.php in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MediaWiki 'includes/upload/UploadBase.php'跨站脚本漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-2242 was patched at 2024-05-15
442.
Denial of Service - GNOME desktop (CVE-2012-2738) - High [508]
Description: The VteTerminal in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 0.4 | 10 | CVSS Base Score is 4.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-2738 was patched at 2024-05-15
443.
Denial of Service - GNU C Library (CVE-2010-4756) - High [508]
Description: The glob implementation in the GNU C Library (aka
debian: CVE-2010-4756 was patched at 2024-05-15
444.
Denial of Service - OpenSSL (CVE-2006-4343) - High [508]
Description: The get_server_hello function in the SSLv2 client code in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] openssl-dos.txt, [seebug] OpenSSL < 0.9.7l / 0.9.8d SSLv2 Client Crash Exploit, [seebug] OpenSSL SSLv2 - Null Pointer Dereference Client Denial of Service Vulnerability, [seebug] OpenSSL < 0.9.7l / 0.9.8d - SSLv2 Client Crash Exploit, [seebug] Apple Mac OS X 2006-007存在多个安全漏洞, [exploitpack] OpenSSL 0.9.7l0.9.8d - SSLv2 Client Crash, [exploitpack] OpenSSL SSLv2 - Null Pointer Dereference Client Denial of Service, [exploitdb] OpenSSL < 0.9.7l/0.9.8d - SSLv2 Client Crash, [exploitdb] OpenSSL SSLv2 - Null Pointer Dereference Client Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4343 was patched at 2024-05-15
445.
Denial of Service - OpenSSL (CVE-2008-0891) - High [508]
Description: Double free vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenSSL多个拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-0891 was patched at 2024-05-15
446.
Denial of Service - OpenSSL (CVE-2008-1672) - High [508]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenSSL多个拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1672 was patched at 2024-05-15
447.
Denial of Service - PHP (CVE-2009-3622) - High [508]
Description: Algorithmic complexity vulnerability in wp-trackback.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] WordPress Trackback脚本拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3622 was patched at 2024-05-15
448.
Denial of Service - RPC (CVE-2007-6599) - High [508]
Description: Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenAFS文件服务器远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-6599 was patched at 2024-05-15
449.
Memory Corruption - Google Chrome (CVE-2021-30597) - High [508]
Description: Use after free in Browser UI in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30597 was patched at 2024-05-15
450.
Cross Site Scripting - Git (CVE-2022-39285) - High [507]
Description: ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Zoneminder Log Injection / XSS / Cross Site Request Forgery, [zdt] Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass Exploit, [exploitdb] Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.4 | 14 | Git | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-39285 was patched at 2024-05-15
451.
Denial of Service - Cacti (CVE-2007-3112) - High [505]
Description: graph_image.php in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] New cacti packages fix insufficient input sanitising) | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-3112 was patched at 2024-05-15
452.
Denial of Service - TLS (CVE-2012-1663) - High [505]
Description: Double free vulnerability in libgnu
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] GnuTLS libgnutls Double-free Certificate List Parsing Remote DoS, [exploitpack] GnuTLS libgnutls - Double-Free Certificate List Parsing Remote Denial of Service, [seebug] GnuTLS libgnutls Double-free Certificate List Parsing Remote DoS, [exploitdb] GnuTLS libgnutls - Double-Free Certificate List Parsing Remote Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | TLS | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1663 was patched at 2024-05-15
453.
Memory Corruption - Unknown Product (CVE-2024-29131) - High [505]
Description: {'vulners_cve_data_all': 'Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1.\n\nUsers are recommended to upgrade to version 2.10.1, which fixes the issue.\n\n', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-29131 was patched at 2024-05-15
454.
Cross Site Scripting - Roundcube (CVE-2020-18670) - High [504]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Roundcube is a web-based IMAP email client | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-18670 was patched at 2024-05-15
455.
Cross Site Scripting - Roundcube (CVE-2020-18671) - High [504]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Roundcube is a web-based IMAP email client | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-18671 was patched at 2024-05-15
456.
Denial of Service - Apache Traffic Server (CVE-2012-0256) - High [503]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apache Traffic Server HTTP主机标头处理缓冲区溢出漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | The Apache Traffic Server is a modular, high-performance reverse proxy and forward proxy server, generally comparable to Nginx and Squid | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-0256 was patched at 2024-05-15
457.
Denial of Service - BIND (CVE-2006-4096) - High [503]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2007-005多个安全漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4096 was patched at 2024-05-15
458.
Denial of Service - BIND (CVE-2011-1907) - High [503]
Description: ISC
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ISC BIND 9 RRSIG Query类型远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-1907 was patched at 2024-05-15
459.
Memory Corruption - vim (CVE-2021-3968) - High [503]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | Vim is a free and open-source, screen-based text editor program | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-3968 was patched at 2024-05-15
460.
Memory Corruption - vim (CVE-2021-4136) - High [503]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | Vim is a free and open-source, screen-based text editor program | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-4136 was patched at 2024-05-15
461.
Memory Corruption - vim (CVE-2021-4173) - High [503]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | Vim is a free and open-source, screen-based text editor program | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-4173 was patched at 2024-05-15
debian: CVE-2021-41736 was patched at 2024-05-15
debian: CVE-2021-41737 was patched at 2024-05-15
462.
Information Disclosure - Apache Tomcat (CVE-2008-5519) - High [502]
Description: The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apache Tomcat mod_jk Content-Length头信息泄露漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 0.3 | 10 | CVSS Base Score is 2.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5519 was patched at 2024-05-15
463.
Security Feature Bypass - Git (CVE-2023-42503) - High [501]
Description: {'vulners_cve_data_all': 'Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Commons Compress:\xa0from 1.22 before 1.24.0.\n\nUsers are recommended to upgrade to version 1.24.0, which fixes the issue.\n\nA third party can create a malformed TAR file by manipulating file modification times headers, which when parsed with Apache Commons Compress, will cause a denial of service issue via CPU consumption.\n\nIn version 1.22 of Apache Commons Compress, support was added for file modification times with higher precision (issue # COMPRESS-612 [1]). The format for the PAX extended headers carrying this data consists of two numbers separated by a period [2], indicating seconds and subsecond precision (for example “1647221103.5998539”). The impacted fields are “atime”, “ctime”, “mtime” and “LIBARCHIVE.creationtime”. No input validation is performed prior to the parsing of header values.\n\nParsing of these numbers uses the BigDecimal [3] class from the JDK which has a publicly known algorithmic complexity issue when doing operations on large numbers, causing denial of service (see issue # JDK-6560193 [4]). A third party can manipulate file time headers in a TAR file by placing a number with a very long fraction (300,000 digits) or a number with exponent notation (such as “9e9999999”) within a file modification time header, and the parsing of files with these headers will take hours instead of seconds, leading to a denial of service via exhaustion of CPU resources. This issue is similar to CVE-2012-2098 [5].\n\n[1]: https://issues.apache.org/jira/browse/COMPRESS-612 \n[2]: https://pubs.opengroup.org/onlinepubs/9699919799/utilities/pax.html#tag_20_92_13_05 \n[3]: https://docs.oracle.com/javase/8/docs/api/java/math/BigDecimal.html \n[4]: https://bugs.openjdk.org/browse/JDK-6560193 \n[5]: https://vulners.com/cve/CVE-2012-2098 \n\nOnly applications using CompressorStreamFactory class (with auto-detection of file types), TarArchiveInputStream and TarFile classes to parse TAR files are impacted. Since this code was introduced in v1.22, only that version and later versions are impacted.\n\n', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apache Commons Compress和Apache Ant拒绝服务漏洞) | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.4 | 14 | Git | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-42503 was patched at 2024-05-15
464.
Cross Site Scripting - Cacti (CVE-2022-41444) - High [500]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-41444 was patched at 2024-05-15
465.
Cross Site Scripting - Cacti (CVE-2022-48547) - High [500]
Description: A reflected cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-48547 was patched at 2024-05-15
466.
Cross Site Scripting - Cacti (CVE-2023-39511) - High [500]
Description: Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-39511 was patched at 2024-05-15
467.
Cross Site Scripting - Cacti (CVE-2023-50250) - High [500]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-50250 was patched at 2024-05-15
468.
Denial of Service - Unknown Product (CVE-2017-16137) - High [500]
Description: {'vulners_cve_data_all': 'The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-16137 was patched at 2024-05-15
469.
Remote Code Execution - Unknown Product (CVE-2004-0541) - High [500]
Description: {'vulners_cve_data_all': 'Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Squid NTLM Authenticate Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0541 was patched at 2024-05-15
470.
Remote Code Execution - Unknown Product (CVE-2004-0557) - High [500]
Description: {'vulners_cve_data_all': 'Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] SoX - .wav Local Buffer Overflow, [seebug] SoX - (.wav) Local Buffer Overflow Exploiter, [seebug] SoX Local Buffer Overflow Exploiter (Via Crafted WAV File), [packetstorm] evil_song.py, [exploitdb] SoX - '.wav' Local Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0557 was patched at 2024-05-15
471.
Remote Code Execution - Unknown Product (CVE-2005-1099) - High [500]
Description: {'vulners_cve_data_all': 'Multiple buffer overflows in the HandleChild function in server.c in Greylisting daemon (GLD) 1.3 and 1.4, when GLD is listening on a network interface, allow remote attackers to execute arbitrary code.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] GLD (Greylisting Daemon) Postfix Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-1099 was patched at 2024-05-15
472.
Remote Code Execution - Unknown Product (CVE-2006-5815) - High [500]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrary code, as demonstrated by vd_proftpd.pm, a "ProFTPD remote exploit."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] vd_proftpd.pm.txt, [packetstorm] ProFTPD 1.2 - 1.3.0 sreplace Buffer Overflow (Linux)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-5815 was patched at 2024-05-15
473.
Remote Code Execution - Unknown Product (CVE-2008-1100) - High [500]
Description: {'vulners_cve_data_all': 'Buffer overflow in the cli_scanpe function in libclamav (libclamav/pe.c) for ClamAV 0.92 and 0.92.1 allows remote attackers to execute arbitrary code via a crafted Upack PE file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ClamAV libclamav/pe.c UPACK文件处理堆溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1100 was patched at 2024-05-15
474.
Remote Code Execution - Unknown Product (CVE-2008-1558) - High [500]
Description: {'vulners_cve_data_all': 'Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory and execute arbitrary code via a large streamid SDP parameter. NOTE: this issue has been referred to as an integer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MPlayer sdpplin_parse()函数RTSP整数溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1558 was patched at 2024-05-15
475.
Remote Code Execution - Unknown Product (CVE-2008-2469) - High [500]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in the SPF_dns_resolv_lookup function in Spf_dns_resolv.c in libspf2 before 1.2.8 allows remote attackers to execute arbitrary code via a long DNS TXT record with a modified length field.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] libspf2 DNS TXT记录处理堆溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-2469 was patched at 2024-05-15
476.
Remote Code Execution - Unknown Product (CVE-2008-5030) - High [500]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in the cddb_read_disc_data function in cddb.c in libcdaudio 0.99.12p2 allows remote CDDB servers to execute arbitrary code via long CDDB data.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] libcdaudio cddb.c远程堆溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5030 was patched at 2024-05-15
477.
Remote Code Execution - Unknown Product (CVE-2009-0544) - High [500]
Description: {'vulners_cve_data_all': 'Buffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large ARC2 key length.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] PyCrypto ARC2模块缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0544 was patched at 2024-05-15
478.
Remote Code Execution - Unknown Product (CVE-2009-0839) - High [500]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a long IMAGEPATH or NAME attribute, allows remote attackers to execute arbitrary code via a crafted id parameter in a query action.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MapServer mapserv程序多个远程安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0839 was patched at 2024-05-15
479.
Remote Code Execution - Unknown Product (CVE-2009-1372) - High [500]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ClamAV UPack拒绝服务和cli_url_canon()栈溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1372 was patched at 2024-05-15
480.
Remote Code Execution - Unknown Product (CVE-2009-2281) - High [500]
Description: {'vulners_cve_data_all': 'Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a large HTTP request, related to an integer overflow that triggers a heap-based buffer overflow. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-0840.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MapServer mapserv程序多个远程安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2281 was patched at 2024-05-15
481.
Remote Code Execution - Unknown Product (CVE-2009-2415) - High [500]
Description: {'vulners_cve_data_all': 'Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Memcached多个基于堆的缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2415 was patched at 2024-05-15
482.
Remote Code Execution - Unknown Product (CVE-2009-2694) - High [500]
Description: {'vulners_cve_data_all': 'The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Pidgin MSN 2.5.8 - Remote Code Execution, [seebug] Pidgin MSN <= 2.5.8 - Remote Code Execution Exploit, [seebug] Pidgin Libpurple库msn_slplink_process_msg()函数内存破坏漏洞, [seebug] Pidgin MSN <= 2.5.8 Remote Code Execution Exploit, [seebug] Pidgin多个缓冲区溢出漏洞, [packetstorm] Pidgin MSN 2.5.8 Code Execution, [exploitdb] Pidgin MSN 2.5.8 - Remote Code Execution) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2694 was patched at 2024-05-15
483.
Remote Code Execution - Unknown Product (CVE-2010-4221) - High [500]
Description: {'vulners_cve_data_all': 'Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involving a TELNET IAC escape character to a (1) FTP or (2) FTPS server.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([saint] ProFTPD Telnet IAC buffer overflow, [saint] ProFTPD Telnet IAC buffer overflow, [saint] ProFTPD Telnet IAC buffer overflow, [saint] ProFTPD Telnet IAC buffer overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-4221 was patched at 2024-05-15
484.
Remote Code Execution - Unknown Product (CVE-2011-3012) - High [500]
Description: {'vulners_cve_data_all': 'The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file, a different vulnerability than CVE-2011-2764.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Quake 3 Shell Injection / Code Execution) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-3012 was patched at 2024-05-15
485.
Remote Code Execution - Unknown Product (CVE-2013-0277) - High [500]
Description: {'vulners_cve_data_all': 'ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Ruby on Rails 远程代码执行漏洞(CVE-2013-0277)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-0277 was patched at 2024-05-15
486.
Remote Code Execution - Unknown Product (CVE-2014-0011) - High [500]
Description: {'vulners_cve_data_all': 'Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, when NDEBUG is enabled, allow remote VNC servers to cause a denial of service (vncviewer crash) and possibly execute arbitrary code via vectors related to screen image rendering.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] TigerVNC "ZRLE_DECODE()"缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-0011 was patched at 2024-05-15
487.
Remote Code Execution - Unknown Product (CVE-2014-8322) - High [500]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Aireplay-ng 1.2 beta3 - tcp_test Length Stack Overflow, [seebug] Aireplay-ng 1.2 beta3 - "tcp_test" Length Parameter Stack Overflow, [exploitdb] Aireplay-ng 1.2 beta3 - 'tcp_test' Length Stack Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-8322 was patched at 2024-05-15
488.
Remote Code Execution - Unknown Product (CVE-2015-0855) - High [500]
Description: {'vulners_cve_data_all': 'The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via shell metacharacters in a file path.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-0855 was patched at 2024-05-15
489.
Remote Code Execution - Unknown Product (CVE-2015-8396) - High [500]
Description: {'vulners_cve_data_all': 'Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows attackers to execute arbitrary code via crafted header dimensions in a DICOM image file, which triggers a buffer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Grassroots DICOM (GDCM) 2.6.0 and 2.6.1 - ImageRegionReader::ReadIntoBuffer Buffer Overflow, [zdt] Grassroots DICOM (GDCM) 2.6.0 and 2.6.1 - ImageRegionReader::ReadIntoBuffer Buffer Overflow, [exploitdb] Grassroots DICOM (GDCM) 2.6.0 and 2.6.1 - ImageRegionReader::ReadIntoBuffer Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-8396 was patched at 2024-05-15
490.
Remote Code Execution - Unknown Product (CVE-2016-1000027) - High [500]
Description: {'vulners_cve_data_all': 'Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-1000027 was patched at 2024-05-15
491.
Remote Code Execution - Unknown Product (CVE-2016-2563) - High [500]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cause a denial of service (stack memory corruption) or execute arbitrary code via a crafted SCP-SINK file-size response to an SCP download request.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Putty pscp 0.66 - Stack Buffer Overwrite, [zdt] Putty pscp 0.66 - Stack Buffer Overwrite, [seebug] PuTTY pscp 客户端栈缓冲区覆盖(CVE-2016-2563), [exploitdb] Putty pscp 0.66 - Stack Buffer Overwrite) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-2563 was patched at 2024-05-15
492.
Remote Code Execution - Unknown Product (CVE-2016-6809) - High [500]
Description: {'vulners_cve_data_all': 'Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apache Tika remote code execution vulnerability(CVE-2016-6809), [zdt] Apache Tika 1.13 Code Execution Vulnerability) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-6809 was patched at 2024-05-15
493.
Remote Code Execution - Unknown Product (CVE-2017-2800) - High [500]
Description: {'vulners_cve_data_all': 'A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denial of service and possible remote code execution. In order to trigger this vulnerability, the attacker needs to supply a malicious x509 certificate to either a server or a client application using this library.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] wolfSSL 3.10.2 - x509 Certificate Text Parsing Off-by-One, [seebug] WolfSSL library X509 Certificate Text Parsing Code Execution Vulnerability(CVE-2017-2800), [exploitpack] wolfSSL 3.10.2 - x509 Certificate Text Parsing Off-by-One, [exploitdb] wolfSSL 3.10.2 - x509 Certificate Text Parsing Off-by-One) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2800 was patched at 2024-05-15
494.
Remote Code Execution - Unknown Product (CVE-2017-2891) - High [500]
Description: {'vulners_cve_data_all': 'An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed pointer potentially resulting in remote code execution. An attacker needs to send this HTTP request over the network to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Cesanta Mongoose HTTP Server CGI Remote Code Execcution Vulnerability(CVE-2017-2891)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2891 was patched at 2024-05-15
495.
Remote Code Execution - Unknown Product (CVE-2017-2892) - High [500]
Description: {'vulners_cve_data_all': 'An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT packet can cause an arbitrary out-of-bounds memory read and write potentially resulting in information disclosure, denial of service and remote code execution. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Cesanta Mongoose MQTT Payload Length Remote Code Execution(CVE-2017-2892)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2892 was patched at 2024-05-15
496.
Remote Code Execution - Unknown Product (CVE-2017-2894) - High [500]
Description: {'vulners_cve_data_all': 'An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow resulting in remote code execution. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Cesanta Mongoose MQTT SUBSCRIBE Multiple Topics Remote Code Execution(CVE-2017-2894)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2894 was patched at 2024-05-15
497.
Remote Code Execution - Unknown Product (CVE-2017-2921) - High [500]
Description: {'vulners_cve_data_all': 'An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause an integer overflow, leading to a heap buffer overflow and resulting in denial of service and potential remote code execution. An attacker needs to send a specially crafted websocket packet over network to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Cesanta Mongoose Websocket Protocol Packet Length Code Execution Vulnerability(CVE-2017-2921)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2921 was patched at 2024-05-15
498.
Remote Code Execution - Unknown Product (CVE-2017-2922) - High [500]
Description: {'vulners_cve_data_all': 'An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause a buffer to be allocated while leaving stale pointers which leads to a use-after-free vulnerability which can be exploited to achieve remote code execution. An attacker needs to send a specially crafted websocket packet over the network to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Cesanta Mongoose Websocket Protocol Fragmented Packet Code Execution Vulnerability(CVE-2017-2922)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2922 was patched at 2024-05-15
499.
Remote Code Execution - Unknown Product (CVE-2019-5420) - High [500]
Description: {'vulners_cve_data_all': 'A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
debian: CVE-2019-5420 was patched at 2024-05-15
500.
Remote Code Execution - Unknown Product (CVE-2020-13576) - High [500]
Description: {'vulners_cve_data_all': 'A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-13576 was patched at 2024-05-15
501.
Remote Code Execution - Unknown Product (CVE-2020-20703) - High [500]
Description: {'vulners_cve_data_all': 'Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-20703 was patched at 2024-05-15
502.
Remote Code Execution - Unknown Product (CVE-2021-20308) - High [500]
Description: {'vulners_cve_data_all': 'Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-20308 was patched at 2024-05-15
503.
Remote Code Execution - Unknown Product (CVE-2021-21783) - High [500]
Description: {'vulners_cve_data_all': 'A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-21783 was patched at 2024-05-15
504.
Remote Code Execution - Unknown Product (CVE-2021-31800) - High [500]
Description: {'vulners_cve_data_all': 'Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-31800 was patched at 2024-05-15
505.
Remote Code Execution - Unknown Product (CVE-2021-32798) - High [500]
Description: {'vulners_cve_data_all': 'The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an XSS when a victim opens a malicious ipynb document in Jupyter Notebook. The XSS allows an attacker to execute arbitrary code on the victim computer using Jupyter APIs.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32798 was patched at 2024-05-15
506.
Remote Code Execution - Unknown Product (CVE-2021-43523) - High [500]
Description: {'vulners_cve_data_all': 'In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-43523 was patched at 2024-05-15
507.
Remote Code Execution - Unknown Product (CVE-2022-29622) - High [500]
Description: {'vulners_cve_data_all': 'An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases in which uploading arbitrary files is the desired behavior. Also, there are configuration options in all versions that can change the default behavior of how files are handled. Strapi does not consider this to be a valid vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-29622 was patched at 2024-05-15
508.
Remote Code Execution - Unknown Product (CVE-2023-26035) - High [500]
Description: {'vulners_cve_data_all': 'ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which expects an id to fetch an existing monitor but can be passed an object to create a new one instead. TriggerOn ends up calling shell_exec using the supplied Id. This issue is fixed in This issue is fixed in versions 1.36.33 and 1.37.33.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
debian: CVE-2023-26035 was patched at 2024-05-15
509.
Remote Code Execution - Unknown Product (CVE-2023-36109) - High [500]
Description: {'vulners_cve_data_all': 'Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_raw component at /jerry-core/ecma/base/ecma-helpers-string.c.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Classic Buffer Overflow in Jerryscript) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-36109 was patched at 2024-05-15
510.
Remote Code Execution - Unknown Product (CVE-2023-49093) - High [500]
Description: {'vulners_cve_data_all': 'HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been patched in version 3.9.0', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-49093 was patched at 2024-05-15
511.
Remote Code Execution - Unknown Product (CVE-2023-49606) - High [500]
Description: {'vulners_cve_data_all': 'A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for CVE-2023-49606, [githubexploit] Exploit for CVE-2023-49606) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-49606 was patched at 2024-05-15, 2024-06-05
512.
Denial of Service - Python (CVE-2023-36464) - High [498]
Description: {'vulners_cve_data_all': 'pypdf is an open source, pure-python PDF library. In affected versions an attacker may craft a PDF which leads to an infinite loop if `__parse_content_stream` is executed. That is, for example, the case if the user extracted text from such a PDF. This issue was introduced in pull request #969 and resolved in pull request #1828. Users are advised to upgrade. Users unable to upgrade may modify the line `while peek not in (b"\\r", b"\\n")` in `pypdf/generic/_data_structures.py` to `while peek not in (b"\\r", b"\\n", b"")`.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-36464 was patched at 2024-05-15
513.
Denial of Service - Wireshark (CVE-2015-8735) - High [498]
Description: The get_value function in epan/dissectors/packet-btatt.c in the Bluetooth Attribute (aka BT ATT) dissector in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Wireshark - memcpy (get_value / dissect_btatt) SIGSEGV) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-8735 was patched at 2024-05-15
514.
Denial of Service - Wireshark (CVE-2015-8736) - High [498]
Description: The mp2t_find_next_pcr function in wiretap/mp2t.c in the MP2T file parser in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Wireshark - file_read (wtap_read_bytes_or_eof/mp2t_find_next_pcr) Stack Based Buffer Overflow) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-8736 was patched at 2024-05-15
515.
Denial of Service - Wireshark (CVE-2015-8739) - High [498]
Description: The ipmi_fmt_udpport function in epan/dissectors/packet-ipmi.c in the IPMI dissector in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Wireshark - wmem_alloc Assertion Failure) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-8739 was patched at 2024-05-15
516.
Denial of Service - Wireshark (CVE-2016-6512) - High [498]
Description: epan/dissectors/packet-wap.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Wireshark 2.0.0 < 2.0.4 - MMSE / WAP / WBXML / WSP Dissectors Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-6512 was patched at 2024-05-15
517.
Elevation of Privilege - Linux Kernel (CVE-2019-18675) - High [498]
Description: The
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-18675 was patched at 2024-05-15
518.
Memory Corruption - tiffcrop (CVE-2023-25434) - High [498]
Description: {'vulners_cve_data_all': 'libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesBytes() at /libtiff/tools/tiffcrop.c:3215.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | Tiffcrop processes one or more files created according to the Tag Image File Format, Revision 6.0, specification into one or more TIFF file(s) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-25434 was patched at 2024-05-15
519.
Authentication Bypass - Unknown Product (CVE-2021-42949) - High [496]
Description: {'vulners_cve_data_all': 'The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for CVE-2021-42949) | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-42949 was patched at 2024-05-15
520.
Authentication Bypass - Unknown Product (CVE-2022-32532) - High [496]
Description: {'vulners_cve_data_all': 'Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Incorrect Authorization in Apache Shiro) | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-32532 was patched at 2024-05-15
521.
Denial of Service - RPC (CVE-2013-4261) - High [496]
Description: OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenStack Nova拒绝服务漏洞(CVE-2013-4261)) | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 0.3 | 10 | CVSS Base Score is 3.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-4261 was patched at 2024-05-15
522.
Memory Corruption - Binutils (CVE-2020-16590) - High [496]
Description: {'vulners_cve_data_all': 'A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_symbol_table, as demonstrated in readelf, via a crafted file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-16590 was patched at 2024-05-15
523.
Memory Corruption - Binutils (CVE-2020-35493) - High [496]
Description: A flaw exists in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-35493 was patched at 2024-05-15
524.
Memory Corruption - Binutils (CVE-2020-35495) - High [496]
Description: {'vulners_cve_data_all': 'There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw affects binutils versions prior to 2.34.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-35495 was patched at 2024-05-15
525.
Memory Corruption - Binutils (CVE-2020-35496) - High [496]
Description: {'vulners_cve_data_all': 'There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. This flaw affects binutils versions prior to 2.34.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-35496 was patched at 2024-05-15
526.
Memory Corruption - Binutils (CVE-2020-35507) - High [496]
Description: {'vulners_cve_data_all': 'There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-35507 was patched at 2024-05-15
527.
Security Feature Bypass - FreeIPA (CVE-2024-1481) - High [496]
Description: {'vulners_cve_data_all': 'A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be interpreted as command arguments to kinit on the FreeIPA server, which can lead to a denial of service.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | FreeIPA is a free and open source identity management system | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2024-1481 was patched at 2024-04-30
debian: CVE-2024-1481 was patched at 2024-05-15
oraclelinux: CVE-2024-1481 was patched at 2024-05-03, 2024-05-24
redhat: CVE-2024-1481 was patched at 2024-04-30, 2024-05-22
528.
Remote Code Execution - Git (CVE-2005-4268) - High [495]
Description: Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of service (crash) and possibly
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] VMware ESX Service Console多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | Git | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-4268 was patched at 2024-05-15
529.
Code Injection - Unknown Product (CVE-2016-7954) - High [494]
Description: {'vulners_cve_data_all': 'Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-7954 was patched at 2024-05-15
530.
Code Injection - Unknown Product (CVE-2021-23383) - High [494]
Description: {'vulners_cve_data_all': 'The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-23383 was patched at 2024-05-15
531.
Command Injection - Unknown Product (CVE-2019-8341) - High [494]
Description: {'vulners_cve_data_all': 'An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION COMMANDS}} in a URI. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid because users shouldn't use untrusted templates without sandboxing', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-8341 was patched at 2024-05-15
532.
Command Injection - Unknown Product (CVE-2021-27905) - High [494]
Description: {'vulners_cve_data_all': 'The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also "leaderUrl" alias) parameter that is used to designate another ReplicationHandler on another Solr core to replicate index data into the local core. To prevent a SSRF vulnerability, Solr ought to check these parameters against a similar configuration it uses for the "shards" parameter. Prior to this bug getting fixed, it did not. This problem affects essentially all Solr versions prior to it getting fixed in 8.8.2.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Server-Side Request Forgery in Apache Solr, [githubexploit] Exploit for Server-Side Request Forgery in Apache Solr, [githubexploit] Exploit for Server-Side Request Forgery in Apache Solr, [githubexploit] Exploit for Server-Side Request Forgery in Apache Solr, [seebug] Apache Solr SSRF漏洞 (CVE-2021-27905)) | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-27905 was patched at 2024-05-15
533.
Command Injection - Unknown Product (CVE-2022-35583) - High [494]
Description: {'vulners_cve_data_all': 'wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] wkhtmltopdf 0.12.6 - Server Side Request Forgery Vulnerability, [packetstorm] wkhtmltopdf 0.12.6 Server-Side Request Forgery) | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-35583 was patched at 2024-05-15
534.
Command Injection - Unknown Product (CVE-2022-40083) - High [494]
Description: {'vulners_cve_data_all': 'Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged by attackers to cause a Server-Side Request Forgery (SSRF).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-40083 was patched at 2024-05-15
535.
Command Injection - Unknown Product (CVE-2023-38336) - High [494]
Description: {'vulners_cve_data_all': 'netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Avaya CMS / IR Solaris scp命令行shell命令注入漏洞, [githubexploit] Exploit for OS Command Injection in Openbsd Openssh, [githubexploit] Exploit for OS Command Injection in Openbsd Openssh) | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-38336 was patched at 2024-05-15
536.
Denial of Service - Cacti (CVE-2007-3113) - High [494]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] New cacti packages fix insufficient input sanitising) | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-3113 was patched at 2024-05-15
537.
Denial of Service - nginx (CVE-2011-4315) - High [494]
Description: Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] nginx DNS解析器远程堆缓冲区溢出漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4315 was patched at 2024-05-15
538.
Security Feature Bypass - Cacti (CVE-2023-30534) - High [494]
Description: {'vulners_cve_data_all': 'Cacti is an open source operational monitoring and fault management framework. There are two instances of insecure deserialization in Cacti version 1.2.24. While a viable gadget chain exists in Cacti’s vendor directory (phpseclib), the necessary gadgets are not included, making them inaccessible and the insecure deserializations not exploitable. Each instance of insecure deserialization is due to using the unserialize function without sanitizing the user input. Cacti has a “safe” deserialization that attempts to sanitize the content and check for specific values before calling unserialize, but it isn’t used in these instances. The vulnerable code lies in graphs_new.php, specifically within the host_new_graphs_save function. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.\n', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-30534 was patched at 2024-05-15
539.
Security Feature Bypass - Unknown Product (CVE-2020-7610) - High [494]
Description: {'vulners_cve_data_all': 'All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-7610 was patched at 2024-05-15
540.
Information Disclosure - nginx (CVE-2012-1180) - High [493]
Description: Use-after-free vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] nginx 'ngx_cpystrn()'信息泄露漏洞(CVE-2012-1180)) | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1180 was patched at 2024-05-15
541.
Cross Site Scripting - Perl (CVE-2008-5080) - High [492]
Description: awstats.pl in AWStats 6.8 and earlier does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] AWStats awstats.pl跨站脚本漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5080 was patched at 2024-05-15
542.
Cross Site Scripting - Perl (CVE-2010-2087) - High [492]
Description: Oracle Mojarra 1.2_14 and 2.0.2, as used in IBM WebSphere Application Server, Caucho Resin, and other applications, does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Oracle Mojarra ViewState远程跨站脚本漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-2087 was patched at 2024-05-15
543.
Cross Site Scripting - Perl (CVE-2012-2751) - High [492]
Description: ModSecurity before 2.6.6, when used with PHP, does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ModSecurity引号解析安全限制绕过漏洞(CVE-2012-2751), [packetstorm] Parodia 6.8 SQL Injection) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-2751 was patched at 2024-05-15
544.
Cross Site Scripting - Perl (CVE-2012-4230) - High [492]
Description: The bbcode plugin in TinyMCE 3.5.8 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] TinyMCE 3.5.8 Cross Site Scripting) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-4230 was patched at 2024-05-15
545.
Cross Site Scripting - Perl (CVE-2013-1855) - High [492]
Description: The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Ruby on Rails 'sanitize_css()'方法跨站脚本漏洞(CVE-2013-1855)) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-1855 was patched at 2024-05-15
546.
Cross Site Scripting - Roundcube (CVE-2009-0413) - High [492]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Roundcube Webmail邮件消息HTML注入漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Roundcube is a web-based IMAP email client | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0413 was patched at 2024-05-15
547.
Cross Site Scripting - Roundcube (CVE-2013-5645) - High [492]
Description: Multiple cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Roundcube Webmail 0.9.2 Cross Site Scripting) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Roundcube is a web-based IMAP email client | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-5645 was patched at 2024-05-15
548.
Arbitrary File Writing - Unknown Product (CVE-2009-4013) - High [491]
Description: {'vulners_cve_data_all': 'Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vectors involving (1) control field names, (2) control field values, and (3) control files of patch systems.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Debian Lintian多个本地安全漏洞) | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4013 was patched at 2024-05-15
549.
Arbitrary File Writing - Unknown Product (CVE-2019-3681) - High [491]
Description: {'vulners_cve_data_all': 'A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Software Development Kit 12-SP5, SUSE Linux Enterprise Software Development Kit 12-SP4; openSUSE Leap 15.1, openSUSE Factory allowed remote attackers that can change downloaded packages to overwrite arbitrary files. This issue affects: SUSE Linux Enterprise Module for Development Tools 15 osc versions prior to 0.169.1-3.20.1. SUSE Linux Enterprise Software Development Kit 12-SP5 osc versions prior to 0.162.1-15.9.1. SUSE Linux Enterprise Software Development Kit 12-SP4 osc versions prior to 0.162.1-15.9.1. openSUSE Leap 15.1 osc versions prior to 0.169.1-lp151.2.15.1. openSUSE Factory osc versions prior to 0.169.0 .', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-3681 was patched at 2024-05-15
550.
Denial of Service - BIND (CVE-2021-32823) - High [491]
Description: In the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32823 was patched at 2024-05-15
551.
Denial of Service - Curl (CVE-2011-0418) - High [491]
Description: The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] FreeBSD 9.1 - ftpd Remote Denial of Service, [seebug] FreeBSD 9.1 ftpd Remote Denial of Service, [exploitdb] FreeBSD 9.1 - 'ftpd' Remote Denial of Service, [packetstorm] Multiple Vendors libc/glob(3) GLOB_BRACE|GLOB_LIMIT Memory Exhaustion) | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | Curl is a command-line tool for transferring data specified with URL syntax | |
| 0.4 | 10 | CVSS Base Score is 4.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-0418 was patched at 2024-05-15
552.
Denial of Service - FFmpeg (CVE-2009-4636) - High [491]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg多个媒体文件解析拒绝服务和代码执行漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4636 was patched at 2024-05-15
553.
Denial of Service - FFmpeg (CVE-2009-4639) - High [491]
Description: The av_rescale_rnd function in the AVI demuxer in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg多个媒体文件解析拒绝服务和代码执行漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4639 was patched at 2024-05-15
554.
Memory Corruption - FFmpeg (CVE-2020-35964) - High [491]
Description: track_header in libavformat/vividas.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-35964 was patched at 2024-05-15
555.
Memory Corruption - macOS (CVE-2021-31321) - High [491]
Description: {'vulners_cve_data_all': 'Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic function of their custom fork of the rlottie library. A remote attacker might be able to overwrite Telegram's stack memory out-of-bounds on a victim device via a malicious animated sticker.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | macOS is an operating system developed and marketed by Apple Inc | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-31321 was patched at 2024-05-15
556.
Denial of Service - Apache HTTP Server (CVE-2011-4415) - High [489]
Description: The ap_pregsub function in server/util.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Apache < 2.0.64 / < 2.2.21 mod_setenvif - Integer Overflow Vulnerability, [seebug] Apache HTTP Server 'ap_pregsub()'函数本地拒绝服务漏洞(CVE-2011-4415), [seebug] Apache HTTP Server "ap_pregsub()"函数本地权限提升漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.1 | 10 | CVSS Base Score is 1.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4415 was patched at 2024-05-15
557.
Path Traversal - Git (CVE-2021-40978) - High [489]
Description: The mkdocs 1.2.2 built-in dev-server allows
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Path Traversal in Mkdocs) | |
| 0.7 | 15 | Path Traversal | |
| 0.4 | 14 | Git | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-40978 was patched at 2024-05-15
558.
Cross Site Scripting - Cacti (CVE-2023-39366) - High [488]
Description: Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-39366 was patched at 2024-05-15
559.
Cross Site Scripting - Cacti (CVE-2023-39510) - High [488]
Description: Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-39510 was patched at 2024-05-15
560.
Cross Site Scripting - Cacti (CVE-2023-39512) - High [488]
Description: Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-39512 was patched at 2024-05-15
561.
Cross Site Scripting - Cacti (CVE-2023-39514) - High [488]
Description: Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-39514 was patched at 2024-05-15
562.
Information Disclosure - Git (CVE-2024-31497) - High [488]
Description: {'vulners_cve_data_all': 'In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scenario where an adversary is able to read messages signed by PuTTY or Pageant. The required set of signed messages may be publicly readable because they are stored in a public Git service that supports use of SSH for commit signing, and the signatures were made by Pageant through an agent-forwarding mechanism. In other words, an adversary may already have enough signature information to compromise a victim's private key, even if there is no further use of vulnerable PuTTY versions. After a key compromise, an adversary may be able to conduct supply-chain attacks on software maintained in Git. A second, independent scenario is that the adversary is an operator of an SSH server to which the victim authenticates (for remote login or file copy), even though this server is not fully trusted by the victim, and the victim uses the same private key for SSH connections to other services operated by other entities. Here, the rogue server operator (who would otherwise have no way to determine the victim's private key) can derive the victim's private key, and then use it for unauthorized access to those other services. If the other services include Git services, then again it may be possible to conduct supply-chain attacks on software maintained in Git. This also affects, for example, FileZilla before 3.67.0, WinSCP before 6.3.3, TortoiseGit before 2.15.0.1, and TortoiseSVN through 1.14.6.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Putty) | |
| 0.83 | 15 | Information Disclosure | |
| 0.4 | 14 | Git | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-31497 was patched at 2024-05-15
redos: CVE-2024-31497 was patched at 2024-05-03
563.
Remote Code Execution - Unknown Product (CVE-2007-1536) - High [488]
Description: {'vulners_cve_data_all': 'Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file that triggers a heap-based buffer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2007-005多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-1536 was patched at 2024-05-15
564.
Remote Code Execution - Unknown Product (CVE-2007-3762) - High [488]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to execute arbitrary code by sending a long (1) voice or (2) video RTP frame.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Asterisk IAX2隧道驱动IAX2_Write函数远程栈溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-3762 was patched at 2024-05-15
565.
Remote Code Execution - Unknown Product (CVE-2007-5849) - High [488]
Description: {'vulners_cve_data_all': 'Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] CUPS SNMP后端asn1_get_string()函数远程栈溢出漏洞, [seebug] Apple Mac OS X v10.5.1 2007-009 Multiple Security Vulnerabilities) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-5849 was patched at 2024-05-15
566.
Remote Code Execution - Unknown Product (CVE-2008-0888) - High [488]
Description: {'vulners_cve_data_all': 'The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Info-ZIP UnZip inflate_dynamic()函数堆破坏漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-0888 was patched at 2024-05-15
567.
Remote Code Execution - Unknown Product (CVE-2008-0984) - High [488]
Description: {'vulners_cve_data_all': 'The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] VideoLAN VLC媒体播放器MP4 Demuxer远程代码执行漏洞, [packetstorm] Core Security Technologies Advisory 2008.0130) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-0984 was patched at 2024-05-15
568.
Remote Code Execution - Unknown Product (CVE-2008-1670) - High [488]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted image.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] KDE KHTML PNGLoader堆溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1670 was patched at 2024-05-15
569.
Remote Code Execution - Unknown Product (CVE-2008-2426) - High [488]
Description: {'vulners_cve_data_all': 'Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1.4.0 allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a PNM image with a crafted header, related to the load function in src/modules/loaders/loader_pnm.c; or (2) a crafted XPM image, related to the load function in src/modules/loader_xpm.c.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] imlib2库多个栈溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-2426 was patched at 2024-05-15
570.
Remote Code Execution - Unknown Product (CVE-2008-3632) - High [488]
Description: {'vulners_cve_data_all': 'Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a web page with crafted Cascading Style Sheets (CSS) import statements.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple iPod Touch 2.1版本之前多个远程漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3632 was patched at 2024-05-15
571.
Remote Code Execution - Unknown Product (CVE-2008-3732) - High [488]
Description: {'vulners_cve_data_all': 'Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3732 was patched at 2024-05-15
572.
Remote Code Execution - Unknown Product (CVE-2008-4654) - High [488]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows remote attackers to execute arbitrary code via a TiVo TY media file with a header containing a crafted size value.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([saint] VLC media player TY file parse_master buffer overflow, [saint] VLC media player TY file parse_master buffer overflow, [saint] VLC media player TY file parse_master buffer overflow, [saint] VLC media player TY file parse_master buffer overflow, [packetstorm] VideoLAN VLC TiVo Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-4654 was patched at 2024-05-15
573.
Remote Code Execution - Unknown Product (CVE-2008-4686) - High [488]
Description: {'vulners_cve_data_all': 'Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary code via a crafted .ty file, a different vulnerability than CVE-2008-4654.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([saint] VLC media player TY file parse_master buffer overflow, [saint] VLC media player TY file parse_master buffer overflow, [saint] VLC media player TY file parse_master buffer overflow, [saint] VLC media player TY file parse_master buffer overflow, [packetstorm] VideoLAN VLC TiVo Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-4686 was patched at 2024-05-15
574.
Remote Code Execution - Unknown Product (CVE-2008-4829) - High [488]
Description: {'vulners_cve_data_all': 'Multiple buffer overflows in lib/http.c in Streamripper 1.63.5 allow remote attackers to execute arbitrary code via (1) a long "Zwitterion v" HTTP header, related to the http_parse_sc_header function; (2) a crafted pls playlist with a long entry, related to the http_get_pls function; or (3) a crafted m3u playlist with a long File entry, related to the http_get_m3u function.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Streamripper lib/http.c文件多个缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-4829 was patched at 2024-05-15
575.
Remote Code Execution - Unknown Product (CVE-2008-5032) - High [488]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in VideoLAN VLC media player 0.5.0 through 0.9.5 might allow user-assisted attackers to execute arbitrary code via the header of an invalid CUE image file, related to modules/access/vcd/cdrom.c. NOTE: this identifier originally included an issue related to RealText, but that issue has been assigned a separate identifier, CVE-2008-5036.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([saint] VLC media player RealText subtitle file ParseRealText buffer overflow, [saint] VLC media player RealText subtitle file ParseRealText buffer overflow, [saint] VLC media player RealText subtitle file ParseRealText buffer overflow, [saint] VLC media player RealText subtitle file ParseRealText buffer overflow, [packetstorm] VLC Media Player RealText Subtitle Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5032 was patched at 2024-05-15
576.
Remote Code Execution - Unknown Product (CVE-2008-5036) - High [488]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execute arbitrary code via an an invalid RealText (rt) subtitle file, related to the ParseRealText function in modules/demux/subtitle.c. NOTE: this issue was SPLIT from CVE-2008-5032 on 20081110.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([saint] VLC media player RealText subtitle file ParseRealText buffer overflow, [saint] VLC media player RealText subtitle file ParseRealText buffer overflow, [saint] VLC media player RealText subtitle file ParseRealText buffer overflow, [saint] VLC media player RealText subtitle file ParseRealText buffer overflow, [packetstorm] VLC Media Player RealText Subtitle Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5036 was patched at 2024-05-15
577.
Remote Code Execution - Unknown Product (CVE-2008-5101) - High [488]
Description: {'vulners_cve_data_all': 'Buffer overflow in the BMP reader in OptiPNG 0.6 and 0.6.1 allows user-assisted attackers to execute arbitrary code via a crafted BMP image, related to an "array overflow."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OptiPNG BMP阅读器缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5101 was patched at 2024-05-15
578.
Remote Code Execution - Unknown Product (CVE-2008-5276) - High [488]
Description: {'vulners_cve_data_all': 'Integer overflow in the ReadRealIndex function in real.c in the Real demuxer plugin in VideoLAN VLC media player 0.9.0 through 0.9.7 allows remote attackers to execute arbitrary code via a malformed RealMedia (.rm) file that triggers a heap-based buffer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5276 was patched at 2024-05-15
579.
Remote Code Execution - Unknown Product (CVE-2009-0186) - High [488]
Description: {'vulners_cve_data_all': 'Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] libsndfile CAF文件处理堆溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0186 was patched at 2024-05-15
580.
Remote Code Execution - Unknown Product (CVE-2009-1376) - High [488]
Description: {'vulners_cve_data_all': 'Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows. NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Pidgin多个缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1376 was patched at 2024-05-15
581.
Remote Code Execution - Unknown Product (CVE-2009-3607) - High [488]
Description: {'vulners_cve_data_all': 'Integer overflow in the create_surface_from_thumbnail_data function in glib/poppler-page.cc in Poppler 0.x allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Poppler 'create_surface_from_thumbnail_data()'整数溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3607 was patched at 2024-05-15
582.
Remote Code Execution - Unknown Product (CVE-2009-4270) - High [488]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Ghostscript errprintf()函数PDF文件处理栈溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4270 was patched at 2024-05-15
583.
Remote Code Execution - Unknown Product (CVE-2010-2546) - High [488]
Description: {'vulners_cve_data_all': 'Multiple heap-based buffer overflows in loaders/load_it.c in libmikmod, possibly 3.1.12, might allow remote attackers to execute arbitrary code via (1) crafted samples or (2) crafted instrument definitions in an Impulse Tracker file, related to panpts, pitpts, and IT_ProcessEnvelope. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3995.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Winamp模块解码器插件多个缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-2546 was patched at 2024-05-15
584.
Remote Code Execution - Unknown Product (CVE-2011-4130) - High [488]
Description: {'vulners_cve_data_all': 'Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute arbitrary code via vectors involving an error that occurs after an FTP data transfer.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ProFTPD Prior To 1.3.3g Use-After-Free 远程代码执行漏洞, [seebug] ProFTPD响应池释放后重用代码执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4130 was patched at 2024-05-15
585.
Remote Code Execution - Unknown Product (CVE-2012-1775) - High [488]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code via a crafted MMS:// stream.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] VLC Media Player MMS流栈缓冲区溢出漏洞, [saint] VideoLAN VLC Media Player MMS URI Stack Overflow, [saint] VideoLAN VLC Media Player MMS URI Stack Overflow, [saint] VideoLAN VLC Media Player MMS URI Stack Overflow, [saint] VideoLAN VLC Media Player MMS URI Stack Overflow, [packetstorm] VLC MMS Stream Handling Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1775 was patched at 2024-05-15
586.
Remote Code Execution - Unknown Product (CVE-2015-7505) - High [488]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted LZW stream in a GIF file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Libnsgif 0.1.2 Stack Overflow / Out-Of-Bounds Read Exploit) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-7505 was patched at 2024-05-15
587.
Remote Code Execution - Unknown Product (CVE-2015-7508) - High [488]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in the bmp_decode_rle function in libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the last row of RLE data in a crafted BMP file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Libnsbmp 0.1.2 Heap Overflow / Out-Of-Bounds Read Exploit) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-7508 was patched at 2024-05-15
588.
Remote Code Execution - Unknown Product (CVE-2017-2814) - High [488]
Description: {'vulners_cve_data_all': 'An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted pdf can cause an image resizing after allocation has already occurred, resulting in heap corruption which can lead to code execution. An attacker controlled PDF file can be used to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Poppler PDF Image Display DCTStream::readScan() Code Execution Vulnerability(CVE-2017-2814)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2814 was patched at 2024-05-15
589.
Remote Code Execution - Unknown Product (CVE-2018-15537) - High [488]
Description: {'vulners_cve_data_all': 'Unrestricted file upload (with remote code execution) in OCS Inventory NG ocsreports allows a privileged user to gain access to the server via crafted HTTP requests.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] OCS Inventory NG ocsreports Shell Upload, [zdt] OCS Inventory NG ocsreports Shell Upload Vulnerability) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-15537 was patched at 2024-05-15
590.
Remote Code Execution - Unknown Product (CVE-2019-5064) - High [488]
Description: {'vulners_cve_data_all': 'An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A specially crafted JSON file can cause a buffer overflow, resulting in multiple heap corruptions and potentially code execution. An attacker can provide a specially crafted file to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-5064 was patched at 2024-05-15
591.
Remote Code Execution - Unknown Product (CVE-2020-24020) - High [488]
Description: {'vulners_cve_data_all': 'Buffer Overflow vulnerability in FFMpeg 4.2.3 in dnn_execute_layer_pad in libavfilter/dnn/dnn_backend_native_layer_pad.c due to a call to memcpy without length checks, which could let a remote malicious user execute arbitrary code.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-24020 was patched at 2024-05-15
592.
Remote Code Execution - Unknown Product (CVE-2020-28589) - High [488]
Description: {'vulners_cve_data_all': 'An improper array index validation vulnerability exists in the LoadObj functionality of tinyobjloader v2.0-rc1 and tinyobjloader development commit 79d4421. A specially crafted file could lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-28589 was patched at 2024-05-15
593.
Remote Code Execution - Unknown Product (CVE-2021-23169) - High [488]
Description: {'vulners_cve_data_all': 'A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-23169 was patched at 2024-05-15
594.
Remote Code Execution - Unknown Product (CVE-2022-22909) - High [488]
Description: {'vulners_cve_data_all': 'HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Hotel Druid 3.0.3 Remote Code Execution, [githubexploit] Exploit for Code Injection in Digitaldruid Hoteldruid, [githubexploit] Exploit for Code Injection in Digitaldruid Hoteldruid, [zdt] Hotel Druid 3.0.3 - Remote Code Execution Exploit, [exploitdb] Hotel Druid 3.0.3 - Remote Code Execution (RCE)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-22909 was patched at 2024-05-15
595.
Remote Code Execution - Unknown Product (CVE-2022-24715) - High [488]
Description: {'vulners_cve_data_all': 'Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade should limit access to the Icinga Web 2 configuration.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Path Traversal in Icinga Icinga Web 2, [githubexploit] Exploit for Path Traversal in Icinga Icinga Web 2, [githubexploit] Exploit for Path Traversal in Icinga Icinga Web 2, [zdt] Icinga Web 2.10 - Authenticated Remote Code Execution Exploit, [packetstorm] Icinga Web 2.10 Remote Code Execution, [exploitdb] Icinga Web 2.10 - Authenticated Remote Code Execution) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-24715 was patched at 2024-05-15
596.
Denial of Service - Perl (CVE-2007-3763) - High [486]
Description: The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] asa-2007-015.rb.txt, [seebug] Asterisk多个远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-3763 was patched at 2024-05-15
597.
Denial of Service - Perl (CVE-2009-1375) - High [486]
Description: The PurpleCircBuffer implementation in Pidgin (formerly Gaim) before 2.5.6 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Pidgin多个缓冲区溢出漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1375 was patched at 2024-05-15
598.
Denial of Service - Perl (CVE-2009-3626) - High [486]
Description: Perl 5.10.1 allows context-dependent attackers to cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Perl UTF-8规则表达式处理远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3626 was patched at 2024-05-15
599.
Denial of Service - Perl (CVE-2011-0761) - High [486]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-0761 was patched at 2024-05-15
600.
Denial of Service - Perl (CVE-2012-6084) - High [486]
Description: modules/m_capab.c in (1) ircd-ratbox before 3.0.8 and (2) Charybdis before 3.4.2 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Ratbox IRCd Denial Of Service, [zdt] Ratbox IRCd Denial Of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-6084 was patched at 2024-05-15
601.
Denial of Service - Perl (CVE-2013-0238) - High [486]
Description: The try_parse_v4_netmask function in hostmask.c in IRCD-Hybrid before 8.0.6 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ircd-hybrid 8.0.5 - Denial of Service, [zdt] ircd-hybrid 8.0.5 Denial Of Service, [packetstorm] ircd-hybrid 8.0.5 Denial Of Service, [exploitpack] ircd-hybrid 8.0.5 - Denial of Service, [exploitdb] ircd-hybrid 8.0.5 - Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-0238 was patched at 2024-05-15
602.
Denial of Service - Python (CVE-2012-2921) - High [486]
Description: Universal Feed Parser (aka feedparser or
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] feedparser 拒绝服务漏洞(CVE-2012-2921)) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-2921 was patched at 2024-05-15
603.
Denial of Service - Wireshark (CVE-2009-3242) - High [486]
Description: Unspecified vulnerability in packet.c in the GSM A RR dissector in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Wireshark: Multiple vulnerabilities) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3242 was patched at 2024-05-15
604.
Denial of Service - Wireshark (CVE-2009-3549) - High [486]
Description: packet-paltalk.c in the Paltalk dissector in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Wireshark 1.2.2和1.0.9版本修复多个拒绝服务漏洞, [seebug] Wireshark: Multiple vulnerabilities) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3549 was patched at 2024-05-15
605.
Denial of Service - Wireshark (CVE-2009-3551) - High [486]
Description: Off-by-one error in the dissect_negprot_response function in packet-smb.c in the SMB dissector in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Wireshark 1.2.2和1.0.9版本修复多个拒绝服务漏洞, [seebug] Wireshark: Multiple vulnerabilities) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3551 was patched at 2024-05-15
606.
Denial of Service - Wireshark (CVE-2015-8740) - High [486]
Description: The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Wireshark - dissect_diameter_base_framed_ipv6_prefix Stack Based Buffer Overflow) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-8740 was patched at 2024-05-15
607.
Authentication Bypass - Unknown Product (CVE-2022-46146) - High [484]
Description: {'vulners_cve_data_all': 'Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml file and users' bcrypted passwords, they can bypass security by poisoning the built-in authentication cache. Versions 0.7.2 and 0.8.2 contain a fix for the issue. There is no workaround, but attacker must have access to the hashed password to use this functionality.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-46146 was patched at 2024-05-15
608.
Code Injection - Unknown Product (CVE-2007-4575) - High [482]
Description: {'vulners_cve_data_all': 'HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code via crafted database documents, related to "exposing static java methods."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenOffice HSQLDB Database Engine Unspecified Java Code Execution Vulnerability, [seebug] OpenOffice HSQLDB数据库引擎Java代码执行漏洞, [canvas] Immunity Canvas: OOO_230) | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-4575 was patched at 2024-05-15
609.
Command Injection - Unknown Product (CVE-2021-32714) - High [482]
Description: {'vulners_cve_data_all': 'hyper is an HTTP library for Rust. In versions prior to 0.14.10, hyper's HTTP server and client code had a flaw that could trigger an integer overflow when decoding chunk sizes that are too big. This allows possible data loss, or if combined with an upstream HTTP proxy that allows chunk sizes larger than hyper does, can result in "request smuggling" or "desync attacks." The vulnerability is patched in version 0.14.10. Two possible workarounds exist. One may reject requests manually that contain a `Transfer-Encoding` header or ensure any upstream proxy rejects `Transfer-Encoding` chunk sizes greater than what fits in 64-bit unsigned integers.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32714 was patched at 2024-05-15
610.
Denial of Service - TLS (CVE-2022-38153) - High [482]
Description: An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is exploitable. Man-in-the-middle attackers or a malicious server can crash
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] wolfSSL 5.3.0 Denial Of Service Vulnerability) | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | TLS | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-38153 was patched at 2024-05-15
611.
Memory Corruption - TLS (CVE-2022-42905) - High [482]
Description: {'vulners_cve_data_all': 'In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can trigger a buffer over-read on the heap of 5 bytes. (WOLFSSL_CALLBACKS is only intended for debugging.)', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] wolfSSL 5.5.2 WOLFSSL_CALLBACKS Heap Buffer Over-Read Vulnerability, [packetstorm] wolfSSL WOLFSSL_CALLBACKS Heap Buffer Over-Read) | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | TLS | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-42905 was patched at 2024-05-15
612.
Remote Code Execution - TLS (CVE-2023-26463) - High [482]
Description: strongSwan 5.9.8 and 5.9.9 potentially allows
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | TLS | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-26463 was patched at 2024-05-15
613.
Security Feature Bypass - Unknown Product (CVE-2019-10173) - High [482]
Description: {'vulners_cve_data_all': 'It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] OpenMRS Reporting Module 0.9.7 Remote Code Execution, [exploitpack] OpenMRS Reporting Module 0.9.7 - Remote Code Execution, [zdt] OpenMRS Reporting Module 0.9.7 - Remote Code Execution, [exploitdb] OpenMRS Reporting Module 0.9.7 - Remote Code Execution) | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-10173 was patched at 2024-05-15
614.
Arbitrary File Writing - Unknown Product (CVE-2010-0012) - High [479]
Description: {'vulners_cve_data_all': 'Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Transmission任意文件覆盖漏洞) | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-0012 was patched at 2024-05-15
615.
Denial of Service - BIND (CVE-2010-0213) - High [479]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ISC BIND 9 RRSIG记录类型远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.3 | 10 | CVSS Base Score is 2.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-0213 was patched at 2024-05-15
616.
Denial of Service - BIND (CVE-2011-2465) - High [479]
Description: Unspecified vulnerability in ISC
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ISC BIND 9 RPZ配置远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.3 | 10 | CVSS Base Score is 2.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-2465 was patched at 2024-05-15
617.
Memory Corruption - macOS (CVE-2021-31317) - High [479]
Description: Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | macOS is an operating system developed and marketed by Apple Inc | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-31317 was patched at 2024-05-15
618.
Spoofing - PHP (CVE-2008-3456) - High [478]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin setup.php文件跨站脚本执行漏洞) | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3456 was patched at 2024-05-15
619.
Denial of Service - GPAC (CVE-2020-23267) - High [477]
Description: An issue was discovered in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23267 was patched at 2024-05-15
620.
Path Traversal - Git (CVE-2024-32465) - High [477]
Description: {'vulners_cve_data_all': 'Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for CVE-2024-32004) | |
| 0.7 | 15 | Path Traversal | |
| 0.4 | 14 | Git | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-32465 was patched at 2024-05-15
redos: CVE-2024-32465 was patched at 2024-05-27
ubuntu: CVE-2024-32465 was patched at 2024-05-28
621.
Cross Site Scripting - Cacti (CVE-2009-4032) - High [476]
Description: Multiple cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Cacti 0.8.7e: Multiple Security Issues, [seebug] New cacti packages fix insufficient input sanitising, [exploitpack] Cacti 0.8.7e - Multiple Vulnerabilities, [packetstorm] Cacti 0.8.7e Cross Site Scripting, [exploitdb] Cacti 0.8.7e - Multiple Vulnerabilities) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4032 was patched at 2024-05-15
622.
Cross Site Scripting - Cacti (CVE-2010-2543) - High [476]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Cacti 0.8.7e: Multiple Security Issues, [seebug] New cacti packages fix insufficient input sanitising, [exploitpack] Cacti 0.8.7e - Multiple Vulnerabilities, [packetstorm] Cacti 0.8.7e Cross Site Scripting, [exploitdb] Cacti 0.8.7e - Multiple Vulnerabilities) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-2543 was patched at 2024-05-15
623.
Cross Site Scripting - HID (CVE-2005-0870) - High [476]
Description: Multiple cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Hardened-PHP Project Security Advisory 2005-21.81) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | HID | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-0870 was patched at 2024-05-15
624.
Cross Site Scripting - ntopng (CVE-2014-4329) - High [476]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Ntop-NG 1.1 Cross Site Scripting) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | ntopng is an open-source computer software for monitoring traffic on a computer network | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-4329 was patched at 2024-05-15
625.
Cross Site Scripting - ntopng (CVE-2014-5464) - High [476]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] ntopng 1.2.0 Cross Site Scripting) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | ntopng is an open-source computer software for monitoring traffic on a computer network | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-5464 was patched at 2024-05-15
626.
Remote Code Execution - Unknown Product (CVE-2002-0392) - High [476]
Description: {'vulners_cve_data_all': 'Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([canvas] Immunity Canvas: APACHECHUNK_WIN32, [saint] Apache chunked encoding buffer overflow, [saint] Apache chunked encoding buffer overflow, [saint] Apache chunked encoding buffer overflow, [saint] Apache chunked encoding buffer overflow, [packetstorm] Apache Win32 Chunked Encoding) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-0392 was patched at 2024-05-15
627.
Remote Code Execution - Unknown Product (CVE-2003-0015) - High [476]
Description: {'vulners_cve_data_all': 'Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Checkin-prog commands.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([d2] DSquare Exploit Pack: D2SEC_PSERVERD) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0015 was patched at 2024-05-15
628.
Remote Code Execution - Unknown Product (CVE-2003-0705) - High [476]
Description: {'vulners_cve_data_all': 'Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Mah-Jong 1.4 Client/Server Remote sscanf() Buffer Overflow Vulnerability, [exploitpack] Mah-Jong 1.4 - ClientServer Remote sscanf() Buffer Overflow, [exploitdb] Mah-Jong 1.4 - Client/Server Remote sscanf() Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0705 was patched at 2024-05-15
629.
Remote Code Execution - Unknown Product (CVE-2003-0962) - High [476]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([canvas] Immunity Canvas: RSYNC) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0962 was patched at 2024-05-15
630.
Remote Code Execution - Unknown Product (CVE-2004-0396) - High [476]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([canvas] Immunity Canvas: PSERVERD) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0396 was patched at 2024-05-15
631.
Remote Code Execution - Unknown Product (CVE-2004-0397) - High [476]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute arbitrary code via a (1) DAV2 REPORT query or (2) get-dated-rev svn-protocol command.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([canvas] Immunity Canvas: SVNDATE, [packetstorm] Subversion Date Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0397 was patched at 2024-05-15
632.
Remote Code Execution - Unknown Product (CVE-2004-0782) - High [476]
Description: {'vulners_cve_data_all': 'Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Solaris 10 dtprintinfo / libXm / libXpm Security Issues, [zdt] Solaris 10 dtprintinfo / libXm / libXpm Security Issues Vulnerability) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0782 was patched at 2024-05-15
633.
Remote Code Execution - Unknown Product (CVE-2004-1561) - High [476]
Description: {'vulners_cve_data_all': 'Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of headers.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([canvas] Immunity Canvas: ICECAST, [packetstorm] Icecast 2.0.1 Header Overwrite) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-1561 was patched at 2024-05-15
634.
Remote Code Execution - Unknown Product (CVE-2005-3627) - High [476]
Description: {'vulners_cve_data_all': 'Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index" value that is not checked by DCTStream::readHuffmanTables, and (3) certain uses of the scanInfo.numComps value by DCTStream::readScanInfo.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Poppler PDF Image Display DCTStream::readProgressiveSOF() Code Execution Vulnerability(CVE-2017-2818)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-3627 was patched at 2024-05-15
635.
Remote Code Execution - Unknown Product (CVE-2006-0460) - High [476]
Description: {'vulners_cve_data_all': 'Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] BomberClone 0.11.6.2 - Error Messages Remote Buffer Overflow, [seebug] BomberClone < 0.11.6.2 - (Error Messages) Remote Buffer Overflow Exploit, [seebug] BomberClone < 0.11.6.2 (Error Messages) Remote Buffer Overflow Exploit, [packetstorm] Bomberclone 0.11.6 Buffer Overflow, [exploitdb] BomberClone < 0.11.6.2 - Error Messages Remote Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-0460 was patched at 2024-05-15
636.
Remote Code Execution - Unknown Product (CVE-2006-1236) - High [476]
Description: {'vulners_cve_data_all': 'Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrary code via a long setup sound command, a different vulnerability than CVE-2006-1010.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Crossfire Server 1.0 Buffer Overflow, [zdt] crossfire-server 1.9.0 - SetUp() Remote Buffer Overflow Exploit, [exploitdb] crossfire-server 1.9.0 - 'SetUp()' Remote Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-1236 was patched at 2024-05-15
637.
Remote Code Execution - Unknown Product (CVE-2006-3242) - High [476]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the browse_get_namespace function in imap/browse.c of Mutt 1.4.2.1 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long namespaces received from the IMAP server.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Mutt BROWSE_GET_NAMESPACE IMAP名称空间处理远程溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3242 was patched at 2024-05-15
638.
Remote Code Execution - Unknown Product (CVE-2006-3460) - High [476]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in the JPEG decoder in the TIFF library (libtiff) before 3.8.2 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an encoded JPEG stream that is longer than the scan line size (TiffScanLineSize).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Libtiff图形库多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3460 was patched at 2024-05-15
639.
Remote Code Execution - Unknown Product (CVE-2006-3461) - High [476]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in the PixarLog decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbitrary code via unknown vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Libtiff图形库多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3461 was patched at 2024-05-15
640.
Remote Code Execution - Unknown Product (CVE-2006-3462) - High [476]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in the NeXT RLE decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbitrary code via unknown vectors involving decoding large RLE images.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Libtiff图形库多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3462 was patched at 2024-05-15
641.
Remote Code Execution - Unknown Product (CVE-2006-3465) - High [476]
Description: {'vulners_cve_data_all': 'Unspecified vulnerability in the custom tag support for the TIFF library (libtiff) before 3.8.2 allows remote attackers to cause a denial of service (instability or crash) and execute arbitrary code via unknown vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Libtiff图形库多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3465 was patched at 2024-05-15
642.
Remote Code Execution - Unknown Product (CVE-2006-4182) - High [476]
Description: {'vulners_cve_data_all': 'Integer overflow in ClamAV 0.88.1 and 0.88.4, and other versions before 0.88.5, allows remote attackers to cause a denial of service (scanning service crash) and execute arbitrary code via a crafted Portable Executable (PE) file that leads to a heap-based buffer overflow when less memory is allocated than expected.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2006-007存在多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4182 was patched at 2024-05-15
643.
Remote Code Execution - Unknown Product (CVE-2006-4335) - High [476]
Description: {'vulners_cve_data_all': 'Array index error in the make_table function in unlzh.c in the LZH decompression component in gzip 1.3.5, when running on certain platforms, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GZIP archive that triggers an out-of-bounds write, aka a "stack modification vulnerability."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2006-007存在多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4335 was patched at 2024-05-15
644.
Remote Code Execution - Unknown Product (CVE-2006-4336) - High [476]
Description: {'vulners_cve_data_all': 'Buffer underflow in the build_tree function in unpack.c in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted leaf count table that causes a write to a negative index.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2006-007存在多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4336 was patched at 2024-05-15
645.
Remote Code Execution - Unknown Product (CVE-2006-4337) - High [476]
Description: {'vulners_cve_data_all': 'Buffer overflow in the make_table function in the LHZ component in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted decoding table in a GZIP archive.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2006-007存在多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4337 was patched at 2024-05-15
646.
Remote Code Execution - Unknown Product (CVE-2007-5197) - High [476]
Description: {'vulners_cve_data_all': 'Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified vectors related to Reduce in Montgomery-based Pow methods.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Mono System.Math BigInteger整数溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-5197 was patched at 2024-05-15
647.
Remote Code Execution - Unknown Product (CVE-2007-6335) - High [476]
Description: {'vulners_cve_data_all': 'Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MEW packed PE file, which triggers a heap-based buffer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ClamAV 0.91.2 libclamav MEW PE Buffer Overflow Exploit, [exploitpack] ClamAV 0.91.2 - libclamav MEW PE Buffer Overflow, [exploitdb] ClamAV 0.91.2 - libclamav MEW PE Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-6335 was patched at 2024-05-15
648.
Remote Code Execution - Unknown Product (CVE-2007-6681) - High [476]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, and (3) Vplayer file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] VideoLAN VLC Media Player 0.8.6d SSA Parsing Double Sh311 - Universal, [seebug] VLC 0.8.6d SSA Parsing Double Sh311 Universal Exploit, [packetstorm] vlc-doubleshell.txt, [exploitdb] VideoLAN VLC Media Player 0.8.6d SSA Parsing Double Sh311 - Universal) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-6681 was patched at 2024-05-15
649.
Remote Code Execution - Unknown Product (CVE-2007-6682) - High [476]
Description: {'vulners_cve_data_all': 'Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifiers in the Connection parameter.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] vlc-format.txt, [exploitpack] VideoLAN VLC Media Player 0.8.6d - httpd_FileCallBack Remote Format String, [seebug] VLC 0.8.6d httpd_FileCallBack Remote Format String Exploit, [seebug] VLC 0.8.6d - httpd_FileCallBack Remote Format String Exploit, [exploitdb] VideoLAN VLC Media Player 0.8.6d - 'httpd_FileCallBack' Remote Format String) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-6682 was patched at 2024-05-15
650.
Remote Code Execution - Unknown Product (CVE-2008-0314) - High [476]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in spin.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted PeSpin packed PE binary with a modified length value.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ClamAV libclamav库PeSpin堆溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-0314 was patched at 2024-05-15
651.
Remote Code Execution - Unknown Product (CVE-2008-0486) - High [476]
Description: {'vulners_cve_data_all': 'Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN before r25917, and possibly earlier versions, as used in Xine-lib 1.1.10, might allow remote attackers to execute arbitrary code via a crafted FLAC tag, which triggers a buffer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MPlayer demux_audio.c远程栈溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-0486 was patched at 2024-05-15
652.
Remote Code Execution - Unknown Product (CVE-2008-0674) - High [476]
Description: {'vulners_cve_data_all': 'Buffer overflow in PCRE before 7.6 allows remote attackers to execute arbitrary code via a regular expression containing a character class with a large number of characters with Unicode code points greater than 255.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] PCRE字符类缓冲区溢出漏洞, [seebug] Apple Mac OS X 2009-003修补多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-0674 was patched at 2024-05-15
653.
Remote Code Execution - Unknown Product (CVE-2008-1391) - High [476]
Description: {'vulners_cve_data_all': 'Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] 多个BSD平台'strfmon()'函数整数溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1391 was patched at 2024-05-15
654.
Remote Code Execution - Unknown Product (CVE-2008-1688) - High [476]
Description: {'vulners_cve_data_all': 'Unspecified vulnerability in GNU m4 before 1.4.11 might allow context-dependent attackers to execute arbitrary code, related to improper handling of filenames specified with the -F option. NOTE: it is not clear when this issue crosses privilege boundaries.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] GNU m4格式串及文件名引用漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1688 was patched at 2024-05-15
655.
Remote Code Execution - Unknown Product (CVE-2008-1720) - High [476]
Description: {'vulners_cve_data_all': 'Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Rsync xattr支持整数溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1720 was patched at 2024-05-15
656.
Remote Code Execution - Unknown Product (CVE-2008-2149) - High [476]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the searchwn function in Wordnet 2.0, 2.1, and 3.0 might allow context-dependent attackers to execute arbitrary code via a long command line option. NOTE: this issue probably does not cross privilege boundaries except in cases in which Wordnet is used as a back end.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] WordNet多个栈溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-2149 was patched at 2024-05-15
657.
Remote Code Execution - Unknown Product (CVE-2008-2950) - High [476]
Description: {'vulners_cve_data_all': 'The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not initialized by a Page constructor, which allows remote attackers to execute arbitrary code via a crafted PDF document.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] poppler-poc.txt, [seebug] Poppler PDF渲染库页类远程代码执行漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-2950 was patched at 2024-05-15
658.
Remote Code Execution - Unknown Product (CVE-2008-5187) - High [476]
Description: {'vulners_cve_data_all': 'The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XPM file that triggers a "pointer arithmetic error" and a heap-based buffer overflow, a different vulnerability than CVE-2008-2426.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] imlib2库多个栈溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5187 was patched at 2024-05-15
659.
Remote Code Execution - Unknown Product (CVE-2008-5262) - High [476]
Description: {'vulners_cve_data_all': 'Multiple stack-based buffer overflows in the iGetHdrHeader function in src-IL/src/il_hdr.c in DevIL 1.7.4 allow context-dependent attackers to execute arbitrary code via a crafted Radiance RGBE file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] DevIL RGBE文件解析栈溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5262 was patched at 2024-05-15
660.
Remote Code Execution - Unknown Product (CVE-2009-0364) - High [476]
Description: {'vulners_cve_data_all': 'Format string vulnerability in the mini_calendar component in Citadel.org WebCit 7.22, and other versions before 7.39, allows remote attackers to execute arbitrary code via unspecified vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] WebCit Mini_Calendar组件格式串漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0364 was patched at 2024-05-15
661.
Remote Code Execution - Unknown Product (CVE-2009-1720) - High [476]
Description: {'vulners_cve_data_all': 'Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors. NOTE: some of these details are obtained from third party information.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2009-003修补多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1720 was patched at 2024-05-15
662.
Remote Code Execution - Unknown Product (CVE-2009-2265) - High [476]
Description: {'vulners_cve_data_all': 'Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Adobe ColdFusion 8 Remote Command Execution, [packetstorm] ColdFusion 8.0.1 Arbitrary File Upload And Execute, [zdt] Adobe ColdFusion 8 - Remote Command Execution Exploit, [canvas] Immunity Canvas: FCKEDITOR, [exploitdb] Adobe ColdFusion 8 - Remote Command Execution (RCE), [seebug] FCKeditor connectors模块多个跨站脚本及目录遍历漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2265 was patched at 2024-05-15
663.
Remote Code Execution - Unknown Product (CVE-2009-2294) - High [476]
Description: {'vulners_cve_data_all': 'Integer overflow in the Png_datainfo_callback function in Dillo 2.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PNG image with crafted (1) width or (2) height values.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Dillo Png_datainfo_callback()函数整数溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2294 was patched at 2024-05-15
664.
Remote Code Execution - Unknown Product (CVE-2009-2936) - High [476]
Description: {'vulners_cve_data_all': 'The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 does not require authentication for commands received through a TCP port, which allows remote attackers to (1) execute arbitrary code via a vcl.inline directive that provides a VCL configuration file containing inline C code; (2) change the ownership of the master process via param.set, stop, and start directives; (3) read the initial line of an arbitrary file via a vcl.load directive; or (4) conduct cross-site request forgery (CSRF) attacks that leverage a victim's location on a trusted network and improper input validation of directives. NOTE: the vendor disputes this report, saying that it is "fundamentally misguided and pointless.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Varnish Cache CLI Interface Remote Code Execution, [zdt] Varnish Cache CLI Interface Remote Code Execution Exploit) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2936 was patched at 2024-05-15
665.
Remote Code Execution - Unknown Product (CVE-2009-3296) - High [476]
Description: {'vulners_cve_data_all': 'Multiple integer overflows in tiffread.c in CamlImages 2.2 might allow remote attackers to execute arbitrary code via TIFF images containing large width and height values that trigger heap-based buffer overflows.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] CamlImages JPEG处理远程缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3296 was patched at 2024-05-15
666.
Remote Code Execution - Unknown Product (CVE-2009-3617) - High [476]
Description: {'vulners_cve_data_all': 'Format string vulnerability in the AbstractCommand::onAbort function in src/AbstractCommand.cc in aria2 before 1.6.2, when logging is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a download URI. NOTE: some of these details are obtained from third party information.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] aria2 AbstractCommand::onAbort()函数格式串漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3617 was patched at 2024-05-15
667.
Remote Code Execution - Unknown Product (CVE-2010-2891) - High [476]
Description: {'vulners_cve_data_all': 'Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Identifier (aka OID) represented as a numerical string containing many components separated by . (dot) characters.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] LibSMI smiGetNode - Buffer Overflow When Long OID Is Given In Numerical Form, [exploitdb] LibSMI smiGetNode - Buffer Overflow When Long OID Is Given In Numerical Form) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-2891 was patched at 2024-05-15
668.
Remote Code Execution - Unknown Product (CVE-2011-1087) - High [476]
Description: {'vulners_cve_data_all': 'Buffer overflow in VideoLAN VLC media player 1.0.5 allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .mp3 file that is played during bookmark creation.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zeroscience] VLC media player 1.0.5 Goldeneye (bookmarks) Remote Buffer Overflow PoC) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-1087 was patched at 2024-05-15
669.
Remote Code Execution - Unknown Product (CVE-2012-0270) - High [476]
Description: {'vulners_cve_data_all': 'Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a crafted (1) hetro file to the getnum function in util/heti_main.c or (2) PVOC file to the getnum function in util/pv_import.c.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Csound hetro File Handling Stack Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-0270 was patched at 2024-05-15
670.
Remote Code Execution - Unknown Product (CVE-2012-1162) - High [476]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a zip archive with the number of directories set to 0, related to an "incorrect loop construct."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] libzip 0.1 "_zip_readcdir()" 函数缓冲器溢出漏洞(CVE-2012-1162)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1162 was patched at 2024-05-15
671.
Remote Code Execution - Unknown Product (CVE-2012-1502) - High [476]
Description: {'vulners_cve_data_all': 'Double free vulnerability in the PyPAM_conv in PAMmodule.c in PyPam 0.5.0 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a NULL byte in a password string.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] PyPAM 0.4.2 Double-Free Corruption, [seebug] PyPAM - Python bindings for PAM - Double Free Corruption, [exploitpack] PyPAM Python bindings for PAM - Double-Free Corruption, [exploitdb] PyPAM Python bindings for PAM - Double-Free Corruption) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1502 was patched at 2024-05-15
672.
Remote Code Execution - Unknown Product (CVE-2012-2763) - High [476]
Description: {'vulners_cve_data_all': 'Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] GIMP 2.6 script-fu < 2.8.0 Buffer Overflow Vulnerability, [seebug] GIMP 2.6 script-fu < 2.8.0 - Buffer Overflow Vulnerability, [saint] GIMP Script-Fu Server Buffer Overflow, [saint] GIMP Script-Fu Server Buffer Overflow, [saint] GIMP Script-Fu Server Buffer Overflow, [saint] GIMP Script-Fu Server Buffer Overflow, [packetstorm] GIMP script-fu Server Buffer Overflow, [exploitpack] GIMP 2.6 script-fu 2.8.0 - Buffer Overflow (PoC), [exploitdb] GIMP 2.6 script-fu < 2.8.0 - Buffer Overflow (PoC)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-2763 was patched at 2024-05-15
673.
Remote Code Execution - Unknown Product (CVE-2014-1909) - High [476]
Description: {'vulners_cve_data_all': 'Integer signedness error in system/core/adb/adb_client.c in Android Debug Bridge (ADB) for Android 4.4 in the Android SDK Platform Tools 18.0.1 allows ADB servers to execute arbitrary code via a negative length value, which bypasses a signed comparison and triggers a stack-based buffer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Android SDK平台工具符号错误栈缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-1909 was patched at 2024-05-15
674.
Remote Code Execution - Unknown Product (CVE-2014-2240) - High [476]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the cf2_hintmap_build function in cff/cf2hints.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of stem hints in a font file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FreeType 'src/cff/cf2hints.c'远程栈缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-2240 was patched at 2024-05-15
675.
Remote Code Execution - Unknown Product (CVE-2014-6395) - High [476]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in the dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted password length value that is inconsistent with the actual length of the password.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Ettercap 0.8.0 / 0.8.1 Denial Of Service Exploit, [exploitpack] Ettercap 0.8.0 0.8.1 - Multiple Denial of Service Vulnerabilities, [packetstorm] Ettercap 0.8.0 / 0.8.1 Denial Of Service, [exploitdb] Ettercap 0.8.0 < 0.8.1 - Multiple Denial of Service Vulnerabilities) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-6395 was patched at 2024-05-15
676.
Remote Code Execution - Unknown Product (CVE-2014-9376) - High [476]
Description: {'vulners_cve_data_all': 'Integer underflow in Ettercap 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds write) and possibly execute arbitrary code via a small (1) size variable value in the dissector_dhcp function in dissectors/ec_dhcp.c, (2) length value to the dissector_gg function in dissectors/ec_gg.c, or (3) string length to the get_decode_len function in ec_utils.c or a request without a (4) username or (5) password to the dissector_TN3270 function in dissectors/ec_TN3270.c.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Ettercap 0.8.0 / 0.8.1 Denial Of Service, [exploitpack] Ettercap 0.8.0 0.8.1 - Multiple Denial of Service Vulnerabilities, [exploitdb] Ettercap 0.8.0 < 0.8.1 - Multiple Denial of Service Vulnerabilities) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-9376 was patched at 2024-05-15
677.
Remote Code Execution - Unknown Product (CVE-2014-9378) - High [476]
Description: {'vulners_cve_data_all': 'Ettercap 0.8.1 does not validate certain return values, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted (1) name to the parse_line function in mdns_spoof/mdns_spoof.c or (2) base64 encoded password to the dissector_imap function in dissectors/ec_imap.c.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Ettercap 0.8.0 / 0.8.1 Denial Of Service, [exploitpack] Ettercap 0.8.0 0.8.1 - Multiple Denial of Service Vulnerabilities, [exploitdb] Ettercap 0.8.0 < 0.8.1 - Multiple Denial of Service Vulnerabilities) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-9378 was patched at 2024-05-15
678.
Remote Code Execution - Unknown Product (CVE-2014-9379) - High [476]
Description: {'vulners_cve_data_all': 'The radius_get_attribute function in dissectors/ec_radius.c in Ettercap 0.8.1 performs an incorrect cast, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which triggers a stack-based buffer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Ettercap 0.8.0 / 0.8.1 Denial Of Service, [exploitpack] Ettercap 0.8.0 0.8.1 - Multiple Denial of Service Vulnerabilities, [exploitdb] Ettercap 0.8.0 < 0.8.1 - Multiple Denial of Service Vulnerabilities) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-9379 was patched at 2024-05-15
679.
Remote Code Execution - Unknown Product (CVE-2015-0973) - High [476]
Description: {'vulners_cve_data_all': 'Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] libpng 1.6.15 Heap Overflow Exploit) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-0973 was patched at 2024-05-15
680.
Remote Code Execution - Unknown Product (CVE-2016-2334) - High [476]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] 7zip CVE-2016-2334 HFS+ Code Execution Vulnerability, [seebug] 7zip HFS+ NArchive::NHfs::CHandler::ExtractZlibFile Code Execution Vulnerability(CVE-2016-2334)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-2334 was patched at 2024-05-15
681.
Remote Code Execution - Unknown Product (CVE-2016-3861) - High [476]
Description: {'vulners_cve_data_all': 'LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles conversions between Unicode character encodings with different encoding widths, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted file, aka internal bug 29250543.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Android - libutils UTF16 to UTF8 Conversion Heap Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-3861 was patched at 2024-05-15
682.
Remote Code Execution - Unknown Product (CVE-2017-1085) - High [476]
Description: {'vulners_cve_data_all': 'In FreeBSD before 11.2-RELEASE, an application which calls setrlimit() to increase RLIMIT_STACK may turn a read-only memory region below the stack into a read-write region. A specially crafted executable could be exploited to execute arbitrary code in the user context.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] FreeBSD - setrlimit Stack Clash (PoC), [zdt] FreeBSD - setrlimit Stack Clash (PoC) Exploit, [exploitdb] FreeBSD - 'setrlimit' Stack Clash (PoC)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-1085 was patched at 2024-05-15
683.
Remote Code Execution - Unknown Product (CVE-2017-13216) - High [476]
Description: {'vulners_cve_data_all': 'In ashmem_ioctl of ashmem.c, there is an out-of-bounds write due to insufficient locking when accessing asma. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-66954097.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Android - Inter-Process munmap due to Race Condition in ashmem Exploit) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-13216 was patched at 2024-05-15
684.
Remote Code Execution - Unknown Product (CVE-2017-2807) - High [476]
Description: {'vulners_cve_data_all': 'An exploitable buffer overflow vulnerability exists in the tag parsing functionality of Ledger-CLI 3.1.1. A specially crafted journal file can cause an integer underflow resulting in code execution. An attacker can construct a malicious journal file to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Ledger CLI Tags Parsing Code Execution Vulnerability(CVE-2017-2807)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2807 was patched at 2024-05-15
685.
Remote Code Execution - Unknown Product (CVE-2017-2808) - High [476]
Description: {'vulners_cve_data_all': 'An exploitable use-after-free vulnerability exists in the account parsing component of the Ledger-CLI 3.1.1. A specially crafted ledger file can cause a use-after-free vulnerability resulting in arbitrary code execution. An attacker can convince a user to load a journal file to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Ledger CLI Account Directive Use-After-Free Vulnerability(CVE-2017-2808)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2808 was patched at 2024-05-15
686.
Remote Code Execution - Unknown Product (CVE-2017-9806) - High [476]
Description: {'vulners_cve_data_all': 'A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apache OpenOffice DOC WW8Fonts Constructor Code Execution Vulnerability(CVE-2017-9806)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-9806 was patched at 2024-05-15
687.
Remote Code Execution - Unknown Product (CVE-2020-18897) - High [476]
Description: {'vulners_cve_data_all': 'An use-after-free vulnerability in the libpff_item_tree_create_node function of libyal Libpff before 20180623 allows attackers to cause a denial of service (DOS) or execute arbitrary code via a crafted pff file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-18897 was patched at 2024-05-15
688.
Remote Code Execution - Unknown Product (CVE-2020-28600) - High [476]
Description: {'vulners_cve_data_all': 'An out-of-bounds write vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2. A specially crafted STL file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-28600 was patched at 2024-05-15
689.
Remote Code Execution - Unknown Product (CVE-2020-6105) - High [476]
Description: {'vulners_cve_data_all': 'An exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause Information overwrite resulting in a code execution. An attacker can provide a malicious file to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-6105 was patched at 2024-05-15
690.
Remote Code Execution - Unknown Product (CVE-2021-30500) - High [476]
Description: {'vulners_cve_data_all': 'Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0. That allow attackers to execute arbitrary code and cause a denial of service via a crafted file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30500 was patched at 2024-05-15
691.
Remote Code Execution - Unknown Product (CVE-2021-32751) - High [476]
Description: {'vulners_cve_data_all': 'Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `application` plugin and the `gradlew` script are both vulnerable to arbitrary code execution when an attacker is able to change environment variables for the user running the script. This may impact those who use `gradlew` on Unix-like systems or use the scripts generated by Gradle in thieir application on Unix-like systems. For this vulnerability to be exploitable, an attacker needs to be able to set the value of particular environment variables and have those environment variables be seen by the vulnerable scripts. This issue has been patched in Gradle 7.2 by removing the use of `eval` and requiring the use of the `bash` shell. There are a few workarounds available. For CI/CD systems using the Gradle build tool, one may ensure that untrusted users are unable to change environment variables for the user that executes `gradlew`. If one is unable to upgrade to Gradle 7.2, one may generate a new `gradlew` script with Gradle 7.2 and use it for older versions of Gradle. Fpplications using start scripts generated by Gradle, one may ensure that untrusted users are unable to change environment variables for the user that executes the start script. A vulnerable start script could be manually patched to remove the use of `eval` or the use of environment variables that affect the application's command-line. If the application is simple enough, one may be able to avoid the use of the start scripts by running the application directly with Java command.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32751 was patched at 2024-05-15
692.
Remote Code Execution - Unknown Product (CVE-2021-35196) - High [476]
Description: {'vulners_cve_data_all': 'Manuskript through 0.12.0 allows remote attackers to execute arbitrary code via a crafted settings.pickle file in a project file, because there is insecure deserialization via the pickle.load() function in settings.py. NOTE: the vendor's position is that the product is not intended for opening an untrusted project file', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-35196 was patched at 2024-05-15
693.
Remote Code Execution - Unknown Product (CVE-2021-35331) - High [476]
Description: {'vulners_cve_data_all': 'In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-35331 was patched at 2024-05-15
694.
Denial of Service - Perl (CVE-2009-1884) - High [475]
Description: Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Perl Compress::Raw::Bzip2模块单字节溢出漏洞, [seebug] 'Compress::Raw::Zlib' Perl模块远程代码执行漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1884 was patched at 2024-05-15
695.
Denial of Service - Perl (CVE-2010-0420) - High [475]
Description: libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Pidgin多个拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-0420 was patched at 2024-05-15
696.
Denial of Service - Perl (CVE-2011-0421) - High [475]
Description: The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-0421 was patched at 2024-05-15
697.
Denial of Service - Perl (CVE-2011-2728) - High [475]
Description: The bsd_glob function in the File::Glob module for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Perl "decode_xs()"和"File::Glob::bsd_glob()"远程代码执行漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-2728 was patched at 2024-05-15
698.
Denial of Service - Perl (CVE-2011-2943) - High [475]
Description: The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Pidgin拒绝服务和安全绕过漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-2943 was patched at 2024-05-15
699.
Denial of Service - Python (CVE-2013-7040) - High [475]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Python哈希冲突拒绝服务漏洞(CVE-2012-1150)) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-7040 was patched at 2024-05-15
700.
Denial of Service - Wireshark (CVE-2014-2282) - High [475]
Description: The dissect_protocol_data_parameter function in epan/dissectors/packet-m3ua.c in the M3UA dissector in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Wireshark M3UA Dissector拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-2282 was patched at 2024-05-15
701.
Information Disclosure - Perl (CVE-2013-4183) - High [474]
Description: The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenStack Cinder 信息泄漏漏洞(CVE-2013-4183)) | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.2 | 10 | CVSS Base Score is 2.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-4183 was patched at 2024-05-15
702.
Information Disclosure - Python (CVE-2013-2013) - High [474]
Description: The user-password-update command in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenStack Keystone 密码信息泄露漏洞(CVE-2013-2013)) | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.2 | 10 | CVSS Base Score is 2.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-2013 was patched at 2024-05-15
703.
Authentication Bypass - Unknown Product (CVE-2006-2369) - High [472]
Description: {'vulners_cve_data_all': 'RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] RealVNC Authentication Bypass, [seebug] RealVNC 4.1 Authentication Bypass, [exploitpack] RealVNC 4.1.04.1.1 - Authentication Bypass, [packetstorm] RealVNC Authentication Bypass, [canvas] Immunity Canvas: REALVNC_NOAUTH, [exploitdb] RealVNC - Authentication Bypass (Metasploit), [exploitdb] RealVNC 4.1.0/4.1.1 - Authentication Bypass) | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-2369 was patched at 2024-05-15
704.
Authentication Bypass - Unknown Product (CVE-2006-2450) - High [472]
Description: {'vulners_cve_data_all': 'auth.c in LibVNCServer 0.7.1 allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, a different issue than CVE-2006-2369.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] RealVNC Authentication Bypass, [seebug] RealVNC 4.1 Authentication Bypass, [exploitpack] RealVNC 4.1.04.1.1 - Authentication Bypass, [canvas] Immunity Canvas: REALVNC_NOAUTH, [packetstorm] RealVNC Authentication Bypass, [exploitdb] RealVNC - Authentication Bypass (Metasploit), [exploitdb] RealVNC 4.1.0/4.1.1 - Authentication Bypass) | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-2450 was patched at 2024-05-15
705.
Authentication Bypass - Unknown Product (CVE-2021-45098) - High [472]
Description: {'vulners_cve_data_all': 'An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with random TCP options of the md5header from the client side. After the three-way handshake, it's possible to inject an RST ACK with a random TCP md5header option. Then, the client can send an HTTP GET request with a forbidden URL. The server will ignore the RST ACK and send the response HTTP packet for the client's request. These packets will not trigger a Suricata reject action.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-45098 was patched at 2024-05-15
706.
Denial of Service - Linux Kernel (CVE-2019-16413) - High [471]
Description: An issue was discovered in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-16413 was patched at 2024-05-15
707.
Command Injection - Unknown Product (CVE-2018-1335) - High [470]
Description: {'vulners_cve_data_all': 'From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Apache Tika 1.15 - 1.17 - Header Command Injection Exploit, [zdt] Apache Tika-server < 1.18 - Command Injection Exploit, [exploitpack] Apache Tika-server 1.18 - Command Injection, [packetstorm] Apache Tika 1.17 Header Command Injection, [packetstorm] Apache Tika Server Command Injection, [metasploit] Apache Tika Header Command Injection, [exploitdb] Apache Tika 1.15 - 1.17 - Header Command Injection (Metasploit), [exploitdb] Apache Tika-server < 1.18 - Command Injection) | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-1335 was patched at 2024-05-15
708.
Command Injection - Unknown Product (CVE-2018-16744) - High [470]
Description: {'vulners_cve_data_all': 'An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized. It could allow for command injection if untrusted input can reach it, because popen is used.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] mgetty 1.2.0 Buffer Overflow / Privilege Escalation Vulnerabilities) | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-16744 was patched at 2024-05-15
709.
Command Injection - Unknown Product (CVE-2019-0227) - High [470]
Description: {'vulners_cve_data_all': 'A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-0227 was patched at 2024-05-15
710.
Command Injection - Unknown Product (CVE-2022-23935) - High [470]
Description: {'vulners_cve_data_all': 'lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\\|$/ check, leading to command injection.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for OS Command Injection in Exiftool Project Exiftool, [githubexploit] Exploit for OS Command Injection in Exiftool Project Exiftool) | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-23935 was patched at 2024-05-15
711.
Command Injection - Unknown Product (CVE-2022-45059) - High [470]
Description: {'vulners_cve_data_all': 'An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing the Varnish Cache servers from forwarding critical headers to the backend.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for HTTP Request Smuggling in Varnish Cache Project Varnish Cache, [githubexploit] Exploit for HTTP Request Smuggling in Varnish Cache Project Varnish Cache) | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-45059 was patched at 2024-05-15
712.
Command Injection - Unknown Product (CVE-2024-22243) - High [470]
Description: {'vulners_cve_data_all': 'Applications that use UriComponentsBuilder\xa0to parse an externally provided URL (e.g. through a query parameter) AND\xa0perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html \xa0attack or to a SSRF attack if the URL is used after passing validation checks.\n', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for CVE-2024-22243) | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-22243 was patched at 2024-05-15
713.
Command Injection - Unknown Product (CVE-2024-22259) - High [470]
Description: {'vulners_cve_data_all': 'Applications that use UriComponentsBuilder in Spring Framework\xa0to parse an externally provided URL (e.g. through a query parameter) AND\xa0perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html \xa0attack or to a SSRF attack if the URL is used after passing validation checks.\n\nThis is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.\n\n', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for CVE-2024-22243) | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-22259 was patched at 2024-05-15
714.
Command Injection - Unknown Product (CVE-2024-22262) - High [470]
Description: {'vulners_cve_data_all': 'Applications that use UriComponentsBuilder\xa0to parse an externally provided URL (e.g. through a query parameter) AND\xa0perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html \xa0attack or to a SSRF attack if the URL is used after passing validation checks.\n\nThis is the same as CVE-2024-22259 https://spring.io/security/cve-2024-22259 \xa0and CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.\n\n', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for CVE-2024-22243) | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-22262 was patched at 2024-05-15
715.
Denial of Service - nginx (CVE-2009-3896) - High [470]
Description: src/http/ngx_http_parse.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] nginx ngx_http_process_request_headers()函数空指针引用拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3896 was patched at 2024-05-15
716.
Memory Corruption - TLS (CVE-2022-39173) - High [470]
Description: In wolfSSL before 5.5.1, malicious clients can cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] wolfSSL Buffer Overflow) | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | TLS | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-39173 was patched at 2024-05-15
717.
Security Feature Bypass - Unknown Product (CVE-2017-5123) - High [470]
Description: {'vulners_cve_data_all': 'Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-5123 was patched at 2024-05-15
718.
Security Feature Bypass - Unknown Product (CVE-2019-5597) - High [470]
Description: {'vulners_cve_data_all': 'In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before 12.0-RELEASE-p4, a bug in the pf IPv6 fragment reassembly logic incorrectly uses the last extension header offset from the last received packet instead of the first packet allowing maliciously crafted IPv6 packets to cause a crash or potentially bypass the packet filter.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-5597 was patched at 2024-05-15
719.
Security Feature Bypass - Unknown Product (CVE-2021-41945) - High [470]
Description: {'vulners_cve_data_all': 'Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-41945 was patched at 2024-05-15
720.
Security Feature Bypass - Unknown Product (CVE-2023-50386) - High [470]
Description: {'vulners_cve_data_all': 'Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1.\n\nIn the affected versions, Solr ConfigSets accepted Java jar and class files to be uploaded through the ConfigSets API.\nWhen backing up Solr Collections, these configSet files would be saved to disk when using the LocalFileSystemRepository (the default for backups).\nIf the backup was saved to a directory that Solr uses in its ClassPath/ClassLoaders, then the jar and class files would be available to use with any ConfigSet, trusted or untrusted.\n\nWhen Solr is run in a secure way (Authorization enabled), as is strongly suggested, this vulnerability is limited to extending the Backup permissions with the ability to add libraries.\nUsers are recommended to upgrade to version 8.11.3 or 9.4.1, which fix the issue.\nIn these versions, the following protections have been added:\n\n * Users are no longer able to upload files to a configSet that could be executed via a Java ClassLoader.\n * The Backup API restricts saving backups to directories that are used in the ClassLoader.\n\n', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Apache Solr Backup/Restore API Remote Code Execution Exploit, [packetstorm] Apache Solr Backup/Restore API Remote Code Execution, [githubexploit] Exploit for Improper Control of Dynamically-Managed Code Resources in Apache Solr, [metasploit] Apache Solr Backup/Restore APIs RCE) | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-50386 was patched at 2024-05-15
721.
XXE Injection - Unknown Product (CVE-2013-1915) - High [470]
Description: {'vulners_cve_data_all': 'ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ModSecurity XML外部实体信息泄露漏洞(CVE-2013-1915)) | |
| 0.97 | 15 | XXE Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-1915 was patched at 2024-05-15
722.
Arbitrary File Reading - Unknown Product (CVE-2010-2445) - High [469]
Description: {'vulners_cve_data_all': 'freeciv 2.2 before 2.2.1 and 2.3 before 2.3.0 allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua functionality, related to the (1) os, (2) io, (3) package, (4) dofile, (5) loadfile, (6) loadlib, (7) module, and (8) require modules or functions.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Android 2.0 FreeCIV Arbitrary Code Execution) | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-2445 was patched at 2024-05-15
723.
Denial of Service - GPAC (CVE-2020-19481) - High [465]
Description: An issue was discovered in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-19481 was patched at 2024-05-15
724.
Denial of Service - GPAC (CVE-2020-22352) - High [465]
Description: The gf_dash_segmenter_probe_input function in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-22352 was patched at 2024-05-15
725.
Denial of Service - GPAC (CVE-2020-23266) - High [465]
Description: An issue was discovered in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23266 was patched at 2024-05-15
726.
Denial of Service - GPAC (CVE-2020-23269) - High [465]
Description: An issue was discovered in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23269 was patched at 2024-05-15
727.
Denial of Service - GPAC (CVE-2020-24829) - High [465]
Description: An issue was discovered in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-24829 was patched at 2024-05-15
728.
Denial of Service - GPAC (CVE-2021-32132) - High [465]
Description: The abst_box_size function in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32132 was patched at 2024-05-15
729.
Denial of Service - GPAC (CVE-2021-32134) - High [465]
Description: The gf_odf_desc_copy function in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32134 was patched at 2024-05-15
730.
Denial of Service - GPAC (CVE-2021-32135) - High [465]
Description: The trak_box_size function in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32135 was patched at 2024-05-15
731.
Denial of Service - GPAC (CVE-2021-32138) - High [465]
Description: The DumpTrackInfo function in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32138 was patched at 2024-05-15
732.
Denial of Service - GPAC (CVE-2021-32139) - High [465]
Description: The gf_isom_vp_config_get function in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32139 was patched at 2024-05-15
733.
Denial of Service - GPAC (CVE-2021-32269) - High [465]
Description: An issue was discovered in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32269 was patched at 2024-05-15
734.
Denial of Service - GPAC (CVE-2021-32270) - High [465]
Description: An issue was discovered in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32270 was patched at 2024-05-15
735.
Denial of Service - GPAC (CVE-2021-32437) - High [465]
Description: The gf_hinter_finalize function in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32437 was patched at 2024-05-15
736.
Denial of Service - GPAC (CVE-2021-32438) - High [465]
Description: The gf_media_export_filters function in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32438 was patched at 2024-05-15
737.
Denial of Service - GPAC (CVE-2021-32440) - High [465]
Description: The Media_RewriteODFrame function in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32440 was patched at 2024-05-15
738.
Memory Corruption - GPAC (CVE-2020-19751) - High [465]
Description: {'vulners_cve_data_all': 'An issue was discovered in gpac 0.8.0. The gf_odf_del_ipmp_tool function in odf_code.c has a heap-based buffer over-read.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-19751 was patched at 2024-05-15
739.
Cross Site Scripting - Unknown Product (CVE-2012-2399) - High [464]
Description: {'vulners_cve_data_all': 'Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the buttonText parameter, a different vulnerability than CVE-2012-3414.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] WordPress E-Commerce 3.8.9.5 File Upload / XSS / CSRF / Code Execution, [packetstorm] WordPress 3.3.1 swfupload.swf Cross Site Scripting, [packetstorm] SWF Upload Cross Site Scripting, [packetstorm] Dotclear 2.4.4 Cross Site Scripting / Content Spoofing, [zdt] Wordpress Plugin (wp-e-commerce v3.8.9.5) Multiple Vulnerabilities, [zdt] Dotclear XSS Vulnerabilities, [seebug] Turbomail邮件系统XSS-1) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-2399 was patched at 2024-05-15
740.
Remote Code Execution - Kerberos (CVE-2002-1235) - High [464]
Description: The kadm_ser_in function in (1) the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-1235 was patched at 2024-05-15
741.
Remote Code Execution - Kerberos (CVE-2004-0434) - High [464]
Description: k5admind (kadmind) for Heimdal allows remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0434 was patched at 2024-05-15
742.
Remote Code Execution - Kerberos (CVE-2004-0523) - High [464]
Description: Multiple buffer overflows in krb5_aname_to_localname for MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0523 was patched at 2024-05-15
743.
Remote Code Execution - Kerberos (CVE-2004-0772) - High [464]
Description: Double free vulnerabilities in error handling code in krb524d for MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0772 was patched at 2024-05-15
744.
Remote Code Execution - Kerberos (CVE-2005-1689) - High [464]
Description: Double free vulnerability in the krb5_recvauth function in MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-1689 was patched at 2024-05-15
745.
Remote Code Execution - Kerberos (CVE-2017-15088) - High [464]
Description: plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-15088 was patched at 2024-05-15
746.
Remote Code Execution - Unknown Product (CVE-2006-0745) - High [464]
Description: {'vulners_cve_data_all': 'X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] xorg-x11-server modulepath Local Privilege Escalation, [exploitpack] xorg-x11-server 1.20.3 - modulepath Local Privilege Escalation, [exploitdb] xorg-x11-server < 1.20.3 - 'modulepath' Local Privilege Escalation) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-0745 was patched at 2024-05-15
747.
Remote Code Execution - Unknown Product (CVE-2007-0017) - High [464]
Description: {'vulners_cve_data_all': 'Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] VLCMediaSlayer-x86.pl.txt, [packetstorm] VLCMediaSlayer-ppc.pl.txt) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-0017 was patched at 2024-05-15
748.
Remote Code Execution - Unknown Product (CVE-2007-0104) - High [464]
Description: {'vulners_cve_data_all': 'The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Microsoft Publisher文件解析多个内存破坏漏洞(MS08-012)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-0104 was patched at 2024-05-15
749.
Remote Code Execution - Unknown Product (CVE-2007-2807) - High [464]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute arbitrary code via a long private message.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Eggdrop/Windrop 1.6.19 Denial Of Service, [seebug] Eggdrop/Windrop 1.6.19 ctcpbuf Remote Crash Vulnerability, [exploitpack] EggdropWindrop 1.6.19 - ctcpbuf Remote Crash, [exploitdb] Eggdrop/Windrop 1.6.19 - ctcpbuf Remote Crash) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-2807 was patched at 2024-05-15
750.
Remote Code Execution - Unknown Product (CVE-2007-2958) - High [464]
Description: {'vulners_cve_data_all': 'Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Sylpheed和Sylpheed-Claws POP3远程格式串处理漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-2958 was patched at 2024-05-15
751.
Remote Code Execution - Unknown Product (CVE-2007-4727) - High [464]
Description: {'vulners_cve_data_all': 'Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows remote attackers to overwrite arbitrary CGI variables and execute arbitrary code via an HTTP request with a long content length, as demonstrated by overwriting the SCRIPT_FILENAME variable, aka a "header overflow."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([d2] DSquare Exploit Pack: D2SEC_LIGHTTPD3) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-4727 was patched at 2024-05-15
752.
Remote Code Execution - Unknown Product (CVE-2007-5301) - High [464]
Description: {'vulners_cve_data_all': 'Buffer overflow in the vorbis_stream_info function in input/vorbis/vorbis_engine.c (aka the vorbis input plugin) in AlsaPlayer before 0.99.80-rc3 allows remote attackers to execute arbitrary code via a .OGG file with long comments.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Alsaplayer < 0.99.80-rc3 Vorbis Input Local Buffer Overflow Exploit, [seebug] Alsaplayer < 0.99.80-rc3 - Vorbis Input Local Buffer Overflow Exploit, [exploitpack] AlsaPlayer 0.99.80-rc3 - Vorbis Input Local Buffer Overflow, [packetstorm] alsaplayer-overflow.txt, [exploitdb] AlsaPlayer < 0.99.80-rc3 - Vorbis Input Local Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-5301 was patched at 2024-05-15
753.
Remote Code Execution - Unknown Product (CVE-2007-5848) - High [464]
Description: {'vulners_cve_data_all': 'Buffer overflow in CUPS in Apple Mac OS X 10.4.11 allows local admin users to execute arbitrary code via a crafted URI to the CUPS service.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X v10.5.1 2007-009 Multiple Security Vulnerabilities) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-5848 was patched at 2024-05-15
754.
Remote Code Execution - Unknown Product (CVE-2008-0073) - High [464]
Description: {'vulners_cve_data_all': 'Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] mplayer-overflowpoc.txt, [exploitpack] MPlayer 1.0 rc2 - sdpplin_parse() Array Indexing Buffer Overflow (PoC), [seebug] MPlayer sdpplin_parse() Array Indexing Buffer Overflow Exploit PoC, [seebug] xine-lib sdpplin_parse()函数远程溢出漏洞, [exploitdb] MPlayer 1.0 rc2 - 'sdpplin_parse()' Array Indexing Buffer Overflow (PoC)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-0073 was patched at 2024-05-15
755.
Remote Code Execution - Unknown Product (CVE-2008-1102) - High [464]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote attackers to execute arbitrary code via a .blend file that contains a crafted Radiance RGBE image.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Blender radiance_hdr.c文件远程栈溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1102 was patched at 2024-05-15
756.
Remote Code Execution - Unknown Product (CVE-2008-1489) - High [464]
Description: {'vulners_cve_data_all': 'Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MP4 RDRF box that triggers a heap-based buffer overflow, a different vulnerability than CVE-2008-0984.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] VLC媒体播放器MP4_ReadBox_rdrf()函数堆溢出漏洞, [seebug] VideoLAN VLC媒体播放器MP4 Demuxer远程代码执行漏洞, [packetstorm] Core Security Technologies Advisory 2008.0130) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1489 was patched at 2024-05-15
757.
Remote Code Execution - Unknown Product (CVE-2008-1881) - High [464]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to execute arbitrary code via a long subtitle in an SSA file. NOTE: this issue is due to an incomplete fix for CVE-2007-6681.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1881 was patched at 2024-05-15
758.
Remote Code Execution - Unknown Product (CVE-2008-2310) - High [464]
Description: {'vulners_cve_data_all': 'Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2008-004更新修复多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-2310 was patched at 2024-05-15
759.
Remote Code Execution - Unknown Product (CVE-2008-3794) - High [464]
Description: {'vulners_cve_data_all': 'Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execute arbitrary code via a crafted mmst link with a negative size value, which bypasses a size check and triggers an integer overflow followed by a heap-based buffer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3794 was patched at 2024-05-15
760.
Remote Code Execution - Unknown Product (CVE-2008-5824) - High [464]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in msadpcm.c in libaudiofile in audiofile 0.2.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WAV file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5824 was patched at 2024-05-15
761.
Remote Code Execution - Unknown Product (CVE-2009-1373) - High [464]
Description: {'vulners_cve_data_all': 'Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer. NOTE: some of these details are obtained from third party information.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Pidgin多个缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1373 was patched at 2024-05-15
762.
Remote Code Execution - Unknown Product (CVE-2009-1721) - High [464]
Description: {'vulners_cve_data_all': 'The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2009-003修补多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1721 was patched at 2024-05-15
763.
Remote Code Execution - Unknown Product (CVE-2009-1722) - High [464]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2009-003修补多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1722 was patched at 2024-05-15
764.
Remote Code Execution - Unknown Product (CVE-2009-2624) - High [464]
Description: {'vulners_cve_data_all': 'The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2006-007存在多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2624 was patched at 2024-05-15
765.
Remote Code Execution - Unknown Product (CVE-2009-2830) - High [464]
Description: {'vulners_cve_data_all': 'Multiple buffer overflows in Christos Zoulas file before 5.03 in Apple Mac OS X 10.6.x before 10.6.2 allow user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Common Document Format (CDF) file. NOTE: this might overlap CVE-2009-1515.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2009-006更新修复多个安全漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2830 was patched at 2024-05-15
766.
Remote Code Execution - Unknown Product (CVE-2009-3605) - High [464]
Description: {'vulners_cve_data_all': 'Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, related to (1) glib/poppler-page.cc; (2) ArthurOutputDev.cc, (3) CairoOutputDev.cc, (4) GfxState.cc, (5) JBIG2Stream.cc, (6) PSOutputDev.cc, and (7) SplashOutputDev.cc in poppler/; and (8) SplashBitmap.cc, (9) Splash.cc, and (10) SplashFTFont.cc in splash/. NOTE: this may overlap CVE-2009-0791.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] CUPS pdftops过滤器多个整数溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3605 was patched at 2024-05-15
767.
Remote Code Execution - Unknown Product (CVE-2011-0522) - High [464]
Description: {'vulners_cve_data_all': 'The StripTags function in (1) the USF decoder (modules/codec/subtitles/subsdec.c) and (2) the Text decoder (modules/codec/subtitles/subsusf.c) in VideoLAN VLC Media Player 1.1 before 1.1.6-rc allows remote attackers to execute arbitrary code via a subtitle with an opening "<" without a closing ">" in an MKV file, which triggers heap memory corruption, as demonstrated using refined-australia-blu720p-sample.mkv.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] VLC Media Player Memory Corruption) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-0522 was patched at 2024-05-15
768.
Remote Code Execution - Unknown Product (CVE-2011-1574) - High [464]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the ReadS3M method in load_s3m.cpp in libmodplug before 0.8.8.2 allows remote attackers to execute arbitrary code via a crafted S3M file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([saint] VLC Media Player Libmodplug CSoundFile::ReadS3M() Function S3M File Handling Overflow, [saint] VLC Media Player Libmodplug CSoundFile::ReadS3M() Function S3M File Handling Overflow, [saint] VLC Media Player Libmodplug CSoundFile::ReadS3M() Function S3M File Handling Overflow, [saint] VLC Media Player Libmodplug CSoundFile::ReadS3M() Function S3M File Handling Overflow, [packetstorm] VideoLAN VLC ModPlug ReadS3M Stack Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-1574 was patched at 2024-05-15
769.
Remote Code Execution - Unknown Product (CVE-2011-2587) - High [464]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in the DemuxAudioSipr function in real.c in the RealMedia demuxer in VideoLAN VLC media player 1.1.x before 1.1.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Real Media file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] VLC Media Player ".RM"和".AVI"文件多个远程堆缓冲区溢出漏洞(CVE-2011-2587)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-2587 was patched at 2024-05-15
770.
Remote Code Execution - Unknown Product (CVE-2012-3377) - High [464]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in the Ogg_DecodePacket function in the OGG demuxer (modules/demux/ogg.c) in VideoLAN VLC media player before 2.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted OGG file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] VLC Media Player 'OGG'文件远程堆缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-3377 was patched at 2024-05-15
771.
Remote Code Execution - Unknown Product (CVE-2013-1428) - High [464]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated peers to cause a denial of service (crash) or possibly execute arbitrary code via a large TCP packet.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Tincd Post-Authentication Remote TCP Stack Buffer Overflow Exploit, [packetstorm] Tincd Post-Authentication Remote TCP Stack Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-1428 was patched at 2024-05-15
772.
Remote Code Execution - Unknown Product (CVE-2013-3245) - High [464]
Description: {'vulners_cve_data_all': 'plugins/demux/libmkv_plugin.dll in VideoLAN VLC Media Player 2.0.7, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MKV file, possibly involving an integer overflow and out-of-bounds read or heap-based buffer overflow, or an uncaught exception. NOTE: the vendor disputes the severity and claimed vulnerability type of this issue, stating "This PoC crashes VLC, indeed, but does nothing more... this is not an integer overflow error, but an uncaught exception and I doubt that it is exploitable. This uncaught exception makes VLC abort, not execute random code, on my Linux 64bits machine." A PoC posted by the original researcher shows signs of an attacker-controlled out-of-bounds read, but the affected instruction does not involve a register that directly influences control flow', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] VLC Media Player远程整数溢出漏洞(CVE-2013-3245)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-3245 was patched at 2024-05-15
773.
Remote Code Execution - Unknown Product (CVE-2018-7567) - High [464]
Description: {'vulners_cve_data_all': 'In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are able to exploit a Blind Remote Code Execution vulnerability by loading a crafted opm file with an embedded CodeInstall element to execute a command on the server during package installation. NOTE: the vendor disputes this issue stating "the behaviour is as designed and needed for different packages to be installed", "there is a security warning if the package is not verified by OTRS Group", and "there is the possibility and responsibility of an admin to check packages before installation which is possible as they are not binary.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] OTRS Authenticated Command Injection Exploit, [packetstorm] OTRS Command Injection) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-7567 was patched at 2024-05-15
774.
Denial of Service - Perl (CVE-2012-2214) - High [463]
Description: proxy.c in libpurple in Pidgin before 2.10.4 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Pidgin <2.10.4 XMPP协议文件传输请求处理远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.3 | 10 | CVSS Base Score is 3.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-2214 was patched at 2024-05-15
775.
Memory Corruption - Wireshark (CVE-2019-5721) - High [463]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-5721 was patched at 2024-05-15
776.
Memory Corruption - tiffcrop (CVE-2023-25435) - High [463]
Description: {'vulners_cve_data_all': 'libtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesShifted8bits() at /libtiff/tools/tiffcrop.c:3753.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | Tiffcrop processes one or more files created according to the Tag Image File Format, Revision 6.0, specification into one or more TIFF file(s) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-25435 was patched at 2024-05-15
777.
Cross Site Scripting - MediaWiki (CVE-2024-34507) - High [461]
Description: An issue was discovered in includes/CommentFormatter/CommentParser.php in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-34507 was patched at 2024-05-15
redos: CVE-2024-34507 was patched at 2024-05-14
778.
Authentication Bypass - Kerberos (CVE-2023-3326) - High [460]
Description: {'vulners_cve_data_all': 'pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) from the Kerberos KDC (Key Distribution Center) over the network, as a way to verify the password. However, if a keytab is not provisioned on the system, pam_krb5 has no way to validate the response from the KDC, and essentially trusts the tgt provided over the network as being valid. In a non-default FreeBSD installation that leverages pam_krb5 for authentication and does not have a keytab provisioned, an attacker that is able to control both the password and the KDC responses can return a valid tgt, allowing authentication to occur for any user on the system.\n', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-3326 was patched at 2024-05-15
779.
Authentication Bypass - Unknown Product (CVE-2008-0169) - High [460]
Description: {'vulners_cve_data_all': 'Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any account for which an OpenID identity is configured and a password is not configured, by specifying an empty password during the login sequence.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ikiwiki空口令绕过认证漏洞) | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-0169 was patched at 2024-05-15
780.
Authentication Bypass - Unknown Product (CVE-2021-31924) - High [460]
Description: {'vulners_cve_data_all': 'Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, could lead to a local PIN bypass. This issue does not allow user presence (touch) or cryptographic signature verification to be bypassed, so an attacker would still need to physically possess and interact with the YubiKey or another enrolled authenticator. If pam-u2f is configured to require PIN authentication, and the application using pam-u2f allows the user to submit NULL as the PIN, pam-u2f will attempt to perform a FIDO2 authentication without PIN. If this authentication is successful, the PIN requirement is bypassed.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-31924 was patched at 2024-05-15
781.
Authentication Bypass - wpa_supplicant (CVE-2023-52160) - High [459]
Description: The implementation of PEAP in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | wpa_supplicant is a free software implementation of an IEEE 802.11i supplicant for Linux, FreeBSD, NetBSD, QNX, AROS, Microsoft Windows, Solaris, OS/2 (including ArcaOS and eComStation) and Haiku | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2023-52160 was patched at 2024-04-30
debian: CVE-2023-52160 was patched at 2024-05-15
oraclelinux: CVE-2023-52160 was patched at 2024-05-02
redhat: CVE-2023-52160 was patched at 2024-04-30
782.
Unknown Vulnerability Type - Windows Encrypting File System (CVE-2017-5473) - High [459]
Description: {'vulners_cve_data_all': 'Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lua, admin/change_user_prefs.lua, admin/delete_user.lua, and admin/password_reset.lua.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] ntopng Web Interface 2.4.160627 Cross Site Request Forgery, [zdt] ntopng Web Interface 2.4.160627 Cross Site Request Forgery Vulnerability, [exploitpack] NTOPNG 2.4 Web Interface - Cross-Site Request Forgery, [exploitdb] NTOPNG 2.4 Web Interface - Cross-Site Request Forgery) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | Encrypting File System (EFS) on Microsoft Windows is a feature introduced in version 3.0 of NTFS that provides filesystem-level encryption | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-5473 was patched at 2024-05-15
783.
Unknown Vulnerability Type - Windows LDAP (CVE-2018-8764) - High [459]
Description: {'vulners_cve_data_all': 'Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] LDAP Account Manager 6.2 Cross Site Scripting) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | Windows LDAP (Lightweight Directory Access Protocol) is an open and cross platform protocol used for directory services authentication | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-8764 was patched at 2024-05-15
784.
Memory Corruption - Kerberos (CVE-2024-26458) - High [458]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2024-26458 was patched at 2024-05-22
debian: CVE-2024-26458 was patched at 2024-05-15
oraclelinux: CVE-2024-26458 was patched at 2024-05-29
redhat: CVE-2024-26458 was patched at 2024-05-22
redos: CVE-2024-26458 was patched at 2024-04-23
785.
Memory Corruption - Kerberos (CVE-2024-26461) - High [458]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2024-26461 was patched at 2024-05-22
debian: CVE-2024-26461 was patched at 2024-05-15
oraclelinux: CVE-2024-26461 was patched at 2024-05-29
redhat: CVE-2024-26461 was patched at 2024-05-22
redos: CVE-2024-26461 was patched at 2024-04-23
786.
Memory Corruption - Kerberos (CVE-2024-26462) - High [458]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-26462 was patched at 2024-05-15
redos: CVE-2024-26462 was patched at 2024-04-23
787.
Security Feature Bypass - Unknown Product (CVE-2012-2663) - High [458]
Description: {'vulners_cve_data_all': 'extensions/libxt_tcp.c in iptables through 1.4.21 does not match TCP SYN+FIN packets in --syn rules, which might allow remote attackers to bypass intended firewall restrictions via crafted packets. NOTE: the CVE-2012-6638 fix makes this issue less relevant.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Linux kernel 2.6.x iptables '--syn'规则安全绕过漏洞, [seebug] Linux Kernel 'tcp_rcv_state_process()'函数拒绝服务漏洞) | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-2663 was patched at 2024-05-15
788.
Security Feature Bypass - Unknown Product (CVE-2019-20149) - High [458]
Description: {'vulners_cve_data_all': 'ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflicting name, as demonstrated by 'constructor': {'name':'Symbol'}. Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Exposure of Resource to Wrong Sphere in Kind-Of Project Kind-Of) | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-20149 was patched at 2024-05-15
789.
Information Disclosure - Unknown Product (CVE-2019-15058) - High [457]
Description: {'vulners_cve_data_all': 'stb_image.h (aka the stb image loader) 2.23 has a heap-based buffer over-read in stbi__tga_load, leading to Information Disclosure or Denial of Service.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-15058 was patched at 2024-05-15
790.
Information Disclosure - Unknown Product (CVE-2021-3402) - High [457]
Description: {'vulners_cve_data_all': 'An integer overflow and several buffer overflow reads in libyara/modules/macho/macho.c in YARA v4.0.3 and earlier could allow an attacker to either cause denial of service or information disclosure via a malicious Mach-O file. Affects all versions before libyara 4.0.4', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-3402 was patched at 2024-05-15
791.
Arbitrary File Writing - Unknown Product (CVE-2008-5377) - High [455]
Description: {'vulners_cve_data_all': 'pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] CUPS Privilege Escalation Exploit, [seebug] CUPS < 1.3.8-4 - (pstopdf filter) Privilege Escalation Exploit, [seebug] CUPS < 1.3.8-4 (pstopdf filter) Privilege Escalation Exploit, [exploitpack] CUPS 1.3.8-4 - Local Privilege Escalation, [exploitdb] CUPS < 1.3.8-4 - Local Privilege Escalation) | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5377 was patched at 2024-05-15
792.
Arbitrary File Writing - Unknown Product (CVE-2008-5394) - High [455]
Description: {'vulners_cve_data_all': '/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field in a utmp entry.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Debian Linux /bin/login软件包本地权限提升漏洞) | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5394 was patched at 2024-05-15
793.
Arbitrary File Writing - Unknown Product (CVE-2009-2939) - High [455]
Description: {'vulners_cve_data_all': 'The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Debian和Ubuntu Postfix不安全临时文件建立漏洞) | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2939 was patched at 2024-05-15
794.
Unknown Vulnerability Type - Node.js (CVE-2022-29078) - High [454]
Description: {'vulners_cve_data_all': 'The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is executed upon template compilation).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-29078 was patched at 2024-05-15
795.
Unknown Vulnerability Type - OpenSSL (CVE-2006-3738) - High [454]
Description: {'vulners_cve_data_all': 'Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2006-007存在多个安全漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3738 was patched at 2024-05-15
796.
Unknown Vulnerability Type - PHP (CVE-2008-4796) - High [454]
Description: {'vulners_cve_data_all': 'The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary commands via shell metacharacters in https URLs.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Feed2JS File Disclosure, [packetstorm] Nagios Core Curl Command Injection / Code Execution, [seebug] Nagios Core < 4.2.2 Curl Command Injection/Code Execution (CVE-2016-9565)) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-4796 was patched at 2024-05-15
797.
Unknown Vulnerability Type - PHP (CVE-2008-7251) - High [454]
Description: {'vulners_cve_data_all': 'libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin创建不安全文件和目录漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-7251 was patched at 2024-05-15
798.
Unknown Vulnerability Type - PHP (CVE-2008-7252) - High [454]
Description: {'vulners_cve_data_all': 'libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin创建不安全文件和目录漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-7252 was patched at 2024-05-15
799.
Unknown Vulnerability Type - PHP (CVE-2009-2853) - High [454]
Description: {'vulners_cve_data_all': 'Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([dsquare] WordPress 2.8.3 RCE, [seebug] WordPress wp-admin非授权管理访问漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2853 was patched at 2024-05-15
800.
Unknown Vulnerability Type - PHP (CVE-2016-6175) - High [454]
Description: {'vulners_cve_data_all': 'Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] PHP gettext 1.0.12 - gettext.php Code Execution, [packetstorm] PHP gettext 1.0.12 Code Execution, [zdt] PHP gettext 1.0.12 - (gettext.php) Unauthenticated Code Execution, [exploitdb] PHP gettext 1.0.12 - 'gettext.php' Code Execution) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-6175 was patched at 2024-05-15
801.
Denial of Service - Git (CVE-2018-20164) - High [453]
Description: An issue was discovered in regex.yaml (aka regexes.yaml) in UA-Parser UAP-Core before 0.6.0. A Regular Expression
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] UA-Parser Denial Of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | Git | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-20164 was patched at 2024-05-15
802.
Memory Corruption - GPAC (CVE-2020-19750) - High [453]
Description: {'vulners_cve_data_all': 'An issue was discovered in gpac 0.8.0. The strdup function in box_code_base.c has a heap-based buffer over-read.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-19750 was patched at 2024-05-15
803.
Memory Corruption - GPAC (CVE-2021-32271) - High [453]
Description: {'vulners_cve_data_all': 'An issue was discovered in gpac through 20200801. A stack-buffer-overflow exists in the function DumpRawUIConfig located in odf_dump.c. It allows an attacker to cause code Execution.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32271 was patched at 2024-05-15
804.
Memory Corruption - GPAC (CVE-2023-0358) - High [453]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-0358 was patched at 2024-05-15
805.
Cross Site Scripting - Unknown Product (CVE-2013-6364) - High [452]
Description: {'vulners_cve_data_all': 'Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Horde Groupware Web Mail Edition 5.1.2 - CSRF Vulnerability, [zdt] Horde 5.1.2 CSRF / Cross Site Scripting Vulnerabilities, [packetstorm] Horde 5.1.2 Cross Site Request Forgery / Cross Site Scripting, [exploitpack] Horde Groupware Web Mail Edition 5.1.2 - Cross-Site Request Forgery (2), [exploitdb] Horde Groupware Web Mail Edition 5.1.2 - Cross-Site Request Forgery (2)) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-6364 was patched at 2024-05-15
806.
Remote Code Execution - Kerberos (CVE-2005-0490) - High [452]
Description: Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-0490 was patched at 2024-05-15
807.
Remote Code Execution - Kerberos (CVE-2006-6143) - High [452]
Description: The RPC library in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-6143 was patched at 2024-05-15
808.
Remote Code Execution - Kerberos (CVE-2008-0948) - High [452]
Description: Buffer overflow in the RPC library (lib/rpc/rpc_dtablesize.c) used by libgssrpc and kadmind in MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-0948 was patched at 2024-05-15
809.
Remote Code Execution - Kerberos (CVE-2012-1014) - High [452]
Description: The process_as_req function in the Key Distribution Center (KDC) in MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.9 | 10 | CVSS Base Score is 9.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1014 was patched at 2024-05-15
810.
Remote Code Execution - Unknown Product (CVE-2012-6081) - High [452]
Description: {'vulners_cve_data_all': 'Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as exploited in the wild in July 2012.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] MoinMoin twikidraw Action Traversal File Upload, [zdt] MoinMoin twikidraw Action Traversal File Upload Vulnerability, [seebug] MoinMoin action/twikidraw.py和action/anywikidraw.py任意代码执行漏洞, [dsquare] MoinMoin 1.9.5 RCE) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-6081 was patched at 2024-05-15
811.
Remote Code Execution - Unknown Product (CVE-2012-6495) - High [452]
Description: {'vulners_cve_data_all': 'Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to overwrite arbitrary files via unspecified vectors. NOTE: this can be leveraged with CVE-2012-6081 to execute arbitrary code.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([canvas] Immunity Canvas: MOINMOIN_RCE, [packetstorm] MoinMoin twikidraw Action Traversal File Upload, [zdt] MoinMoin twikidraw Action Traversal File Upload Vulnerability, [seebug] MoinMoin action/twikidraw.py和action/anywikidraw.py任意代码执行漏洞, [dsquare] MoinMoin 1.9.5 RCE) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-6495 was patched at 2024-05-15
812.
Remote Code Execution - Unknown Product (CVE-2019-1010091) - High [452]
Description: {'vulners_cve_data_all': 'tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact is: JavaScript code execution. The component is: Media element. The attack vector is: The victim must paste malicious content to media element's embed tab.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Cross-site Scripting in Tiny Tinymce) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-1010091 was patched at 2024-05-15
813.
Denial of Service - Perl (CVE-2013-6436) - High [451]
Description: The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] libvirt "lxcDomainGetMemoryParameters()"拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.2 | 10 | CVSS Base Score is 2.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-6436 was patched at 2024-05-15
814.
Denial of Service - Perl (CVE-2014-2573) - High [451]
Description: The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenStack Compute (Nova) VMWare驱动配额限制绕过拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.2 | 10 | CVSS Base Score is 2.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-2573 was patched at 2024-05-15
815.
Elevation of Privilege - Unknown Product (CVE-2016-10156) - High [449]
Description: {'vulners_cve_data_all': 'A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local attackers to escalate their privileges to root. This is fixed in v229.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Systemd 228 (SUSE 12 SP2 Ubuntu Touch 15.04) - Local Privilege Escalation, [packetstorm] Systemd 228 Privilege Escalation, [zdt] Systemd 228 - Privilege Escalation Vulnerability, [exploitdb] Systemd 228 (SUSE 12 SP2 / Ubuntu Touch 15.04) - Local Privilege Escalation) | |
| 0.85 | 15 | Elevation of Privilege | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-10156 was patched at 2024-05-15
816.
Elevation of Privilege - Unknown Product (CVE-2019-18862) - High [449]
Description: {'vulners_cve_data_all': 'maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] GNU Mailutils 3.7 Privilege Escalation, [zdt] GNU Mailutils 3.7 - Privilege Escalation Exploit, [exploitpack] GNU Mailutils 3.7 - Privilege Escalation, [exploitdb] GNU Mailutils 3.7 - Privilege Escalation) | |
| 0.85 | 15 | Elevation of Privilege | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-18862 was patched at 2024-05-15
817.
Memory Corruption - PHP (CVE-2013-1427) - High [448]
Description: The configuration file for the FastCGI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] lighttpd不安全临时文件创建漏洞(CVE-2013-1427)) | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.2 | 10 | CVSS Base Score is 1.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-1427 was patched at 2024-05-15
818.
Command Injection - Unknown Product (CVE-2022-3590) - High [447]
Description: {'vulners_cve_data_all': 'WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Time-of-check Time-of-use (TOCTOU) Race Condition in Wordpress, [wpexploit] WP <= 6.2 - Unauthenticated Blind SSRF via DNS Rebinding) | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-3590 was patched at 2024-05-15
819.
Remote Code Execution - Linux Kernel (CVE-2017-13715) - High [447]
Description: The __skb_flow_dissect function in net/core/flow_dissector.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-13715 was patched at 2024-05-15
820.
Remote Code Execution - Windows Kernel (CVE-2008-0296) - High [447]
Description: Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Media Player 0.8.6d and earlier on
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows Kernel | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-0296 was patched at 2024-05-15
821.
Remote Code Execution - Windows Kernel (CVE-2009-2688) - High [447]
Description: Multiple integer overflows in glyphs-eimage.c in XEmacs 21.4.22, when running on
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows Kernel | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2688 was patched at 2024-05-15
822.
Remote Code Execution - Windows Kernel (CVE-2022-28181) - High [447]
Description: NVIDIA GPU Display Driver for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows Kernel | |
| 1.0 | 10 | CVSS Base Score is 9.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-28181 was patched at 2024-05-15
823.
Remote Code Execution - Windows LDAP (CVE-2002-1347) - High [447]
Description: Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows LDAP (Lightweight Directory Access Protocol) is an open and cross platform protocol used for directory services authentication | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-1347 was patched at 2024-05-15
824.
Unknown Vulnerability Type - Apache HTTP Server (CVE-2013-2249) - High [447]
Description: {'vulners_cve_data_all': 'mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apache HTTP Server mod_session_dbd 远程安全漏洞(CVE-2013-2249)) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-2249 was patched at 2024-05-15
825.
Unknown Vulnerability Type - Linux Kernel (CVE-2016-6187) - High [447]
Description: {'vulners_cve_data_all': 'The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buffer size, which allows local users to gain privileges by triggering an AppArmor setprocattr hook.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Linux Kernel < 4.5.1 - Off-By-One (PoC) Exploit, [exploitpack] Linux Kernel 4.5.1 - Off-By-One (PoC), [exploitdb] Linux Kernel < 4.5.1 - Off-By-One (PoC)) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-6187 was patched at 2024-05-15
826.
Unknown Vulnerability Type - Linux Kernel (CVE-2021-45100) - High [447]
Description: {'vulners_cve_data_all': 'The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it sets the SMB2_GLOBAL_CAP_ENCRYPTION flag when using the SMB 3.1.1 protocol, which is a violation of the SMB protocol specification. When Windows 10 detects this protocol violation, it disables encryption.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-45100 was patched at 2024-05-15
827.
Unknown Vulnerability Type - Windows LDAP (CVE-2011-4075) - High [447]
Description: {'vulners_cve_data_all': 'The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as exploited in the wild in October 2011.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([dsquare] phpLDAPadmin 1.2.1.1 RCE) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | Windows LDAP (Lightweight Directory Access Protocol) is an open and cross platform protocol used for directory services authentication | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4075 was patched at 2024-05-15
828.
Denial of Service - Unknown Product (CVE-2017-7938) - High [446]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long argument. An example threat model is automated execution of DMitry with hostname strings found in local log files.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Dmitry 1.3a - Local Buffer Overflow (PoC), [zdt] DMitry - ( Deepmagic Information Gathering Tool ) - Local Stack Buffer Overflow Vulnerability, [packetstorm] Dmitry 1.3a Local Stack Buffer Overflow, [exploitdb] Dmitry 1.3a - Local Buffer Overflow (PoC)) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-7938 was patched at 2024-05-15
829.
Denial of Service - Unknown Product (CVE-2017-9430) - High [446]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a command line with a long name argument that is mishandled in a strcpy call for argv[0]. An example threat model is a web application that launches dnstracer with an untrusted name string.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] DNSTracer 1.9 - Buffer Overflow Exploit, [zdt] DNSTracer 1.8.1 - Buffer Overflow Vulnerability, [exploitpack] DNSTracer 1.8.1 - Buffer Overflow (PoC), [exploitpack] DNSTracer 1.9 - Local Buffer Overflow, [packetstorm] DNSTracer 1.8.1 Buffer Overflow, [packetstorm] DNSTracer 1.9 Buffer Overflow, [exploitdb] DNSTracer 1.8.1 - Buffer Overflow (PoC), [exploitdb] DNSTracer 1.9 - Local Buffer Overflow) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-9430 was patched at 2024-05-15
830.
Denial of Service - Unknown Product (CVE-2018-16492) - High [446]
Description: {'vulners_cve_data_all': 'A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-16492 was patched at 2024-05-15
831.
Denial of Service - Unknown Product (CVE-2019-11072) - High [446]
Description: {'vulners_cve_data_all': 'lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malicious HTTP GET request, as demonstrated by mishandling of /%2F? in burl_normalize_2F_to_slash_fix in burl.c. NOTE: The developer states "The feature which can be abused to cause the crash is a new feature in lighttpd 1.4.50, and is not enabled by default. It must be explicitly configured in the config file (e.g. lighttpd.conf). Certain input will trigger an abort() in lighttpd when that feature is enabled. lighttpd detects the underflow or realloc() will fail (in both 32-bit and 64-bit executables), also detected in lighttpd. Either triggers an explicit abort() by lighttpd. This is not exploitable beyond triggering the explicit abort() with subsequent application exit.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-11072 was patched at 2024-05-15
832.
Memory Corruption - HID (CVE-2018-1121) - High [446]
Description: procps-ng, procps is vulnerable to a process
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Procps-ng - Multiple Vulnerabilities, [exploitpack] Procps-ng - Multiple Vulnerabilities, [packetstorm] Procps-ng Audit Report, [exploitdb] Procps-ng - Multiple Vulnerabilities) | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | HID | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-1121 was patched at 2024-05-15
debian: CVE-2018-11210 was patched at 2024-05-15
833.
Path Traversal - Unknown Product (CVE-2022-23457) - High [446]
Description: {'vulners_cve_data_all': 'ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default implementation of `Validator.getValidDirectoryPath(String, String, File, boolean)` may incorrectly treat the tested input string as a child of the specified parent directory. This potentially could allow control-flow bypass checks to be defeated if an attack can specify the entire string representing the 'input' path. This vulnerability is patched in release 2.3.0.0 of ESAPI. As a workaround, it is possible to write one's own implementation of the Validator interface. However, maintainers do not recommend this.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-23457 was patched at 2024-05-15
834.
Security Feature Bypass - Unknown Product (CVE-2023-26159) - High [446]
Description: {'vulners_cve_data_all': 'Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site, potentially leading to information disclosure, phishing attacks, or other security breaches.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-26159 was patched at 2024-05-15
835.
Arbitrary File Reading - Unknown Product (CVE-2010-0013) - High [445]
Description: {'vulners_cve_data_all': 'Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Pidgin MSN 2.6.4 - File Download, [packetstorm] Pidgin MSN 2.6.4 File Download, [seebug] Pidgin MSN <= 2.6.4 File Download Vulnerability, [exploitdb] Pidgin MSN 2.6.4 - File Download) | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-0013 was patched at 2024-05-15
836.
Arbitrary File Reading - Unknown Product (CVE-2017-5982) - High [445]
Description: {'vulners_cve_data_all': 'Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, as demonstrated by image/image%3A%2F%2F%2e%2e%252fetc%252fpasswd.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Kodi 17.0 Local File Inclusion Exploit, [packetstorm] Kodi 17.1 Local File Inclusion) | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-5982 was patched at 2024-05-15
837.
Information Disclosure - Unknown Product (CVE-2008-4359) - High [445]
Description: {'vulners_cve_data_all': 'lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Lighttpd URI重写/重定向信息泄露漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-4359 was patched at 2024-05-15
838.
Information Disclosure - Unknown Product (CVE-2016-1886) - High [445]
Description: {'vulners_cve_data_all': 'Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to obtain sensitive information from kernel memory, cause a denial of service (memory overwrite and kernel crash), or gain privileges via a negative value in the flen structure member in the arg argument in a SETFKEY ioctl call, which triggers a "two way heap and stack overflow."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] FreeBSD Kernel (FreeBSD 10.2 < 10.3 x64) - SETFKEY (PoC) Exploit) | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-1886 was patched at 2024-05-15
839.
Information Disclosure - Unknown Product (CVE-2017-2895) - High [445]
Description: {'vulners_cve_data_all': 'An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory read potentially resulting in information disclosure and denial of service. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Cesanta Mongoose MQTT SUBSCRIBE Topic Length Information Leak(CVE-2017-2895)) | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2895 was patched at 2024-05-15
840.
Information Disclosure - Unknown Product (CVE-2018-19045) - High [445]
Description: {'vulners_cve_data_all': 'keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive information.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-19045 was patched at 2024-05-15
841.
Information Disclosure - Unknown Product (CVE-2018-9144) - High [445]
Description: {'vulners_cve_data_all': 'In Exiv2 0.26, there is an out-of-bounds read in Exiv2::Internal::binaryToString in image.cpp. It could result in denial of service or information disclosure.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-9144 was patched at 2024-05-15
842.
Information Disclosure - Unknown Product (CVE-2022-45868) - High [445]
Description: {'vulners_cve_data_all': 'The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the web admin console. Consequently, a local user (or an attacker that has obtained local access through some means) would be able to discover the password by listing processes and their arguments. NOTE: the vendor states "This is not a vulnerability of H2 Console ... Passwords should never be passed on the command line and every qualified DBA or system administrator is expected to know that." Nonetheless, the issue was fixed in 2.2.220.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-45868 was patched at 2024-05-15
843.
Unknown Vulnerability Type - PHP (CVE-2009-1960) - High [442]
Description: {'vulners_cve_data_all': 'inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([canvas] Immunity Canvas: DOKUWIKI_EXEC2) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1960 was patched at 2024-05-15
844.
Unknown Vulnerability Type - PHP (CVE-2015-8379) - High [442]
Description: {'vulners_cve_data_all': 'CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] CakePHP 3.2.0 CSRF Bypass) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-8379 was patched at 2024-05-15
845.
Unknown Vulnerability Type - PHP (CVE-2017-5368) - High [442]
Description: {'vulners_cve_data_all': 'ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a malicious web page, the attacker can silently and automatically create a new admin user within the web application for remote persistence and further attacks. The URL is /zm/index.php and sample parameters could include action=user uid=0 newUser[Username]=attacker1 newUser[Password]=Password1234 conf_password=Password1234 newUser[System]=Edit (among others).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] ZoneMinder - Multiple Vulnerabilities, [packetstorm] ZoneMinder XSS / CSRF / File Disclosure / Authentication Bypass) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-5368 was patched at 2024-05-15
846.
Unknown Vulnerability Type - PHP (CVE-2018-10188) - High [442]
Description: {'vulners_cve_data_all': 'phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] phpMyAdmin 4.8.0 4.8.0-1 - Cross-Site Request Forgery, [zdt] phpMyAdmin 4.8.0 / 4.8.0-1 - Cross-Site Request Forgery Vulnerability, [packetstorm] phpMyAdmin Cross Site Request Forgery, [exploitdb] phpMyAdmin 4.8.0 < 4.8.0-1 - Cross-Site Request Forgery) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-10188 was patched at 2024-05-15
847.
Unknown Vulnerability Type - PHP (CVE-2020-14947) - High [442]
Description: {'vulners_cve_data_all': 'OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php because mib_file in plugins/main_sections/ms_config/ms_snmp_config.php is mishandled in get_mib_oid.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] OCS Inventory NG 2.7 Remote Code Execution, [githubexploit] Exploit for OS Command Injection in Factorfx Open Computer Software Inventory Next Generation, [zdt] OCS Inventory NG 2.7 - Remote Code Execution Exploit, [exploitdb] OCS Inventory NG 2.7 - Remote Code Execution) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-14947 was patched at 2024-05-15
848.
Remote Code Execution - Kerberos (CVE-2002-0657) - High [440]
Description: Buffer overflow in OpenSSL 0.9.7 before 0.9.7-beta3, with
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-0657 was patched at 2024-05-15
849.
Remote Code Execution - Kerberos (CVE-2003-0060) - High [440]
Description: Format string vulnerabilities in the logging routines for MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0060 was patched at 2024-05-15
850.
Remote Code Execution - Kerberos (CVE-2004-0642) - High [440]
Description: Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0642 was patched at 2024-05-15
851.
Remote Code Execution - Kerberos (CVE-2005-1175) - High [440]
Description: Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-1175 was patched at 2024-05-15
852.
Remote Code Execution - Unknown Product (CVE-2003-0165) - High [440]
Description: {'vulners_cve_data_all': 'Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] core.gnome.txt) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0165 was patched at 2024-05-15
853.
Remote Code Execution - Unknown Product (CVE-2005-2335) - High [440]
Description: {'vulners_cve_data_all': 'Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses. NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Fetchmail POP3客户端缓冲区溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-2335 was patched at 2024-05-15
854.
Remote Code Execution - Unknown Product (CVE-2006-2237) - High [440]
Description: {'vulners_cve_data_all': 'The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharacters in the migrate parameter.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([saint] AWStats migrate parameter command injection, [saint] AWStats migrate parameter command injection, [saint] AWStats migrate parameter command injection, [saint] AWStats migrate parameter command injection, [packetstorm] AWStats migrate Remote Command Execution) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-2237 was patched at 2024-05-15
855.
Remote Code Execution - Unknown Product (CVE-2006-2465) - High [440]
Description: {'vulners_cve_data_all': 'Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if mp3info is not installed setuid or setgid in any reasonable context, then this issue might not be a vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] MP3Info 0.8.5a - SEH Buffer Overflow Exploit, [packetstorm] MP3Info 0.8.5 SEH Buffer Overflow) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-2465 was patched at 2024-05-15
856.
Remote Code Execution - Unknown Product (CVE-2007-6613) - High [440]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the print_iso9660_recurse function in iso-info (src/iso-info.c) in GNU Compact Disc Input and Control Library (libcdio) 0.79 and earlier allows context-dependent attackers to cause a denial of service (core dump) and possibly execute arbitrary code via a disk or image that contains a long joilet file name.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] GNU libcdio库cd-info/iso-info文件栈溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-6613 was patched at 2024-05-15
857.
Remote Code Execution - Unknown Product (CVE-2009-1490) - High [440]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Sendmail X-header头远程堆溢出漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1490 was patched at 2024-05-15
858.
Remote Code Execution - Unknown Product (CVE-2023-25440) - High [440]
Description: {'vulners_cve_data_all': 'Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/second name field.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] CiviCRM 5.59.alpha1 Cross Site Scripting, [zdt] CiviCRM 5.59.alpha1 Cross Site Scripting Vulnerability, [exploitdb] CiviCRM 5.59.alpha1 - Stored XSS (Cross-Site Scripting)) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-25440 was patched at 2024-05-15
859.
Unknown Vulnerability Type - Kerberos (CVE-2009-0360) - High [440]
Description: {'vulners_cve_data_all': 'Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] pam-krb5 3.13 - Local Privilege Escalation, [seebug] pam-krb5 API使用本地权限提升漏洞, [seebug] pam-krb5 < 3.13 Local Privilege Escalation Exploit, [seebug] pam-krb5 < 3.13 Local Privilege Escalation Exploit, [exploitdb] pam-krb5 < 3.13 - Local Privilege Escalation) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0360 was patched at 2024-05-15
860.
Unknown Vulnerability Type - MediaWiki (CVE-2017-0372) - High [438]
Description: {'vulners_cve_data_all': 'Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] SyntaxHighlight 2.0 MediaWiki 1.28.0 Stored Cross Site Scripting Vulnerability, [packetstorm] SyntaxHighlight 2.0 MediaWiki 1.28.0 Stored Cross Site Scripting, [packetstorm] MediaWiki SyntaxHighlight Extension Option Injection) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-0372 was patched at 2024-05-15
861.
Unknown Vulnerability Type - SQLite (CVE-2021-37832) - High [438]
Description: {'vulners_cve_data_all': 'A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can issue SQL commands to the SQLite database through the vulnerable idappartamenti parameter.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for SQL Injection in Digitaldruid Hoteldruid, [githubexploit] Exploit for SQL Injection in Digitaldruid Hoteldruid) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | SQLite is a database engine written in the C programming language | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-37832 was patched at 2024-05-15
862.
Elevation of Privilege - Unknown Product (CVE-2021-3864) - High [437]
Description: {'vulners_cve_data_all': 'A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then have a dumpable value set to 1. As a result, if the descendant process crashes and core_pattern is set to a relative value, its core dump is stored in the current directory with uid:gid permissions. An unprivileged local user with eligible root SUID binary could use this flaw to place core dumps into root-owned directories, potentially resulting in escalation of privileges.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Improper Access Control in Linux Linux Kernel) | |
| 0.85 | 15 | Elevation of Privilege | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-3864 was patched at 2024-05-15
863.
Code Injection - Unknown Product (CVE-2021-23413) - High [435]
Description: {'vulners_cve_data_all': 'This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-23413 was patched at 2024-05-15
864.
Command Injection - Unknown Product (CVE-2021-32715) - High [435]
Description: {'vulners_cve_data_all': 'hyper is an HTTP library for rust. hyper's HTTP/1 server code had a flaw that incorrectly parses and accepts requests with a `Content-Length` header with a prefixed plus sign, when it should have been rejected as illegal. This combined with an upstream HTTP proxy that doesn't parse such `Content-Length` headers, but forwards them, can result in "request smuggling" or "desync attacks". The flaw exists in all prior versions of hyper prior to 0.14.10, if built with `rustc` v1.5.0 or newer. The vulnerability is patched in hyper version 0.14.10. Two workarounds exist: One may reject requests manually that contain a plus sign prefix in the `Content-Length` header or ensure any upstream proxy handles `Content-Length` headers with a plus sign prefix.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32715 was patched at 2024-05-15
865.
Memory Corruption - Linux Kernel (CVE-2019-19814) - High [435]
Description: In the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-19814 was patched at 2024-05-15
866.
Memory Corruption - Linux Kernel (CVE-2022-32981) - High [435]
Description: An issue was discovered in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-32981 was patched at 2024-05-15
867.
Memory Corruption - Linux Kernel (CVE-2023-52440) - High [435]
Description: {'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob()\n\nIf authblob->SessionKey.Length is bigger than session key\nsize(CIFS_KEY_SIZE), slub overflow can happen in key exchange codes.\ncifs_arc4_crypt copy to session key array from SessionKey from client.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-52440 was patched at 2024-05-15
868.
Remote Code Execution - Windows Kernel (CVE-2011-0191) - High [435]
Description: Buffer overflow in LibTIFF 3.9.4 and possibly other versions, as used in ImageIO in Apple iTunes before 10.2 on
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows Kernel | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-0191 was patched at 2024-05-15
869.
XXE Injection - Unknown Product (CVE-2014-3242) - High [435]
Description: {'vulners_cve_data_all': 'SOAPpy 0.12.5 allows remote attackers to read arbitrary files via a SOAP request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] SOAPpy 0.12.5 多个漏洞) | |
| 0.97 | 15 | XXE Injection | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-3242 was patched at 2024-05-15
870.
Denial of Service - Unknown Product (CVE-2011-0531) - High [434]
Description: {'vulners_cve_data_all': 'demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary commands via a crafted MKV (WebM or Matroska) file that triggers memory corruption, related to "class mismatching" and the MKV_IS_ID macro.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([saint] VideoLAN VLC Media Player MKV Demuxer Code Execution, [saint] VideoLAN VLC Media Player MKV Demuxer Code Execution, [saint] VideoLAN VLC Media Player MKV Demuxer Code Execution, [saint] VideoLAN VLC Media Player MKV Demuxer Code Execution, [packetstorm] VideoLAN VLC MKV Memory Corruption) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-0531 was patched at 2024-05-15
871.
Denial of Service - Unknown Product (CVE-2018-8002) - High [434]
Description: {'vulners_cve_data_all': 'In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack overflow. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] PoDoFo 0.9.5 - Buffer Overflow Vulnerability, [packetstorm] PoDoFo 0.9.5 Buffer Overflow, [exploitpack] PoDoFo 0.9.5 - Buffer Overflow (PoC), [exploitdb] PoDoFo 0.9.5 - Buffer Overflow (PoC)) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-8002 was patched at 2024-05-15
872.
Denial of Service - Unknown Product (CVE-2020-19497) - High [434]
Description: {'vulners_cve_data_all': 'Integer overflow vulnerability in Mat_VarReadNextInfo5 in mat5.c in tbeu matio (aka MAT File I/O Library) 1.5.17, allows attackers to cause a Denial of Service or possibly other unspecified impacts.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-19497 was patched at 2024-05-15
873.
Denial of Service - Unknown Product (CVE-2020-19498) - High [434]
Description: {'vulners_cve_data_all': 'Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impacts.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-19498 was patched at 2024-05-15
874.
Denial of Service - Unknown Product (CVE-2020-19499) - High [434]
Description: {'vulners_cve_data_all': 'An issue was discovered in heif::Box_iref::get_references in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impact due to an invalid memory read.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-19499 was patched at 2024-05-15
875.
Security Feature Bypass - Unknown Product (CVE-2022-40896) - High [434]
Description: {'vulners_cve_data_all': 'A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-40896 was patched at 2024-05-15
876.
Information Disclosure - Unknown Product (CVE-2009-4235) - High [433]
Description: {'vulners_cve_data_all': 'acpid 1.0.4 sets an unrestrictive umask, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive information by reading this file or cause a denial of service by overwriting this file, a different vulnerability than CVE-2009-4033.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Red Hat acpid '/var/log/acpid'日志文件权限本地特权提升漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4235 was patched at 2024-05-15
877.
Information Disclosure - Unknown Product (CVE-2023-27478) - High [433]
Description: {'vulners_cve_data_all': 'libmemcached-awesome is an open source C/C++ client library and tools for the memcached server. `libmemcached` could return data for a previously requested key, if that previous request timed out due to a low `POLL_TIMEOUT`. This issue has been addressed in version 1.1.4. Users are advised to upgrade. There are several ways to workaround or lower the probability of this bug affecting a given deployment. 1: use a reasonably high `POLL_TIMEOUT` setting, like the default. 2: use separate libmemcached connections for unrelated data. 3: do not re-use libmemcached connections in an unknown state.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-27478 was patched at 2024-05-15
878.
Information Disclosure - Unknown Product (CVE-2024-28849) - High [433]
Description: {'vulners_cve_data_all': 'follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header during cross-domain redirect, but keep the proxy-authentication header which contains credentials too. This vulnerability may lead to credentials leak, but has been addressed in version 1.15.6. Users are advised to upgrade. There are no known workarounds for this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-28849 was patched at 2024-05-15
879.
Spoofing - Perl (CVE-2013-6419) - High [433]
Description: Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenStack Neutron/Nova信息泄漏漏洞) | |
| 0.4 | 15 | Spoofing | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-6419 was patched at 2024-05-15
880.
Authentication Bypass - Apache HTTP Server (CVE-2017-6062) - High [432]
Description: The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.9 | 10 | CVSS Base Score is 8.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-6062 was patched at 2024-05-15
881.
Arbitrary File Writing - Unknown Product (CVE-2007-6683) - High [431]
Description: {'vulners_cve_data_all': 'The browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to overwrite arbitrary files via (1) the :demuxdump-file option in a filename in a playlist, or (2) a EXTVLCOPT statement in an MP3 file, possibly an argument injection vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] VLC媒体播放器浏览器插件任意文件覆盖漏洞) | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-6683 was patched at 2024-05-15
882.
Arbitrary File Writing - Unknown Product (CVE-2008-1694) - High [431]
Description: {'vulners_cve_data_all': 'vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] GNU Emacs创建不安全临时文件漏洞) | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1694 was patched at 2024-05-15
883.
Remote Code Execution - APT (CVE-2023-41101) - High [430]
Description: An issue was discovered in the c
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-41101 was patched at 2024-05-15
884.
Remote Code Execution - Mozilla Firefox (CVE-2006-1790) - High [430]
Description: A regression fix in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-1790 was patched at 2024-05-15
885.
Remote Code Execution - Mozilla Firefox (CVE-2006-4571) - High [430]
Description: Multiple unspecified vulnerabilities in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4571 was patched at 2024-05-15
886.
Remote Code Execution - Mozilla Firefox (CVE-2008-3533) - High [430]
Description: Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3533 was patched at 2024-05-15
887.
Remote Code Execution - OpenSSH (CVE-2002-0639) - High [430]
Description: Integer overflow in sshd in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-0639 was patched at 2024-05-15
888.
Remote Code Execution - OpenSSH (CVE-2002-0640) - High [430]
Description: Buffer overflow in sshd in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-0640 was patched at 2024-05-15
889.
Remote Code Execution - OpenSSH (CVE-2003-0693) - High [430]
Description: A "buffer management error" in buffer_append_space of buffer.c for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0693 was patched at 2024-05-15
890.
Remote Code Execution - OpenSSL (CVE-2003-0545) - High [430]
Description: Double free vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0545 was patched at 2024-05-15
891.
Remote Code Execution - PHP (CVE-2019-10774) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-10774 was patched at 2024-05-15
892.
Remote Code Execution - PHP (CVE-2023-26034) - High [430]
Description: ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are affected by a SQL Injection vulnerability. The (blind) SQL Injection vulnerability is present within the `filter[Query][terms][0][attr]` query string parameter of the `/zm/index.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-26034 was patched at 2024-05-15
893.
Remote Code Execution - PHP (CVE-2023-40619) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-40619 was patched at 2024-05-15
894.
Remote Code Execution - RPC (CVE-2003-0033) - High [430]
Description: Buffer overflow in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0033 was patched at 2024-05-15
895.
Remote Code Execution - RPC (CVE-2003-0252) - High [430]
Description: Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0252 was patched at 2024-05-15
896.
Remote Code Execution - Samba (CVE-2004-0882) - High [430]
Description: Buffer overflow in the QFILEPATHINFO request handler in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0882 was patched at 2024-05-15
897.
Remote Code Execution - Samba (CVE-2004-1154) - High [430]
Description: Integer overflow in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-1154 was patched at 2024-05-15
898.
Remote Code Execution - libvpx (CVE-2016-1621) - High [430]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | libvpx is a free software video codec library from Google and the Alliance for Open Media (AOMedia) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-1621 was patched at 2024-05-15
899.
Unknown Vulnerability Type - OpenSSH (CVE-2003-1562) - High [430]
Description: {'vulners_cve_data_all': 'sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Portable OpenSSH 3.6.1p-PAM4.1-SuSE - Timing Attack, [packetstorm] openssh-timing.txt, [seebug] Portable OpenSSH <= 3.6.1p-PAM / 4.1-SUSE Timing Attack Exploit, [seebug] Portable OpenSSH <= 3.6.1p-PAM / 4.1-SUSE Timing Attack Exploit, [seebug] Portable OpenSSH <= 3.6.1p-PAM / 4.1-SUSE Timing Attack Exploit, [exploitdb] Portable OpenSSH 3.6.1p-PAM/4.1-SuSE - Timing Attack) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-1562 was patched at 2024-05-15
900.
Unknown Vulnerability Type - PHP (CVE-2008-3880) - High [430]
Description: {'vulners_cve_data_all': 'SQL injection vulnerability in zm_html_view_event.php in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary SQL commands via the filter array parameter.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] airVisionNVR 1.1.13 Disclosure / SQL Injection, [exploitdb] airVisionNVR 1.1.13 - 'readfile()' Disclosure / SQL Injection, [exploitpack] airVisionNVR 1.1.13 - readfile() Disclosure SQL Injection, [seebug] airVisionNVR 1.1.13 readfile() Disclosure and SQL Injection) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3880 was patched at 2024-05-15
901.
Unknown Vulnerability Type - PHP (CVE-2008-4360) - High [430]
Description: {'vulners_cve_data_all': 'mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Lighttpd 'mod_userdir'大小写区分对比安全绕过漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-4360 was patched at 2024-05-15
902.
Unknown Vulnerability Type - PHP (CVE-2009-3041) - High [430]
Description: {'vulners_cve_data_all': 'SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([dsquare] SPIP 2.0.8 Information Disclosure) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3041 was patched at 2024-05-15
903.
Unknown Vulnerability Type - PHP (CVE-2009-3697) - High [430]
Description: {'vulners_cve_data_all': 'SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin SQL注入和跨站脚本漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3697 was patched at 2024-05-15
904.
Unknown Vulnerability Type - PHP (CVE-2009-4023) - High [430]
Description: {'vulners_cve_data_all': 'Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for PEAR allows remote attackers to read and write arbitrary files via a crafted $from parameter, a different vector than CVE-2009-4111.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] PEAR Mail软件包Recipient参数注入漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4023 was patched at 2024-05-15
905.
Unknown Vulnerability Type - PHP (CVE-2011-4674) - High [430]
Description: {'vulners_cve_data_all': 'SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows remote attackers to execute arbitrary SQL commands via the only_hostid parameter.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([dsquare] Zabbix <= 1.8.4 SQL Injection) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4674 was patched at 2024-05-15
906.
Unknown Vulnerability Type - PHP (CVE-2012-3435) - High [430]
Description: {'vulners_cve_data_all': 'SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and earlier, and 2.x before 2.0.2rc1, allows remote attackers to execute arbitrary SQL commands via the itemid parameter.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([dsquare] Zabbix 2.0 SQL Injection) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-3435 was patched at 2024-05-15
907.
Unknown Vulnerability Type - PHP (CVE-2012-3448) - High [430]
Description: {'vulners_cve_data_all': 'Unspecified vulnerability in Ganglia Web before 3.5.1 allows remote attackers to execute arbitrary PHP code via unknown attack vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Ganglia Web Frontend 3.5.1 - PHP Code Execution, [seebug] Ganglia Web Frontend < 3.5.1 - PHP Code Execution, [packetstorm] Ganglia Web Frontend PHP Code Execution, [zdt] Ganglia Web Frontend < 3.5.1 - PHP Code Execution Exploit, [exploitdb] Ganglia Web Frontend < 3.5.1 - PHP Code Execution) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-3448 was patched at 2024-05-15
908.
Unknown Vulnerability Type - PHP (CVE-2014-1691) - High [430]
Description: {'vulners_cve_data_all': 'The framework/Util/lib/Horde/Variables.php script in the Util library in Horde before 5.1.1 allows remote attackers to conduct object injection attacks and execute arbitrary PHP code via a crafted serialized object in the _formvars form.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([metasploit] Horde Framework Unserialize PHP Code Execution, [zdt] Horde Framework Unserialize PHP Code Execution, [seebug] Horde Framework Unserialize PHP Code Execution, [packetstorm] Horde Framework Unserialize PHP Code Execution, [packetstorm] Horde Framework Unserialize PHP Code Execution, [exploitdb] Horde Framework - Unserialize PHP Code Execution (Metasploit)) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-1691 was patched at 2024-05-15
909.
Unknown Vulnerability Type - RPC (CVE-2013-1362) - High [430]
Description: {'vulners_cve_data_all': 'Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Nagios NRPE 2.13 Code Execution, [packetstorm] Nagios Remote Plugin Executor Arbitrary Command Execution, [zdt] Nagios Remote Plugin Executor Arbitrary Command Execution, [saint] Nagios Remote Plugin Executor Metacharacter Filtering Omission, [saint] Nagios Remote Plugin Executor Metacharacter Filtering Omission, [saint] Nagios Remote Plugin Executor Metacharacter Filtering Omission, [saint] Nagios Remote Plugin Executor Metacharacter Filtering Omission) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-1362 was patched at 2024-05-15
910.
Unknown Vulnerability Type - Samba (CVE-2010-0728) - High [430]
Description: {'vulners_cve_data_all': 'smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Samba CAP_DAC_OVERRIDE文件权限绕过安全限制漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 0.8 | 10 | CVSS Base Score is 8.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-0728 was patched at 2024-05-15
911.
Memory Corruption - GPAC (CVE-2022-46490) - High [429]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-46490 was patched at 2024-05-15
912.
Remote Code Execution - Linux Kernel (CVE-2023-6270) - High [429]
Description: A flaw was found in the ATA over Ethernet (AoE) driver in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-6270 was patched at 2024-05-06, 2024-05-15
ubuntu: CVE-2023-6270 was patched at 2024-06-07, 2024-06-10, 2024-06-11, 2024-06-14
913.
Cross Site Scripting - Unknown Product (CVE-2006-3636) - High [428]
Description: {'vulners_cve_data_all': 'Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] 0013.txt) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3636 was patched at 2024-05-15
914.
Cross Site Scripting - Unknown Product (CVE-2024-4439) - High [428]
Description: {'vulners_cve_data_all': 'WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the display name. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. In addition, it also makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that have the comment block present and display the comment author's avatar.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-4439 was patched at 2024-05-15
915.
Remote Code Execution - Kerberos (CVE-2004-1189) - High [428]
Description: The add_to_history function in svr_principal.c in libkadm5srv for MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-1189 was patched at 2024-05-15
916.
Remote Code Execution - Unknown Product (CVE-2014-0039) - High [428]
Description: {'vulners_cve_data_all': 'Untrusted search path vulnerability in fwsnort before 1.6.4, when not running as root, allows local users to execute arbitrary code via a Trojan horse fwsnort.conf in the current working directory.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] fwsnort 'fwsnort.conf'本地权限提升漏洞) | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-0039 was patched at 2024-05-15
917.
Unknown Vulnerability Type - Curl (CVE-2007-2951) - High [426]
Description: {'vulners_cve_data_all': 'The parseIrcUrl function in src/kvirc/kernel/kvi_ircurl.cpp in KVIrc 3.2.0 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in an (1) irc:// or (2) irc6:// URI.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] KVIrc irc:// URI处理器远程命令注入漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Curl is a command-line tool for transferring data specified with URL syntax | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-2951 was patched at 2024-05-15
918.
Unknown Vulnerability Type - FFmpeg (CVE-2011-2160) - High [426]
Description: {'vulners_cve_data_all': 'The VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer and other products, does not properly restrict read operations, which allows remote attackers to have an unspecified impact via a crafted VC-1 file, a related issue to CVE-2011-0723.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg畸形"VC1"文件解析内存破坏远程代码执行漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-2160 was patched at 2024-05-15
919.
Unknown Vulnerability Type - FFmpeg (CVE-2013-0869) - High [426]
Description: {'vulners_cve_data_all': 'The field_end function in libavcodec/h264.c in FFmpeg before 1.1.2 allows remote attackers to have an unspecified impact via crafted H.264 data, related to an SPS and slice mismatch and an out-of-bounds array access.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FFmpeg 'field_end()'函数拒绝服务漏洞(CVE-2013-0869)) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-0869 was patched at 2024-05-15
920.
Code Injection - APT (CVE-2019-18889) - High [425]
Description: An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache ad
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-18889 was patched at 2024-05-15
921.
Code Injection - PHP (CVE-2018-1000871) - High [425]
Description: HotelDruid HotelDruid 2.3.0 version 2.3.0 and earlier contains a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-1000871 was patched at 2024-05-15
922.
Code Injection - PHP (CVE-2019-16774) - High [425]
Description: {'vulners_cve_data_all': 'In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-16774 was patched at 2024-05-15
923.
Code Injection - PHP (CVE-2019-8423) - High [425]
Description: ZoneMinder through 1.32.3 has
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-8423 was patched at 2024-05-15
924.
Code Injection - PHP (CVE-2019-8424) - High [425]
Description: ZoneMinder before 1.32.3 has
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-8424 was patched at 2024-05-15
925.
Code Injection - PHP (CVE-2019-8428) - High [425]
Description: ZoneMinder before 1.32.3 has
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-8428 was patched at 2024-05-15
926.
Code Injection - PHP (CVE-2019-8429) - High [425]
Description: ZoneMinder before 1.32.3 has
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-8429 was patched at 2024-05-15
927.
Code Injection - PHP (CVE-2019-9086) - High [425]
Description: HotelDruid before v2.3.1 has
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-9086 was patched at 2024-05-15
928.
Code Injection - PHP (CVE-2019-9087) - High [425]
Description: HotelDruid before v2.3.1 has
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-9087 was patched at 2024-05-15
929.
Code Injection - PHP (CVE-2020-22452) - High [425]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-22452 was patched at 2024-05-15
930.
Command Injection - APT (CVE-2021-39214) - High [425]
Description: mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.2 and below, a malicious client or server is able to perform HTTP
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-39214 was patched at 2024-05-15
931.
Command Injection - APT (CVE-2022-24766) - High [425]
Description: mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.4 and below, a malicious client or server is able to perform HTTP
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-24766 was patched at 2024-05-15
932.
Command Injection - GNOME desktop (CVE-2022-27811) - High [425]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-27811 was patched at 2024-05-15
933.
Command Injection - Node.js (CVE-2018-13797) - High [425]
Description: The macaddress module before 0.2.9 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-13797 was patched at 2024-05-15
934.
Command Injection - Node.js (CVE-2021-42740) - High [425]
Description: The shell-quote package before 1.7.3 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-42740 was patched at 2024-05-15
935.
Command Injection - Node.js (CVE-2022-35949) - High [425]
Description: undici is an HTTP/1.1 client, written from scratch for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-35949 was patched at 2024-05-15
936.
Command Injection - PHP (CVE-2008-3882) - High [425]
Description: Unspecified "
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3882 was patched at 2024-05-15
937.
Command Injection - PHP (CVE-2019-8427) - High [425]
Description: daemonControl in includes/functions.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-8427 was patched at 2024-05-15
938.
Denial of Service - Linux Kernel (CVE-2023-2019) - High [423]
Description: A flaw was found in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-2019 was patched at 2024-05-15
939.
Memory Corruption - Linux Kernel (CVE-2021-32078) - High [423]
Description: {'vulners_cve_data_all': 'An Out-of-Bounds Read was discovered in arch/arm/mach-footbridge/personal-pci.c in the Linux kernel through 5.12.11 because of the lack of a check for a value that shouldn't be negative, e.g., access to element -2 of an array, aka CID-298a58e165e4.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32078 was patched at 2024-05-15
940.
Remote Code Execution - Linux Kernel (CVE-2016-4440) - High [423]
Description: arch/x86/kvm/vmx.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-4440 was patched at 2024-05-15
941.
Remote Code Execution - Windows Encrypting File System (CVE-2021-3403) - High [423]
Description: In ytnef 1.9.3, the TN
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Encrypting File System (EFS) on Microsoft Windows is a feature introduced in version 3.0 of NTFS that provides filesystem-level encryption | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-3403 was patched at 2024-05-15
942.
Remote Code Execution - Windows Kernel (CVE-2006-4046) - High [423]
Description: Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows Kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4046 was patched at 2024-05-15
943.
Remote Code Execution - Windows Kernel (CVE-2021-40827) - High [423]
Description: Clementine Music Player through 1.3.1 (when a GLib 2.0.0 DLL is used) is vulnerable to a Read Access Violation on Block Data Move, affecting the MP3 file parsing functionality at memcpy+0x265. The vulnerability is triggered when the user opens a crafted MP3 file or loads a remote stream URL that is mishandled by Clementine. Attackers could exploit this issue to cause a crash (DoS) of the clementine.exe process or achieve arbitrary
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows Kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-40827 was patched at 2024-05-15
944.
Remote Code Execution - Windows Kernel (CVE-2023-25515) - High [423]
Description:
NVIDIA GPU Display Driver for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows Kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-25515 was patched at 2024-05-15
945.
Remote Code Execution - Windows LDAP (CVE-2002-0825) - High [423]
Description: Buffer overflow in the DNS SRV code for nss_
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows LDAP (Lightweight Directory Access Protocol) is an open and cross platform protocol used for directory services authentication | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-0825 was patched at 2024-05-15
946.
Remote Code Execution - Windows LDAP (CVE-2005-2549) - High [423]
Description: Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows LDAP (Lightweight Directory Access Protocol) is an open and cross platform protocol used for directory services authentication | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-2549 was patched at 2024-05-15
947.
Denial of Service - Unknown Product (CVE-2005-2096) - High [422]
Description: {'vulners_cve_data_all': 'zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] IPComp - encapsulation Kernel Memory Corruption, [seebug] IPComp encapsulation pre-auth kernel memory corruption, [exploitdb] IPComp - encapsulation Kernel Memory Corruption) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-2096 was patched at 2024-05-15
948.
Denial of Service - Unknown Product (CVE-2006-3463) - High [422]
Description: {'vulners_cve_data_all': 'The EstimateStripByteCounts function in TIFF library (libtiff) before 3.8.2 uses a 16-bit unsigned short when iterating over an unsigned 32-bit value, which allows context-dependent attackers to cause a denial of service via a large td_nstrips value, which triggers an infinite loop.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Libtiff图形库多个安全漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3463 was patched at 2024-05-15
949.
Denial of Service - Unknown Product (CVE-2007-2026) - High [422]
Description: {'vulners_cve_data_all': 'The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] File多个拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-2026 was patched at 2024-05-15
950.
Denial of Service - Unknown Product (CVE-2007-5846) - High [422]
Description: {'vulners_cve_data_all': 'The SNMP agent (snmp_agent.c) in net-snmp before 5.4.1 allows remote attackers to cause a denial of service (CPU and memory consumption) via a GETBULK request with a large max-repeaters value.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Net-SNMP GETBULK远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-5846 was patched at 2024-05-15
951.
Denial of Service - Unknown Product (CVE-2008-3264) - High [422]
Description: {'vulners_cve_data_all': 'The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before B.2.5.4, and C.x.x before C.1.10.3; AsteriskNOW; Appliance Developer Kit 0.x.x; and s800i 1.0.x before 1.2.0.1 allows remote attackers to cause a denial of service (traffic amplification) via an IAX2 FWDOWNL request.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Asterisk IAX2固件升级报文放大远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3264 was patched at 2024-05-15
952.
Denial of Service - Unknown Product (CVE-2008-3688) - High [422]
Description: {'vulners_cve_data_all': 'sockethandler.cpp in HTTP Antivirus Proxy (HAVP) 0.88 allows remote attackers to cause a denial of service (hang) by connecting to a non-responsive server, which triggers an infinite loop due to an uninitialized variable.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] HAVP sockethandler.cpp客户端连接拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3688 was patched at 2024-05-15
953.
Denial of Service - Unknown Product (CVE-2009-1250) - High [422]
Description: {'vulners_cve_data_all': 'The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenAFS出错代码远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1250 was patched at 2024-05-15
954.
Denial of Service - Unknown Product (CVE-2014-2828) - High [422]
Description: {'vulners_cve_data_all': 'The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenStack Keystone V3 API验证拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-2828 was patched at 2024-05-15
955.
Denial of Service - Unknown Product (CVE-2015-7507) - High [422]
Description: {'vulners_cve_data_all': 'libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a crafted color table to the (1) bmp_decode_rgb or (2) bmp_decode_rle function.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Libnsbmp 0.1.2 Heap Overflow / Out-Of-Bounds Read Exploit) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-7507 was patched at 2024-05-15
956.
Denial of Service - Unknown Product (CVE-2016-1887) - High [422]
Description: {'vulners_cve_data_all': 'Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to cause a denial of service (memory overwrite and kernel panic) or gain privileges via a negative buflen argument, which triggers a heap-based buffer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] FreeBSD Kernel (FreeBSD 10.2 x64) - sendmsg Kernel Heap Overflow (PoC) Exploit) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-1887 was patched at 2024-05-15
957.
Denial of Service - Unknown Product (CVE-2016-2233) - High [422]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC servers to cause a denial of service (crash) via a large number of options in a CAP LS message.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Hexchat IRC Client 2.11.0 CAP LS Handling Buffer Overflow, [exploitpack] Hexchat IRC Client 2.11.0 - CAP LS Handling Buffer Overflow, [zdt] Hexchat IRC Client 2.11.0 - CAP LS Handling Buffer Overflow, [exploitdb] Hexchat IRC Client 2.11.0 - CAP LS Handling Buffer Overflow) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-2233 was patched at 2024-05-15
958.
Denial of Service - Unknown Product (CVE-2016-4957) - High [422]
Description: {'vulners_cve_data_all': 'ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Network Time Protocol Trap Crash Denial of Service Vulnerability(CVE-2016-9311), [seebug] Network Time Protocol Crypto-NAK Preemptible Association Denial of Service Vulnerability(CVE-2016-1547)) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-4957 was patched at 2024-05-15
959.
Denial of Service - Unknown Product (CVE-2016-6301) - High [422]
Description: {'vulners_cve_data_all': 'The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Phoenix Contact TC Router / TC Cloud Client Command Injection, [packetstorm] ZTE Mobile Hotspot MS910S Backdoor / Hardcoded Password, [packetstorm] Cisco Device Hardcoded Credentials / GNU glibc / BusyBox, [packetstorm] WAGO 852 Industrial Managed Switch Series Code Execution / Hardcoded Credentials) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-6301 was patched at 2024-05-15
960.
Denial of Service - Unknown Product (CVE-2016-9036) - High [422]
Description: {'vulners_cve_data_all': 'An exploitable incorrect return value vulnerability exists in the mp_check function of Tarantool's Msgpuck library 1.0.3. A specially crafted packet can cause the mp_check function to incorrectly return success when trying to check if decoding a map16 packet will read outside the bounds of a buffer, resulting in a denial of service vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Tarantool Msgpuck mp_check Denial Of Service Vulnerability(CVE-2016-9036)) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-9036 was patched at 2024-05-15
961.
Denial of Service - Unknown Product (CVE-2016-9037) - High [422]
Description: {'vulners_cve_data_all': 'An exploitable out-of-bounds array access vulnerability exists in the xrow_header_decode function of Tarantool 1.7.2.0-g8e92715. A specially crafted packet can cause the function to access an element outside the bounds of a global array that is used to determine the type of the specified key's value. This can lead to an out of bounds read within the context of the server. An attacker who exploits this vulnerability can cause a denial of service vulnerability on the server.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Tarantool Key-type Denial Of Service Vulnerability(CVE-2016-9037)) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-9037 was patched at 2024-05-15
962.
Denial of Service - Unknown Product (CVE-2017-16114) - High [422]
Description: {'vulners_cve_data_all': 'The marked module is vulnerable to a regular expression denial of service. Based on the information published in the public issue, 1k characters can block for around 6 seconds.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-16114 was patched at 2024-05-15
963.
Denial of Service - Unknown Product (CVE-2017-2893) - High [422]
Description: {'vulners_cve_data_all': 'An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. An MQTT SUBSCRIBE packet can cause a NULL pointer dereference leading to server crash and denial of service. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Cesanta Mongoose MQTT SUBSCRIBE Command Denial Of Service(CVE-2017-2893)) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2893 was patched at 2024-05-15
964.
Denial of Service - Unknown Product (CVE-2017-7478) - High [422]
Description: {'vulners_cve_data_all': 'OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] OpenVPN 2.4.0 Denial Of Service, [zdt] OpenVPN 2.4.0 - Unauthenticated Denial of Service Exploit) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-7478 was patched at 2024-05-15
965.
Denial of Service - Unknown Product (CVE-2017-9872) - High [422]
Description: {'vulners_cve_data_all': 'The III_dequantize_sample function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-9872 was patched at 2024-05-15
966.
Denial of Service - Unknown Product (CVE-2018-0491) - High [422]
Description: {'vulners_cve_data_all': 'A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a channel to be added more than once in the pending list.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Tor Browser < 0.3.2.10 - Use After Free (PoC ) Exploit, [packetstorm] Tor Browser 0.3.2.x Use-After-Free, [exploitdb] Tor Browser < 0.3.2.10 - Use After Free (PoC)) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-0491 was patched at 2024-05-15
967.
Denial of Service - Unknown Product (CVE-2019-1010239) - High [422]
Description: {'vulners_cve_data_all': 'DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSON_GetObjectItemCaseSensitive() function. The attack vector is: crafted json file. The fixed version is: 1.7.9 and later.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-1010239 was patched at 2024-05-15
968.
Denial of Service - Unknown Product (CVE-2020-13574) - High [422]
Description: {'vulners_cve_data_all': 'A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-13574 was patched at 2024-05-15
969.
Denial of Service - Unknown Product (CVE-2020-13575) - High [422]
Description: {'vulners_cve_data_all': 'A denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-13575 was patched at 2024-05-15
970.
Denial of Service - Unknown Product (CVE-2020-13577) - High [422]
Description: {'vulners_cve_data_all': 'A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-13577 was patched at 2024-05-15
971.
Denial of Service - Unknown Product (CVE-2020-13578) - High [422]
Description: {'vulners_cve_data_all': 'A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-13578 was patched at 2024-05-15
972.
Denial of Service - Unknown Product (CVE-2020-18831) - High [422]
Description: {'vulners_cve_data_all': 'Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-18831 was patched at 2024-05-15
973.
Denial of Service - Unknown Product (CVE-2020-22885) - High [422]
Description: {'vulners_cve_data_all': 'Buffer overflow vulnerability in mujs before 1.0.8 due to recursion in the GC scanning phase, allows remote attackers to cause a denial of service.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-22885 was patched at 2024-05-15
974.
Denial of Service - Unknown Product (CVE-2020-22886) - High [422]
Description: {'vulners_cve_data_all': 'Buffer overflow vulnerability in function jsG_markobject in jsgc.c in mujs before 1.0.8, allows remote attackers to cause a denial of service.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-22886 was patched at 2024-05-15
975.
Denial of Service - Unknown Product (CVE-2020-23308) - High [422]
Description: {'vulners_cve_data_all': 'There is an Assertion 'context_p->stack_top_uint8 == LEXER_EXPRESSION_START' at js-parser-expr.c:3565 in parser_parse_expression in JerryScript 2.2.0.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23308 was patched at 2024-05-15
976.
Denial of Service - Unknown Product (CVE-2020-23309) - High [422]
Description: {'vulners_cve_data_all': 'There is an Assertion 'context_p->stack_depth == context_p->context_stack_depth' failed at js-parser-statm.c:2756 in parser_parse_statements in JerryScript 2.2.0.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23309 was patched at 2024-05-15
977.
Denial of Service - Unknown Product (CVE-2020-23310) - High [422]
Description: {'vulners_cve_data_all': 'There is an Assertion 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at js-parser-statm.c:733 in parser_parse_function_statement in JerryScript 2.2.0.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23310 was patched at 2024-05-15
978.
Denial of Service - Unknown Product (CVE-2020-23311) - High [422]
Description: {'vulners_cve_data_all': 'There is an Assertion 'context_p->token.type == LEXER_RIGHT_BRACE || context_p->token.type == LEXER_ASSIGN || context_p->token.type == LEXER_COMMA' failed at js-parser-expr.c:3230 in parser_parse_object_initializer in JerryScript 2.2.0.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23311 was patched at 2024-05-15
979.
Denial of Service - Unknown Product (CVE-2020-23312) - High [422]
Description: {'vulners_cve_data_all': 'There is an Assertion 'context.status_flags & PARSER_SCANNING_SUCCESSFUL' failed at js-parser.c:2185 in parser_parse_source in JerryScript 2.2.0.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23312 was patched at 2024-05-15
980.
Denial of Service - Unknown Product (CVE-2020-23313) - High [422]
Description: {'vulners_cve_data_all': 'There is an Assertion 'scope_stack_p > context_p->scope_stack_p' failed at js-scanner-util.c:2510 in scanner_literal_is_created in JerryScript 2.2.0', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23313 was patched at 2024-05-15
981.
Denial of Service - Unknown Product (CVE-2020-23314) - High [422]
Description: {'vulners_cve_data_all': 'There is an Assertion 'block_found' failed at js-parser-statm.c:2003 parser_parse_try_statement_end in JerryScript 2.2.0.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23314 was patched at 2024-05-15
982.
Denial of Service - Unknown Product (CVE-2020-23319) - High [422]
Description: {'vulners_cve_data_all': 'There is an Assertion in '(flags >> CBC_STACK_ADJUST_SHIFT) >= CBC_STACK_ADJUST_BASE || (CBC_STACK_ADJUST_BASE - (flags >> CBC_STACK_ADJUST_SHIFT)) <= context_p->stack_depth' in parser_emit_cbc_backward_branch in JerryScript 2.2.0.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23319 was patched at 2024-05-15
983.
Denial of Service - Unknown Product (CVE-2020-23320) - High [422]
Description: {'vulners_cve_data_all': 'There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' in parser_parse_function_arguments in JerryScript 2.2.0.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23320 was patched at 2024-05-15
984.
Denial of Service - Unknown Product (CVE-2020-23322) - High [422]
Description: {'vulners_cve_data_all': 'There is an Assertion in 'context_p->token.type == LEXER_RIGHT_BRACE || context_p->token.type == LEXER_ASSIGN || context_p->token.type == LEXER_COMMA' in parser_parse_object_initializer in JerryScript 2.2.0.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23322 was patched at 2024-05-15
985.
Denial of Service - Unknown Product (CVE-2020-36420) - High [422]
Description: {'vulners_cve_data_all': 'Polipo through 1.1.1, when NDEBUG is omitted, allows denial of service via a reachable assertion during parsing of a malformed Range header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-36420 was patched at 2024-05-15
986.
Denial of Service - Unknown Product (CVE-2021-28302) - High [422]
Description: {'vulners_cve_data_all': 'A stack overflow in pupnp before version 1.14.5 can cause the denial of service through the Parser_parseDocument() function. ixmlNode_free() will release a child node recursively, which will consume stack space and lead to a crash.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-28302 was patched at 2024-05-15
987.
Denial of Service - Unknown Product (CVE-2021-28903) - High [422]
Description: {'vulners_cve_data_all': 'A stack overflow in libyang <= v1.0.225 can cause a denial of service through function lyxml_parse_mem(). lyxml_parse_elem() function will be called recursively, which will consume stack space and lead to crash.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-28903 was patched at 2024-05-15
988.
Denial of Service - Unknown Product (CVE-2021-28905) - High [422]
Description: {'vulners_cve_data_all': 'In function lys_node_free() in libyang <= v1.0.225, it asserts that the value of node->module can't be NULL. But in some cases, node->module can be null, which triggers a reachable assertion (CWE-617).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-28905 was patched at 2024-05-15
989.
Denial of Service - Unknown Product (CVE-2021-31155) - High [422]
Description: {'vulners_cve_data_all': 'Failure to normalize the umask in please before 0.4 allows a local attacker to gain full root privileges if they are allowed to execute at least one command.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-31155 was patched at 2024-05-15
990.
Denial of Service - Unknown Product (CVE-2021-34555) - High [422]
Description: {'vulners_cve_data_all': 'OpenDMARC 1.4.1 and 1.4.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a multi-value From header field.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-34555 was patched at 2024-05-15
991.
Denial of Service - Unknown Product (CVE-2021-37501) - High [422]
Description: {'vulners_cve_data_all': 'Buffer Overflow vulnerability in HDFGroup hdf5-h5dump 1.12.0 through 1.13.0 allows attackers to cause a denial of service via h5tools_str_sprint in /hdf5/tools/lib/h5tools_str.c.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-37501 was patched at 2024-05-15
992.
Denial of Service - Unknown Product (CVE-2022-21680) - High [422]
Description: {'vulners_cve_data_all': 'Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markdown through a vulnerable version of marked and does not use a worker with a time limit may be affected. This issue is patched in version 4.0.10. As a workaround, avoid running untrusted markdown through marked or run marked on a worker thread and set a reasonable time limit to prevent draining resources.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-21680 was patched at 2024-05-15
993.
Denial of Service - Unknown Product (CVE-2022-21681) - High [422]
Description: {'vulners_cve_data_all': 'Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cause catastrophic backtracking against some strings and lead to a denial of service (DoS). Anyone who runs untrusted markdown through a vulnerable version of marked and does not use a worker with a time limit may be affected. This issue is patched in version 4.0.10. As a workaround, avoid running untrusted markdown through marked or run marked on a worker thread and set a reasonable time limit to prevent draining resources.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-21681 was patched at 2024-05-15
994.
Denial of Service - Unknown Product (CVE-2022-25844) - High [422]
Description: {'vulners_cve_data_all': 'The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. **Note:** 1) This package has been deprecated and is no longer maintained. 2) The vulnerable versions are 1.7.0 and higher.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-25844 was patched at 2024-05-15
995.
Denial of Service - Unknown Product (CVE-2022-30780) - High [422]
Description: {'vulners_cve_data_all': 'Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Incorrect Calculation in Lighttpd) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-30780 was patched at 2024-05-15
996.
Denial of Service - Unknown Product (CVE-2022-31394) - High [422]
Description: {'vulners_cve_data_all': 'Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party software, allowing attackers to perform HTTP2 attacks.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-31394 was patched at 2024-05-15
997.
Denial of Service - Unknown Product (CVE-2022-41409) - High [422]
Description: {'vulners_cve_data_all': 'Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified impacts via negative input.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-41409 was patched at 2024-05-15
998.
Denial of Service - Unknown Product (CVE-2023-26964) - High [422]
Description: {'vulners_cve_data_all': 'An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the memory and CPU usage are high which can lead to a Denial of Service (DoS).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-26964 was patched at 2024-05-15
999.
Denial of Service - Unknown Product (CVE-2023-27786) - High [422]
Description: {'vulners_cve_data_all': 'An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the macinstring function.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-27786 was patched at 2024-05-15
1000.
Denial of Service - Unknown Product (CVE-2023-34623) - High [422]
Description: {'vulners_cve_data_all': 'An issue was discovered jtidy thru r938 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-34623 was patched at 2024-05-15
redos: CVE-2023-34623 was patched at 2024-06-06
1001.
Denial of Service - Unknown Product (CVE-2023-43642) - High [422]
Description: {'vulners_cve_data_all': 'snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attacks when decompressing data with a too large chunk size. Due to missing upper bound check on chunk length, an unrecoverable fatal error can occur. All versions of snappy-java including the latest released version 1.1.10.3 are vulnerable to this issue. A fix has been introduced in commit `9f8c3cf74` which will be included in the 1.1.10.4 release. Users are advised to upgrade. Users unable to upgrade should only accept compressed data from trusted sources.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-43642 was patched at 2024-05-15
1002.
Denial of Service - Unknown Product (CVE-2023-50980) - High [422]
Description: {'vulners_cve_data_all': 'gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data for an F(2^m) curve, if the degree of each term in the polynomial is not strictly decreasing.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-50980 was patched at 2024-05-15
1003.
Denial of Service - Unknown Product (CVE-2023-52355) - High [422]
Description: {'vulners_cve_data_all': 'An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-52355 was patched at 2024-05-15
1004.
Denial of Service - Unknown Product (CVE-2024-21490) - High [422]
Description: {'vulners_cve_data_all': 'This affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service. \r\r\r**Note:**\r\rThis package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-21490 was patched at 2024-05-15
1005.
Denial of Service - Unknown Product (CVE-2024-24814) - High [422]
Description: {'vulners_cve_data_all': 'mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validation on mod_auth_openidc_session_chunks cookie value makes the server vulnerable to a denial of service (DoS) attack. An internal security audit has been conducted and the reviewers found that if they manipulated the value of the mod_auth_openidc_session_chunks cookie to a very large integer, like 99999999, the server struggles with the request for a long time and finally gets back with a 500 error. Making a few requests of this kind caused our server to become unresponsive. Attackers can craft requests that would make the server work very hard (and possibly become unresponsive) and/or crash with minimal effort. This issue has been addressed in version 2.4.15.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-24814 was patched at 2024-05-15
1006.
Information Disclosure - Unknown Product (CVE-2012-1257) - High [422]
Description: {'vulners_cve_data_all': 'Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] libpurple 2.8.10 - OTR Information Disclosure, [exploitdb] libpurple 2.8.10 - OTR Information Disclosure) | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1257 was patched at 2024-05-15
1007.
Information Disclosure - Unknown Product (CVE-2020-18972) - High [422]
Description: {'vulners_cve_data_all': 'Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-18972 was patched at 2024-05-15
1008.
Path Traversal - Unknown Product (CVE-2017-10974) - High [422]
Description: {'vulners_cve_data_all': 'Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Yaws 1.91 Unauthenticated Remote File Disclosure, [zdt] Yaws 1.91 - Remote File Disclosure Vulnerability, [exploitpack] Yaws 1.91 - Remote File Disclosure, [exploitdb] Yaws 1.91 - Remote File Disclosure) | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-10974 was patched at 2024-05-15
1009.
Path Traversal - Unknown Product (CVE-2017-12938) - High [422]
Description: {'vulners_cve_data_all': 'UnRAR before 5.5.7 allows remote attackers to bypass a directory-traversal protection mechanism via vectors involving a symlink to the . directory, a symlink to the .. directory, and a regular file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-12938 was patched at 2024-05-15
1010.
Path Traversal - Unknown Product (CVE-2022-24716) - High [422]
Description: {'vulners_cve_data_all': 'Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Path Traversal in Icinga Icinga Web 2, [githubexploit] Exploit for Path Traversal in Icinga Icinga Web 2, [githubexploit] Exploit for Path Traversal in Icinga Icinga Web 2, [githubexploit] Exploit for Path Traversal in Icinga Icinga Web 2, [githubexploit] Exploit for Path Traversal in Icinga Icinga Web 2, [packetstorm] Icinga Web 2.10 Arbitrary File Disclosure, [zdt] Icinga Web 2.10 - Arbitrary File Disclosure Exploit, [exploitdb] Icinga Web 2.10 - Arbitrary File Disclosure) | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-24716 was patched at 2024-05-15
1011.
Path Traversal - Unknown Product (CVE-2024-21633) - High [422]
Description: {'vulners_cve_data_all': 'Apktool is a tool for reverse engineering Android APK files. In versions 2.9.1 and prior, Apktool infers resource files' output path according to their resource names which can be manipulated by attacker to place files at desired location on the system Apktool runs on. Affected environments are those in which an attacker may write/overwrite any file that user has write access, and either user name is known or cwd is under user folder. Commit d348c43b24a9de350ff6e5bd610545a10c1fc712 contains a patch for this issue.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-21633 was patched at 2024-05-15
1012.
Security Feature Bypass - Unknown Product (CVE-2010-2156) - High [422]
Description: {'vulners_cve_data_all': 'ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-2156 was patched at 2024-05-15
1013.
Security Feature Bypass - Unknown Product (CVE-2021-28170) - High [422]
Description: {'vulners_cve_data_all': 'In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-28170 was patched at 2024-05-15
1014.
Unknown Vulnerability Type - Perl (CVE-2007-6610) - High [421]
Description: {'vulners_cve_data_all': 'unp 1.0.12, and other versions before 1.0.14, does not properly escape file names, which might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename argument. NOTE: this might only be a vulnerability when unp is invoked by a third party product.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] unp文件名远程任意Shell命令注入漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-6610 was patched at 2024-05-15
1015.
Unknown Vulnerability Type - Perl (CVE-2008-3910) - High [421]
Description: {'vulners_cve_data_all': 'dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns_decode function, which allows remote attackers to overwrite a buffer and have unspecified other impact.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Dns2tcp远程缓冲区溢出漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3910 was patched at 2024-05-15
1016.
Unknown Vulnerability Type - Perl (CVE-2016-5734) - High [421]
Description: {'vulners_cve_data_all': 'phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote attackers to execute arbitrary PHP code via a crafted string, as demonstrated by the table search-and-replace implementation.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] phpMyAdmin 4.x Remote Code Execution, [seebug] PhpMyAdmin 4.3.0—4.6.2 authorized users remote command execution vulnerability, [zdt] phpMyAdmin 4.x Remote Code Execution Exploit, [zdt] phpMyAdmin 4.6.2 - Authenticated Remote Code Execution, [exploitpack] phpMyAdmin 4.6.2 - (Authenticated) Remote Code Execution, [exploitdb] phpMyAdmin 4.6.2 - (Authenticated) Remote Code Execution) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-5734 was patched at 2024-05-15
1017.
Unknown Vulnerability Type - Perl (CVE-2020-7746) - High [421]
Description: {'vulners_cve_data_all': 'This affects the package chart.js before 2.9.4. The options parameter is not properly sanitized when it is processed. When the options are processed, the existing options (or the defaults options) are deeply merged with provided options. However, during this operation, the keys of the object being set are not checked, leading to a prototype pollution.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-7746 was patched at 2024-05-15
1018.
Unknown Vulnerability Type - Python (CVE-2013-2167) - High [421]
Description: {'vulners_cve_data_all': 'python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenStack python-keystoneclient 安全绕过漏洞(CVE-2013-2167)) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-2167 was patched at 2024-05-15
1019.
Authentication Bypass - Linux Kernel (CVE-2020-15852) - High [420]
Description: {'vulners_cve_data_all': 'An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O port permissions of an unrelated task. This occurs because tss_invalidate_io_bitmap mishandling causes a loss of synchronization between the I/O bitmaps of TSS and Xen, aka CID-cadfad870154.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-15852 was patched at 2024-05-15
1020.
Authentication Bypass - Sudo (CVE-2020-8933) - High [420]
Description: {'vulners_cve_data_all': 'A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using the membership to the "lxd" group, an attacker can attach host devices and filesystems. Within an lxc container, it is possible to attach the host OS filesystem and modify /etc/sudoers to then gain administrative privileges. All images created after 2020-May-07 (20200507) are fixed, and if you cannot update, we recommend you edit /etc/group/security.conf and remove the "lxd" user from the OS Login entry.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.9 | 14 | Sudo is a program for Unix-like computer operating systems that allows users to run programs with the security privileges of another user | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-8933 was patched at 2024-05-15
1021.
Authentication Bypass - Windows Kernel (CVE-2022-28184) - High [420]
Description: {'vulners_cve_data_all': 'NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can access administrator- privileged registers, which may lead to denial of service, information disclosure, and data tampering.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.9 | 14 | Windows Kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-28184 was patched at 2024-05-15
1022.
Arbitrary File Writing - Unknown Product (CVE-2009-1297) - High [419]
Description: {'vulners_cve_data_all': 'iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file that has a predictable name.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] SUSE Linux 'scsi_discovery tool'不安全临时文件建立漏洞) | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1297 was patched at 2024-05-15
1023.
Remote Code Execution - Google Chrome (CVE-2021-30559) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30559 was patched at 2024-05-15
1024.
Remote Code Execution - Google Chrome (CVE-2021-30565) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30565 was patched at 2024-05-15
1025.
Remote Code Execution - Google Chrome (CVE-2021-30575) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30575 was patched at 2024-05-15
1026.
Remote Code Execution - Google Chrome (CVE-2021-30592) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30592 was patched at 2024-05-15
1027.
Remote Code Execution - Google Chrome (CVE-2021-30598) - High [419]
Description: Type confusion in V8 in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30598 was patched at 2024-05-15
1028.
Remote Code Execution - Google Chrome (CVE-2021-30599) - High [419]
Description: Type confusion in V8 in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30599 was patched at 2024-05-15
1029.
Remote Code Execution - Mozilla Firefox (CVE-2006-0748) - High [419]
Description: Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-0748 was patched at 2024-05-15
1030.
Remote Code Execution - Mozilla Firefox (CVE-2006-0749) - High [419]
Description: nsHTMLContentSink.cpp in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-0749 was patched at 2024-05-15
1031.
Remote Code Execution - Mozilla Firefox (CVE-2006-1726) - High [419]
Description: Unspecified vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-1726 was patched at 2024-05-15
1032.
Remote Code Execution - Mozilla Firefox (CVE-2006-1728) - High [419]
Description: Unspecified vulnerability in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-1728 was patched at 2024-05-15
1033.
Remote Code Execution - Mozilla Firefox (CVE-2006-1730) - High [419]
Description: Integer overflow in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-1730 was patched at 2024-05-15
1034.
Remote Code Execution - Mozilla Firefox (CVE-2006-1735) - High [419]
Description: Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-1735 was patched at 2024-05-15
1035.
Remote Code Execution - Mozilla Firefox (CVE-2006-1739) - High [419]
Description: The CSS border-rendering code in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-1739 was patched at 2024-05-15
1036.
Remote Code Execution - Mozilla Firefox (CVE-2006-2779) - High [419]
Description: Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-2779 was patched at 2024-05-15
1037.
Remote Code Execution - Mozilla Firefox (CVE-2006-2780) - High [419]
Description: Integer overflow in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-2780 was patched at 2024-05-15
1038.
Remote Code Execution - Mozilla Firefox (CVE-2006-4565) - High [419]
Description: Heap-based buffer overflow in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4565 was patched at 2024-05-15
1039.
Remote Code Execution - Mozilla Firefox (CVE-2006-6504) - High [419]
Description: Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-6504 was patched at 2024-05-15
1040.
Remote Code Execution - Mozilla Firefox (CVE-2009-3388) - High [419]
Description: liboggplay in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3388 was patched at 2024-05-15
1041.
Remote Code Execution - Mozilla Firefox (CVE-2009-3389) - High [419]
Description: Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3389 was patched at 2024-05-15
1042.
Remote Code Execution - Mozilla Firefox (CVE-2012-1128) - High [419]
Description: FreeType before 2.4.9, as used in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1128 was patched at 2024-05-15
1043.
Remote Code Execution - Mozilla Firefox (CVE-2012-1129) - High [419]
Description: FreeType before 2.4.9, as used in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1129 was patched at 2024-05-15
1044.
Remote Code Execution - Mozilla Firefox (CVE-2012-1133) - High [419]
Description: FreeType before 2.4.9, as used in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1133 was patched at 2024-05-15
1045.
Remote Code Execution - Mozilla Firefox (CVE-2012-1135) - High [419]
Description: FreeType before 2.4.9, as used in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1135 was patched at 2024-05-15
1046.
Remote Code Execution - Mozilla Firefox (CVE-2012-1138) - High [419]
Description: FreeType before 2.4.9, as used in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1138 was patched at 2024-05-15
1047.
Remote Code Execution - PHP (CVE-2022-25018) - High [419]
Description: Pluxml v5.8.7 was discovered to allow attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-25018 was patched at 2024-05-15
1048.
Remote Code Execution - PHP (CVE-2023-43655) - High [419]
Description: Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-43655 was patched at 2024-05-15
1049.
Remote Code Execution - Safari (CVE-2009-0945) - High [419]
Description: Array index error in the insertItemBefore method in WebKit, as used in Apple
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0945 was patched at 2024-05-15
1050.
Remote Code Execution - Safari (CVE-2009-1725) - High [419]
Description: WebKit in Apple
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1725 was patched at 2024-05-15
1051.
Remote Code Execution - Safari (CVE-2016-4692) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-4692 was patched at 2024-05-15
1052.
Remote Code Execution - Safari (CVE-2016-7587) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-7587 was patched at 2024-05-15
1053.
Remote Code Execution - Safari (CVE-2016-7610) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-7610 was patched at 2024-05-15
1054.
Remote Code Execution - Safari (CVE-2016-7611) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-7611 was patched at 2024-05-15
1055.
Remote Code Execution - Safari (CVE-2016-7640) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-7640 was patched at 2024-05-15
1056.
Remote Code Execution - Safari (CVE-2016-7642) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-7642 was patched at 2024-05-15
1057.
Remote Code Execution - Safari (CVE-2016-7646) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-7646 was patched at 2024-05-15
1058.
Remote Code Execution - Safari (CVE-2016-7648) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-7648 was patched at 2024-05-15
1059.
Remote Code Execution - Safari (CVE-2016-7649) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-7649 was patched at 2024-05-15
1060.
Remote Code Execution - Safari (CVE-2017-2506) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2506 was patched at 2024-05-15
1061.
Remote Code Execution - Safari (CVE-2017-2525) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2525 was patched at 2024-05-15
1062.
Remote Code Execution - Safari (CVE-2017-2526) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2526 was patched at 2024-05-15
1063.
Remote Code Execution - Safari (CVE-2017-2530) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2530 was patched at 2024-05-15
1064.
Remote Code Execution - Safari (CVE-2017-2544) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2544 was patched at 2024-05-15
1065.
Remote Code Execution - Safari (CVE-2017-7012) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-7012 was patched at 2024-05-15
1066.
Remote Code Execution - Safari (CVE-2017-7019) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-7019 was patched at 2024-05-15
1067.
Remote Code Execution - Safari (CVE-2017-7020) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 10.3.3 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-7020 was patched at 2024-05-15
1068.
Remote Code Execution - Safari (CVE-2017-7157) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 11.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-7157 was patched at 2024-05-15
1069.
Remote Code Execution - Safari (CVE-2018-4201) - High [419]
Description: An issue was discovered in certain Apple products. iOS before 11.4 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-4201 was patched at 2024-05-15
1070.
Remote Code Execution - Safari (CVE-2019-6201) - High [419]
Description: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-6201 was patched at 2024-05-15
1071.
Remote Code Execution - Safari (CVE-2019-6216) - High [419]
Description: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-6216 was patched at 2024-05-15
1072.
Remote Code Execution - Safari (CVE-2019-6217) - High [419]
Description: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-6217 was patched at 2024-05-15
1073.
Remote Code Execution - Safari (CVE-2019-6226) - High [419]
Description: Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-6226 was patched at 2024-05-15
1074.
Remote Code Execution - Safari (CVE-2019-6227) - High [419]
Description: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, watchOS 5.1.3,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-6227 was patched at 2024-05-15
1075.
Remote Code Execution - Safari (CVE-2019-6233) - High [419]
Description: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-6233 was patched at 2024-05-15
1076.
Remote Code Execution - Safari (CVE-2019-6234) - High [419]
Description: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-6234 was patched at 2024-05-15
1077.
Remote Code Execution - Visual Basic for Applications (CVE-2008-5050) - High [419]
Description: Off-by-one error in the get_unicode_name function (libclamav/
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Visual Basic for Applications is a computer programming language developed and owned by Microsoft | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5050 was patched at 2024-05-15
1078.
Unknown Vulnerability Type - OpenSSH (CVE-2004-2760) - High [419]
Description: {'vulners_cve_data_all': 'sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the correct password, but leaves the connection open after an attempt with an incorrect password, which makes it easier for remote attackers to guess the password by observing the connection state, a different vulnerability than CVE-2003-0190. NOTE: it could be argued that in most environments, this does not cross privilege boundaries without requiring leverage of a separate vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Portable OpenSSH 3.6.1p-PAM4.1-SuSE - Timing Attack, [packetstorm] openssh-timing.txt, [seebug] Portable OpenSSH <= 3.6.1p-PAM / 4.1-SUSE Timing Attack Exploit, [seebug] Portable OpenSSH <= 3.6.1p-PAM / 4.1-SUSE Timing Attack Exploit, [seebug] Portable OpenSSH <= 3.6.1p-PAM / 4.1-SUSE Timing Attack Exploit, [exploitdb] Portable OpenSSH 3.6.1p-PAM/4.1-SuSE - Timing Attack) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-2760 was patched at 2024-05-15
1079.
Unknown Vulnerability Type - OpenSSH (CVE-2008-1483) - High [419]
Description: {'vulners_cve_data_all': 'OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port, as demonstrated by opening TCP port 6010 (IPv4) and sniffing a cookie sent by Emacs.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenSSH X连接会话劫持漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1483 was patched at 2024-05-15
1080.
Unknown Vulnerability Type - OpenSSL (CVE-2015-1793) - High [419]
Description: {'vulners_cve_data_all': 'The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] OpenSSL Alternative Chains Certificate Forgery, [packetstorm] OpenSSL Alternative Chains Certificate Forgery MITM Proxy, [packetstorm] Orion Elite Hidden IP Browser Pro 7.9 OpenSSL / Tor / Man-In-The-Middle, [zdt] OpenSSL Alternative Chains Certificate Forgery Vulnerability, [zdt] OpenSSL 1.0.2c Alternative chains certificate forgery Vulnerability) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-1793 was patched at 2024-05-15
1081.
Unknown Vulnerability Type - PHP (CVE-2007-5976) - High [419]
Description: {'vulners_cve_data_all': 'SQL injection vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to execute arbitrary SQL commands via the db parameter.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin DB_Create.PHP多个输入验证漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-5976 was patched at 2024-05-15
1082.
Unknown Vulnerability Type - PHP (CVE-2007-6318) - High [419]
Description: {'vulners_cve_data_all': 'SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s parameter, when DB_CHARSET is set to (1) Big5, (2) GBK, or possibly other character set encodings that support a "\\" in a multibyte character.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] WordPress wp-db.php Character Set SQL Injection Vulnerability) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-6318 was patched at 2024-05-15
1083.
Unknown Vulnerability Type - PHP (CVE-2009-4111) - High [419]
Description: {'vulners_cve_data_all': 'Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remote attackers to read and write arbitrary files via a crafted $recipients parameter, and possibly other parameters, a different vulnerability than CVE-2009-4023.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] PEAR Mail软件包Recipient参数注入漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4111 was patched at 2024-05-15
1084.
Unknown Vulnerability Type - PHP (CVE-2013-6275) - High [419]
Description: {'vulners_cve_data_all': 'Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Horde Groupware Web Mail Edition 5.1.2 - CSRF Vulnerability, [packetstorm] Horde Groupware Web Mail 5.1.2 Cross Site Request Forgery, [exploitpack] Horde Groupware Web Mail Edition 5.1.2 - Cross-Site Request Forgery (1), [exploitdb] Horde Groupware Web Mail Edition 5.1.2 - Cross-Site Request Forgery (1)) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-6275 was patched at 2024-05-15
1085.
Unknown Vulnerability Type - PHP (CVE-2016-6897) - High [419]
Description: {'vulners_cve_data_all': 'Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] WordPress 4.5.3 - Directory Traversal Denial of Service, [zdt] WordPress 4.5.3 - Directory Traversal / Denial of Service, [exploitdb] WordPress Core 4.5.3 - Directory Traversal / Denial of Service, [metasploit] WordPress Traversal Directory DoS) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-6897 was patched at 2024-05-15
1086.
Unknown Vulnerability Type - Safari (CVE-2009-1703) - High [419]
Description: {'vulners_cve_data_all': 'WebKit in Apple Safari before 4.0 does not prevent references to file: URLs within (1) audio and (2) video elements, which allows remote attackers to determine the existence of arbitrary files via a crafted HTML document.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1703 was patched at 2024-05-15
1087.
Unknown Vulnerability Type - Safari (CVE-2009-1713) - High [419]
Description: {'vulners_cve_data_all': 'The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from different security zones via unspecified vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1713 was patched at 2024-05-15
1088.
Unknown Vulnerability Type - Safari (CVE-2009-2816) - High [419]
Description: {'vulners_cve_data_all': 'The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] WebKit Preflight请求同源策略绕过漏洞, [seebug] Safari 4.0.4版本修复多个安全漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2816 was patched at 2024-05-15
1089.
Command Injection - HTTP/2 (CVE-2021-21299) - High [418]
Description: hyper is an open-source HTTP library for Rust (crates.io). In hyper from version 0.12.0 and before versions 0.13.10 and 0.14.3 there is a vulnerability that can enable a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.9 | 14 | HTTP/2 is a major revision of the HTTP network protocol used by the World Wide Web | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-21299 was patched at 2024-05-15
1090.
Denial of Service - Git (CVE-2012-2657) - High [417]
Description: Buffer overflow in the SQLDriverConnect function in unixODBC 2.0.10, 2.3.1, and earlier allows local users to cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | Git | |
| 0.2 | 10 | CVSS Base Score is 2.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-2657 was patched at 2024-05-15
1091.
Denial of Service - Git (CVE-2012-2658) - High [417]
Description: Buffer overflow in the SQLDriverConnect function in unixODBC 2.3.1 allows local users to cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | Git | |
| 0.2 | 10 | CVSS Base Score is 2.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-2658 was patched at 2024-05-15
1092.
Cross Site Scripting - Unknown Product (CVE-2012-6708) - High [416]
Description: {'vulners_cve_data_all': 'jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for the '<' character anywhere in the string, giving attackers more flexibility when attempting to construct a malicious payload. In fixed versions, jQuery only deems the input to be HTML if it explicitly starts with the '<' character, limiting exploitability only to attackers who can control the beginning of a string, which is far less common.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-6708 was patched at 2024-05-15
1093.
Cross Site Scripting - Unknown Product (CVE-2015-7579) - High [416]
Description: {'vulners_cve_data_all': 'Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via an HTML entity that is mishandled by the Rails::Html::FullSanitizer class.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Ruby on Rails rails-html-sanitizer XSS 漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-7579 was patched at 2024-05-15
1094.
Cross Site Scripting - Unknown Product (CVE-2017-12794) - High [416]
Description: {'vulners_cve_data_all': 'In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for the technical 500 debug page. Given the right circumstances, this allowed a cross-site scripting attack. This vulnerability shouldn't affect most production sites since you shouldn't run with "DEBUG = True" (which makes this page accessible) in your production settings.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-12794 was patched at 2024-05-15
1095.
Cross Site Scripting - Unknown Product (CVE-2018-12040) - High [416]
Description: {'vulners_cve_data_all': 'Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file= URI. NOTE: The vendor states "The XSS ... is in the web profiler, a tool that should never be deployed in production (so, we don't handle those issues as security issues).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] SensioLabs Symfony 3.3.6 Cross Site Scripting) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-12040 was patched at 2024-05-15
1096.
Cross Site Scripting - Unknown Product (CVE-2018-17960) - High [416]
Description: {'vulners_cve_data_all': 'CKEditor 4.x before 4.11.0 allows user-assisted XSS involving a source-mode paste.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-17960 was patched at 2024-05-15
1097.
Cross Site Scripting - Unknown Product (CVE-2018-6561) - High [416]
Description: {'vulners_cve_data_all': 'dijit.Editor in Dojo Toolkit 1.13 allows XSS via the onload attribute of an SVG element.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-6561 was patched at 2024-05-15
1098.
Cross Site Scripting - Unknown Product (CVE-2019-14862) - High [416]
Description: {'vulners_cve_data_all': 'There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Cross-site Scripting in Knockoutjs Knockout) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-14862 was patched at 2024-05-15
1099.
Cross Site Scripting - Unknown Product (CVE-2021-37833) - High [416]
Description: {'vulners_cve_data_all': 'A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitrary execution of JavaScript commands.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Cross-site Scripting in Digitaldruid Hoteldruid) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-37833 was patched at 2024-05-15
1100.
Cross Site Scripting - Unknown Product (CVE-2023-43643) - High [416]
Description: {'vulners_cve_data_all': 'AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to version 1.7.4, there is a potential for a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the `preserveComments` directive must be enabled in your policy file and also allow for certain tags at the same time. As a result, certain crafty inputs can result in elements in comment tags being interpreted as executable when using AntiSamy's sanitized output. This issue has been patched in AntiSamy 1.7.4 and later. ', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-43643 was patched at 2024-05-15
1101.
Cross Site Scripting - Unknown Product (CVE-2024-22119) - High [416]
Description: {'vulners_cve_data_all': 'The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-22119 was patched at 2024-05-15
1102.
Unknown Vulnerability Type - Kerberos (CVE-2010-0014) - High [416]
Description: {'vulners_cve_data_all': 'System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC is unreachable, allows physically proximate attackers to authenticate, via an arbitrary password, to the screen-locking program on a workstation that has any user's Kerberos ticket-granting ticket (TGT); and might allow remote attackers to bypass intended access restrictions via vectors involving an arbitrary password in conjunction with a valid TGT.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Fedora SSSD绕过Kerberos认证漏洞, [seebug] Fedora SSSD Kerberos验证安全绕过漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-0014 was patched at 2024-05-15
1103.
Remote Code Execution - Apache Traffic Server (CVE-2015-3249) - High [414]
Description: The HTTP/2 experimental feature in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | The Apache Traffic Server is a modular, high-performance reverse proxy and forward proxy server, generally comparable to Nginx and Squid | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-3249 was patched at 2024-05-15
1104.
Remote Code Execution - BIND (CVE-2014-9513) - High [414]
Description: Insecure use of temporary files in x
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-9513 was patched at 2024-05-15
1105.
Remote Code Execution - BIND (CVE-2019-14892) - High [414]
Description: A flaw was discovered in jackson-data
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-14892 was patched at 2024-05-15
1106.
Remote Code Execution - BIND (CVE-2019-14893) - High [414]
Description: A flaw was discovered in FasterXML jackson-data
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-14893 was patched at 2024-05-15
1107.
Remote Code Execution - BIND (CVE-2023-37895) - High [414]
Description: Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-37895 was patched at 2024-05-15
1108.
Remote Code Execution - Babel (CVE-2022-46291) - High [414]
Description: Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-46291 was patched at 2024-05-15
1109.
Remote Code Execution - QEMU (CVE-2009-3616) - High [414]
Description: Multiple use-after-free vulnerabilities in vnc.c in the VNC server in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | QEMU is a generic and open source machine & userspace emulator and virtualizer | |
| 1.0 | 10 | CVSS Base Score is 9.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3616 was patched at 2024-05-15
1110.
Remote Code Execution - QEMU (CVE-2019-12928) - High [414]
Description: The QMP migrate command in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | QEMU is a generic and open source machine & userspace emulator and virtualizer | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-12928 was patched at 2024-05-15
1111.
Remote Code Execution - QEMU (CVE-2019-12929) - High [414]
Description: The QMP guest_exec command in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | QEMU is a generic and open source machine & userspace emulator and virtualizer | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-12929 was patched at 2024-05-15
1112.
Remote Code Execution - SQLite (CVE-2017-2513) - High [414]
Description: An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | SQLite is a database engine written in the C programming language | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2513 was patched at 2024-05-15
1113.
Remote Code Execution - SQLite (CVE-2023-32697) - High [414]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | SQLite is a database engine written in the C programming language | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-32697 was patched at 2024-05-15
1114.
Remote Code Execution - iOS (CVE-2017-16082) - High [414]
Description: A
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-16082 was patched at 2024-05-15
1115.
Remote Code Execution - iOS (CVE-2024-21795) - High [414]
Description: A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The B
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-21795 was patched at 2024-05-15
1116.
Remote Code Execution - iOS (CVE-2024-21812) - High [414]
Description: An integer overflow vulnerability exists in the sopen_FAMOS_read functionality of The B
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-21812 was patched at 2024-05-15
1117.
Remote Code Execution - iOS (CVE-2024-22097) - High [414]
Description: A double-free vulnerability exists in the BrainVision Header Parsing functionality of The B
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-22097 was patched at 2024-05-15
1118.
Remote Code Execution - iOS (CVE-2024-23305) - High [414]
Description: An out-of-bounds write vulnerability exists in the BrainVisionMarker Parsing functionality of The B
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-23305 was patched at 2024-05-15
1119.
Remote Code Execution - iOS (CVE-2024-23310) - High [414]
Description: A use-after-free vulnerability exists in the sopen_FAMOS_read functionality of The B
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-23310 was patched at 2024-05-15
1120.
Remote Code Execution - iOS (CVE-2024-23313) - High [414]
Description: An integer underflow vulnerability exists in the sopen_FAMOS_read functionality of The B
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-23313 was patched at 2024-05-15
1121.
Remote Code Execution - iOS (CVE-2024-23606) - High [414]
Description: An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The B
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-23606 was patched at 2024-05-15
1122.
Remote Code Execution - iOS (CVE-2024-23809) - High [414]
Description: A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of The B
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-23809 was patched at 2024-05-15
1123.
Unknown Vulnerability Type - Curl (CVE-2006-2878) - High [414]
Description: {'vulners_cve_data_all': 'The spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" that is inserted into a regular expression that is processed by preg_replace with the /e (executable) modifier.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([canvas] Immunity Canvas: DOKUWIKI_EXEC) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Curl is a command-line tool for transferring data specified with URL syntax | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-2878 was patched at 2024-05-15
1124.
Command Injection - PHP (CVE-2023-26039) - High [413]
Description: ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an OS
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-26039 was patched at 2024-05-15
1125.
Security Feature Bypass - Google Chrome (CVE-2021-30571) - High [413]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30571 was patched at 2024-05-15
1126.
Remote Code Execution - Linux Kernel (CVE-2014-3183) - High [411]
Description: Heap-based buffer overflow in the logi_dj_ll_raw_request function in drivers/hid/hid-logitech-dj.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-3183 was patched at 2024-05-15
1127.
Remote Code Execution - Linux Kernel (CVE-2023-2006) - High [411]
Description: A race condition was found in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-2006 was patched at 2024-05-15
1128.
Remote Code Execution - Windows Kernel (CVE-2023-25512) - High [411]
Description: NVIDIA CUDA toolkit for Linux and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows Kernel | |
| 0.7 | 10 | CVSS Base Score is 6.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-25512 was patched at 2024-05-15
1129.
Remote Code Execution - Windows Kernel (CVE-2023-25513) - High [411]
Description: NVIDIA CUDA toolkit for Linux and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows Kernel | |
| 0.7 | 10 | CVSS Base Score is 6.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-25513 was patched at 2024-05-15
1130.
Remote Code Execution - Windows Kernel (CVE-2023-25514) - High [411]
Description: NVIDIA CUDA toolkit for Linux and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows Kernel | |
| 0.7 | 10 | CVSS Base Score is 6.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-25514 was patched at 2024-05-15
1131.
Unknown Vulnerability Type - Apache HTTP Server (CVE-2009-1191) - High [411]
Description: {'vulners_cve_data_all': 'mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apache mod_proxy_ajp信息泄露漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1191 was patched at 2024-05-15
1132.
Unknown Vulnerability Type - Sudo (CVE-2005-2959) - High [411]
Description: {'vulners_cve_data_all': 'Incomplete blacklist vulnerability in sudo 1.6.8 and earlier allows local users to gain privileges via the (1) SHELLOPTS and (2) PS4 environment variables before executing a bash script on behalf of another user, which are not cleared even though other variables are.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] sudo168p10.sh.txt) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | Sudo is a program for Unix-like computer operating systems that allows users to run programs with the security privileges of another user | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-2959 was patched at 2024-05-15
1133.
Denial of Service - Unknown Product (CVE-2008-1768) - High [410]
Description: {'vulners_cve_data_all': 'Multiple integer overflows in VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via the (1) MP4 demuxer, (2) Real demuxer, and (3) Cinepak codec, which triggers a buffer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] VLC媒体播放器MP及Cinepak解码器缓冲区溢出漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1768 was patched at 2024-05-15
1134.
Denial of Service - Unknown Product (CVE-2008-1769) - High [410]
Description: {'vulners_cve_data_all': 'VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via a crafted Cinepak file that triggers an out-of-bounds array access and memory corruption.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] VLC媒体播放器MP及Cinepak解码器缓冲区溢出漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1769 was patched at 2024-05-15
1135.
Denial of Service - Unknown Product (CVE-2013-2189) - High [410]
Description: {'vulners_cve_data_all': 'Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via invalid PLCF data in a DOC document file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apache OpenOffice 文档内存破坏漏洞(CVE-2013-2189)) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-2189 was patched at 2024-05-15
1136.
Denial of Service - Unknown Product (CVE-2013-4156) - High [410]
Description: {'vulners_cve_data_all': 'Apache OpenOffice.org (OOo) before 4.0 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted element in an OOXML document file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apache OpenOffice DOCM内存破坏漏洞(CVE-2013-4156)) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-4156 was patched at 2024-05-15
1137.
Denial of Service - Unknown Product (CVE-2014-0998) - High [410]
Description: {'vulners_cve_data_all': 'Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows local users to cause a denial of service (crash) and possibly gain privileges via a negative value in a VT_WAITACTIVE ioctl call, which triggers an array index error and out-of-bounds kernel memory access.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] FreeBSD Kernel Multiple Vulnerabilities, [packetstorm] FreeBSD Kernel Crash / Code Execution / Disclosure, [exploitpack] FreeBSD - Multiple Vulnerabilities, [exploitdb] FreeBSD - Multiple Vulnerabilities) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-0998 was patched at 2024-05-15
1138.
Denial of Service - Unknown Product (CVE-2015-7506) - High [410]
Description: {'vulners_cve_data_all': 'The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted LZW stream in a GIF file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Libnsgif 0.1.2 Stack Overflow / Out-Of-Bounds Read Exploit) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-7506 was patched at 2024-05-15
1139.
Denial of Service - Unknown Product (CVE-2016-10504) - High [410]
Description: {'vulners_cve_data_all': 'Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (application crash) via a crafted bmp file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] OpenJPEG - mqc.c Heap-Based Buffer Overflow Exploit) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-10504 was patched at 2024-05-15
1140.
Denial of Service - Unknown Product (CVE-2017-12950) - High [410]
Description: {'vulners_cve_data_all': 'The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities, [zdt] libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities, [exploitdb] libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-12950 was patched at 2024-05-15
1141.
Denial of Service - Unknown Product (CVE-2017-12951) - High [410]
Description: {'vulners_cve_data_all': 'The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted gig file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities, [zdt] libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities, [exploitdb] libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-12951 was patched at 2024-05-15
1142.
Denial of Service - Unknown Product (CVE-2017-12952) - High [410]
Description: {'vulners_cve_data_all': 'The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities, [zdt] libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities, [exploitdb] libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-12952 was patched at 2024-05-15
1143.
Denial of Service - Unknown Product (CVE-2017-12953) - High [410]
Description: {'vulners_cve_data_all': 'The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory write and application crash) via a crafted gig file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities, [exploitpack] libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities, [exploitdb] libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-12953 was patched at 2024-05-15
1144.
Denial of Service - Unknown Product (CVE-2017-12954) - High [410]
Description: {'vulners_cve_data_all': 'The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted gig file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities, [zdt] libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities, [exploitdb] libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-12954 was patched at 2024-05-15
1145.
Denial of Service - Unknown Product (CVE-2018-17438) - High [410]
Description: {'vulners_cve_data_all': 'A SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-17438 was patched at 2024-05-15
1146.
Denial of Service - Unknown Product (CVE-2018-20450) - High [410]
Description: {'vulners_cve_data_all': 'The read_MSAT function in ole.c in libxls 1.4.0 has a double free that allows attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2017-2897.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] libxls read_MSAT Code Execution Vulnerability(CVE-2017-2897)) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-20450 was patched at 2024-05-15
1147.
Denial of Service - Unknown Product (CVE-2019-20056) - High [410]
Description: {'vulners_cve_data_all': 'stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__shiftsigned.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-20056 was patched at 2024-05-15
1148.
Denial of Service - Unknown Product (CVE-2019-7148) - High [410]
Description: {'vulners_cve_data_all': 'An attempted excessive memory allocation was discovered in the function read_long_names in elf_begin.c in libelf in elfutils 0.174. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted elf input, which leads to an out-of-memory exception. NOTE: The maintainers believe this is not a real issue, but instead a "warning caused by ASAN because the allocation is big. By setting ASAN_OPTIONS=allocator_may_return_null=1 and running the reproducer, nothing happens."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-7148 was patched at 2024-05-15
1149.
Denial of Service - Unknown Product (CVE-2020-18773) - High [410]
Description: {'vulners_cve_data_all': 'An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-18773 was patched at 2024-05-15
1150.
Denial of Service - Unknown Product (CVE-2020-18774) - High [410]
Description: {'vulners_cve_data_all': 'A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-18774 was patched at 2024-05-15
1151.
Denial of Service - Unknown Product (CVE-2020-18899) - High [410]
Description: {'vulners_cve_data_all': 'An uncontrolled memory allocation in DataBufdata(subBox.length-sizeof(box)) function of Exiv2 0.27 allows attackers to cause a denial of service (DOS) via a crafted input.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-18899 was patched at 2024-05-15
1152.
Denial of Service - Unknown Product (CVE-2020-21048) - High [410]
Description: {'vulners_cve_data_all': 'An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-21048 was patched at 2024-05-15
1153.
Denial of Service - Unknown Product (CVE-2020-21049) - High [410]
Description: {'vulners_cve_data_all': 'An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-21049 was patched at 2024-05-15
1154.
Denial of Service - Unknown Product (CVE-2020-21677) - High [410]
Description: {'vulners_cve_data_all': 'A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of service (DOS) via converting a crafted PNG file into Sixel format.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-21677 was patched at 2024-05-15
1155.
Denial of Service - Unknown Product (CVE-2020-5421) - High [410]
Description: {'vulners_cve_data_all': 'In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Vulnerability in Pivotal Software Spring Framework) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-5421 was patched at 2024-05-15
1156.
Denial of Service - Unknown Product (CVE-2021-44568) - High [410]
Description: {'vulners_cve_data_all': 'Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 & line 1995), which could cause a remote Denial of Service.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-44568 was patched at 2024-05-15
1157.
Denial of Service - Unknown Product (CVE-2022-22971) - High [410]
Description: {'vulners_cve_data_all': 'In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-22971 was patched at 2024-05-15
1158.
Information Disclosure - Unknown Product (CVE-2008-1111) - High [410]
Description: {'vulners_cve_data_all': 'mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers to obtain sensitive information.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Lighttpd mod_cgi模块信息泄露漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1111 was patched at 2024-05-15
1159.
Information Disclosure - Unknown Product (CVE-2009-1255) - High [410]
Description: {'vulners_cve_data_all': 'The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain sensitive information such as the locations of memory regions, and defeat ASLR protection, by sending a command to the daemon's TCP port.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Memcached stats maps命令信息泄露漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1255 was patched at 2024-05-15
1160.
Information Disclosure - Unknown Product (CVE-2013-7299) - High [410]
Description: {'vulners_cve_data_all': 'framework/common/messageheaderparser.cpp in Tntnet before 2.2.1 allows remote attackers to obtain sensitive information via a header that ends in \\n instead of \\r\\n, which prevents a null terminator from being added and causes Tntnet to include headers from other requests.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Tntnet HTTP报文头泄露漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-7299 was patched at 2024-05-15
1161.
Memory Corruption - Unknown Product (CVE-2014-2830) - High [410]
Description: {'vulners_cve_data_all': 'Stack-based buffer overflow in cifskey.c or cifscreds.c in cifs-utils before 6.4, as used in pam_cifscreds, allows remote attackers to have unspecified impact via unknown vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] 'pam_cifscreds' PAM模块'cifskey.c'栈缓冲区溢出漏洞) | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-2830 was patched at 2024-05-15
1162.
Memory Corruption - Unknown Product (CVE-2017-6542) - High [410]
Description: {'vulners_cve_data_all': 'The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect to the Unix-domain socket representing the forwarded agent connection, which trigger a buffer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] PuTTY 0.68 - ssh_agent_channel_data Integer Overflow Heap Corruption, [packetstorm] PuTTY ssh_agent_channel_data Integer Overflow, [zdt] PuTTY < 0.68 - ssh_agent_channel_data Integer Overflow Heap Corruption Vulnerability, [exploitdb] PuTTY < 0.68 - 'ssh_agent_channel_data' Integer Overflow Heap Corruption) | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-6542 was patched at 2024-05-15
1163.
Memory Corruption - Unknown Product (CVE-2018-25017) - High [410]
Description: {'vulners_cve_data_all': 'RawSpeed (aka librawspeed) 3.1 has a heap-based buffer overflow in TableLookUp::setTable.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-25017 was patched at 2024-05-15
1164.
Memory Corruption - Unknown Product (CVE-2020-23302) - High [410]
Description: {'vulners_cve_data_all': 'There is a heap-use-after-free at ecma-helpers-string.c:772 in ecma_ref_ecma_string in JerryScript 2.2.0', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23302 was patched at 2024-05-15
1165.
Memory Corruption - Unknown Product (CVE-2020-23303) - High [410]
Description: {'vulners_cve_data_all': 'There is a heap-buffer-overflow at jmem-poolman.c:165 in jmem_pools_collect_empty in JerryScript 2.2.0.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23303 was patched at 2024-05-15
1166.
Memory Corruption - Unknown Product (CVE-2020-23306) - High [410]
Description: {'vulners_cve_data_all': 'There is a stack-overflow at ecma-regexp-object.c:535 in ecma_regexp_match in JerryScript 2.2.0.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23306 was patched at 2024-05-15
1167.
Memory Corruption - Unknown Product (CVE-2020-23321) - High [410]
Description: {'vulners_cve_data_all': 'There is a heap-buffer-overflow at lit-strings.c:431 in lit_read_code_unit_from_utf8 in JerryScript 2.2.0.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23321 was patched at 2024-05-15
1168.
Memory Corruption - Unknown Product (CVE-2020-23323) - High [410]
Description: {'vulners_cve_data_all': 'There is a heap-buffer-overflow at re-parser.c in re_parse_char_escape in JerryScript 2.2.0.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23323 was patched at 2024-05-15
1169.
Memory Corruption - Unknown Product (CVE-2020-24978) - High [410]
Description: {'vulners_cve_data_all': 'In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-24978 was patched at 2024-05-15
1170.
Memory Corruption - Unknown Product (CVE-2020-7720) - High [410]
Description: {'vulners_cve_data_all': 'The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Improperly Controlled Modification of Dynamically-Determined Object Attributes in Digitalbazaar Forge) | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-7720 was patched at 2024-05-15
1171.
Memory Corruption - Unknown Product (CVE-2021-45951) - High [410]
Description: {'vulners_cve_data_all': 'Dnsmasq 2.86 has a heap-based buffer overflow in check_bad_address (called from check_for_bogus_wildcard and FuzzCheckForBogusWildcard). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-45951 was patched at 2024-05-15
1172.
Memory Corruption - Unknown Product (CVE-2021-45952) - High [410]
Description: {'vulners_cve_data_all': 'Dnsmasq 2.86 has a heap-based buffer overflow in dhcp_reply (called from dhcp_packet and FuzzDhcp). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-45952 was patched at 2024-05-15
1173.
Memory Corruption - Unknown Product (CVE-2021-45953) - High [410]
Description: {'vulners_cve_data_all': 'Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from hash_questions and fuzz_util.c). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-45953 was patched at 2024-05-15
1174.
Memory Corruption - Unknown Product (CVE-2021-45954) - High [410]
Description: {'vulners_cve_data_all': 'Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from answer_auth and FuzzAuth). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-45954 was patched at 2024-05-15
1175.
Memory Corruption - Unknown Product (CVE-2021-45955) - High [410]
Description: {'vulners_cve_data_all': 'Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called from FuzzResizePacket and fuzz_rfc1035.c) because of the lack of a proper bounds check upon pseudo header re-insertion. NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge." However, a contributor states that a security patch (mentioned in 016162.html) is needed', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-45955 was patched at 2024-05-15
1176.
Memory Corruption - Unknown Product (CVE-2021-45956) - High [410]
Description: {'vulners_cve_data_all': 'Dnsmasq 2.86 has a heap-based buffer overflow in print_mac (called from log_packet and dhcp_reply). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-45956 was patched at 2024-05-15
1177.
Memory Corruption - Unknown Product (CVE-2021-45957) - High [410]
Description: {'vulners_cve_data_all': 'Dnsmasq 2.86 has a heap-based buffer overflow in answer_request (called from FuzzAnswerTheRequest and fuzz_rfc1035.c). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-45957 was patched at 2024-05-15
1178.
Memory Corruption - Unknown Product (CVE-2022-30595) - High [410]
Description: {'vulners_cve_data_all': 'libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-30595 was patched at 2024-05-15
1179.
Memory Corruption - Unknown Product (CVE-2023-49287) - High [410]
Description: {'vulners_cve_data_all': 'TinyDir is a lightweight C directory and file reader. Buffer overflows in the `tinydir_file_open()` function. This vulnerability has been patched in version 1.2.6.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-49287 was patched at 2024-05-15
1180.
Path Traversal - Unknown Product (CVE-2008-2942) - High [410]
Description: {'vulners_cve_data_all': 'Directory traversal vulnerability in patch.py in Mercurial 1.0.1 allows user-assisted attackers to modify arbitrary files via ".." (dot dot) sequences in a patch file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Mercurial 'patch.py'目录遍历漏洞, [seebug] Mercurial patch.py文件目录遍历漏洞) | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-2942 was patched at 2024-05-15
1181.
Path Traversal - Unknown Product (CVE-2010-3867) - High [410]
Description: {'vulners_cve_data_all': 'Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authenticated users to create directories, delete directories, create symlinks, and modify file timestamps via directory traversal sequences in a (1) SITE MKDIR, (2) SITE RMDIR, (3) SITE SYMLINK, or (4) SITE UTIME command.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] ProFTPD 1.3.2rc3 - 1.3.3b Telnet IAC Buffer Overflow, [seebug] ProFTPD多个模块目录遍历和缓冲区溢出漏洞) | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-3867 was patched at 2024-05-15
1182.
Path Traversal - Unknown Product (CVE-2013-4885) - High [410]
Description: {'vulners_cve_data_all': 'The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Nmap 任意文件写漏洞(CVE-2013-4885)) | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-4885 was patched at 2024-05-15
1183.
Path Traversal - Unknown Product (CVE-2019-8943) - High [410]
Description: {'vulners_cve_data_all': 'WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can write the output image to an arbitrary directory via a filename containing two image extensions and ../ sequences, such as a filename ending with the .jpg?/../../file.jpg substring.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] WordPress 5.0.0 crop-image Shell Upload, [packetstorm] WordPress 5.0.0 Remote Code Execution, [zdt] WordPress 5.0.0 crop-image Shell Upload Exploit, [zdt] WordPress Core 5.0 - Remote Code Execution Exploit, [githubexploit] Exploit for Unrestricted Upload of File with Dangerous Type in Wordpress, [githubexploit] Exploit for Path Traversal in Wordpress) | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-8943 was patched at 2024-05-15
1184.
Unknown Vulnerability Type - Perl (CVE-2009-2946) - High [409]
Description: {'vulners_cve_data_all': 'Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Debian devscripts软件包uscan远程代码执行漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2946 was patched at 2024-05-15
1185.
Unknown Vulnerability Type - Perl (CVE-2010-2971) - High [409]
Description: {'vulners_cve_data_all': 'loaders/load_it.c in libmikmod, possibly 3.1.12, does not properly account for the larger size of name##env relative to name##tick and name##node, which allows remote attackers to trigger a buffer over-read and possibly have unspecified other impact via a crafted Impulse Tracker file, a related issue to CVE-2010-2546. NOTE: this issue exists because of an incomplete fix for CVE-2009-3995.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Winamp模块解码器插件多个缓冲区溢出漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-2971 was patched at 2024-05-15
1186.
Unknown Vulnerability Type - Python (CVE-2017-17522) - High [409]
Description: {'vulners_cve_data_all': 'Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that exploitation is impossible because the code relies on subprocess.Popen and the default shell=False setting', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Python 'Lib/webbrowser.py' Remote Command Execution Vulnerability(CVE-2017-17522)) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-17522 was patched at 2024-05-15
1187.
Unknown Vulnerability Type - Wireshark (CVE-2011-3360) - High [409]
Description: {'vulners_cve_data_all': 'Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain privileges via a Trojan horse Lua script in an unspecified directory.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Wireshark 1.6 console.lua Pre-Load / Execution, [saint] Wireshark Lua Untrusted Search Path vulnerability, [saint] Wireshark Lua Untrusted Search Path vulnerability, [saint] Wireshark Lua Untrusted Search Path vulnerability, [saint] Wireshark Lua Untrusted Search Path vulnerability, [d2] DSquare Exploit Pack: D2SEC_WIRESHARK) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-3360 was patched at 2024-05-15
1188.
Code Injection - BIND (CVE-2024-27304) - High [408]
Description: {'vulners_cve_data_all': 'pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-27304 was patched at 2024-05-15
1189.
Elevation of Privilege - Linux Kernel (CVE-2023-28339) - High [408]
Description: OpenDoas through 6.8.2, when TIOCSTI is available, allows
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-28339 was patched at 2024-05-15
1190.
Elevation of Privilege - Windows Kernel (CVE-2023-0184) - High [408]
Description: NVIDIA GPU Display Driver for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows Kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-0184 was patched at 2024-05-15
1191.
Arbitrary File Writing - Unknown Product (CVE-2010-5105) - High [407]
Description: {'vulners_cve_data_all': 'The undo save quit routine in the kernel in Blender 2.5, 2.63a, and earlier allows local users to overwrite arbitrary files via a symlink attack on the quit.blend temporary file. NOTE: this issue might be a regression of CVE-2008-1103.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Blender创建不安全临时文件漏洞) | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-5105 was patched at 2024-05-15
1192.
Arbitrary File Writing - Unknown Product (CVE-2013-0248) - High [407]
Description: {'vulners_cve_data_all': 'The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apache Commons FileUpload不安全临时文件创建漏洞(CVE-2013-0248)) | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-0248 was patched at 2024-05-15
1193.
Remote Code Execution - Binutils (CVE-2005-4807) - High [407]
Description: Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-4807 was patched at 2024-05-15
1194.
Remote Code Execution - Binutils (CVE-2006-2362) - High [407]
Description: Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-2362 was patched at 2024-05-15
1195.
Remote Code Execution - GNOME desktop (CVE-2022-48622) - High [407]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2022-48622 was patched at 2024-05-23, 2024-06-11
debian: CVE-2022-48622 was patched at 2024-05-15
oraclelinux: CVE-2022-48622 was patched at 2024-05-29, 2024-06-11
redhat: CVE-2022-48622 was patched at 2024-05-23, 2024-06-11
ubuntu: CVE-2022-48622 was patched at 2024-06-05
1196.
Remote Code Execution - GNOME desktop (CVE-2023-36250) - High [407]
Description: CSV Injection vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-36250 was patched at 2024-05-15
1197.
Remote Code Execution - GNU C Library (CVE-2002-0651) - High [407]
Description: Buffer overflow in the DNS resolver code used in libc,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-0651 was patched at 2024-05-15
1198.
Remote Code Execution - GNU C Library (CVE-2002-0684) - High [407]
Description: Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-0684 was patched at 2024-05-15
1199.
Remote Code Execution - GNU C Library (CVE-2003-0689) - High [407]
Description: The getgrouplist function in GNU libc (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0689 was patched at 2024-05-15
1200.
Remote Code Execution - Mozilla Firefox (CVE-2006-0292) - High [407]
Description: The Javascript interpreter (jsinterp.c) in Mozilla and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-0292 was patched at 2024-05-15
1201.
Remote Code Execution - Mozilla Firefox (CVE-2006-0294) - High [407]
Description: Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-0294 was patched at 2024-05-15
1202.
Remote Code Execution - Mozilla Firefox (CVE-2006-1529) - High [407]
Description: Unspecified vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-1529 was patched at 2024-05-15
1203.
Remote Code Execution - Mozilla Firefox (CVE-2006-1530) - High [407]
Description: Unspecified vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-1530 was patched at 2024-05-15
1204.
Remote Code Execution - Mozilla Firefox (CVE-2006-1531) - High [407]
Description: Unspecified vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-1531 was patched at 2024-05-15
1205.
Remote Code Execution - Mozilla Firefox (CVE-2006-1723) - High [407]
Description: Unspecified vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-1723 was patched at 2024-05-15
1206.
Remote Code Execution - Mozilla Firefox (CVE-2006-1724) - High [407]
Description: Unspecified vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-1724 was patched at 2024-05-15
1207.
Remote Code Execution - Mozilla Firefox (CVE-2006-2776) - High [407]
Description: Certain privileged UI code in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-2776 was patched at 2024-05-15
1208.
Remote Code Execution - Mozilla Firefox (CVE-2006-3113) - High [407]
Description: Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3113 was patched at 2024-05-15
1209.
Remote Code Execution - Mozilla Firefox (CVE-2006-3805) - High [407]
Description: The Javascript engine in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3805 was patched at 2024-05-15
1210.
Remote Code Execution - Mozilla Firefox (CVE-2006-3806) - High [407]
Description: Multiple integer overflows in the Javascript engine in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3806 was patched at 2024-05-15
1211.
Remote Code Execution - Mozilla Firefox (CVE-2006-3807) - High [407]
Description: Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3807 was patched at 2024-05-15
1212.
Remote Code Execution - Mozilla Firefox (CVE-2006-3808) - High [407]
Description: Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3808 was patched at 2024-05-15
1213.
Remote Code Execution - Mozilla Firefox (CVE-2006-3811) - High [407]
Description: Multiple vulnerabilities in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3811 was patched at 2024-05-15
1214.
Remote Code Execution - Mozilla Firefox (CVE-2006-5747) - High [407]
Description: Unspecified vulnerability in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-5747 was patched at 2024-05-15
1215.
Remote Code Execution - OpenSSH (CVE-2003-0695) - High [407]
Description: Multiple "buffer management errors" in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0695 was patched at 2024-05-15
1216.
Remote Code Execution - OpenSSH (CVE-2006-5051) - High [407]
Description: Signal handler race condition in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-5051 was patched at 2024-05-15
1217.
Remote Code Execution - OpenSSL (CVE-2002-0655) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-0655 was patched at 2024-05-15
1218.
Remote Code Execution - PHP (CVE-2005-4873) - High [407]
Description: Multiple stack-based buffer overflows in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-4873 was patched at 2024-05-15
1219.
Remote Code Execution - PHP (CVE-2008-4096) - High [407]
Description: libraries/database_interface.lib.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 8.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-4096 was patched at 2024-05-15
1220.
Remote Code Execution - PHP (CVE-2010-4335) - High [407]
Description: The _validatePost function in libs/controller/components/security.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-4335 was patched at 2024-05-15
1221.
Remote Code Execution - PHP (CVE-2014-5203) - High [407]
Description: wp-includes/class-wp-customize-widgets.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-5203 was patched at 2024-05-15
1222.
Remote Code Execution - PHP (CVE-2016-6633) - High [407]
Description: An issue was discovered in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-6633 was patched at 2024-05-15
1223.
Remote Code Execution - PHP (CVE-2024-31210) - High [407]
Description: WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plugins -> Add New -> Upload Plugin screen in WordPress. If FTP credentials are requested for installation (in order to move the file into place outside of the `uploads` directory) then the uploaded file remains temporary available in the Media Library despite it not being allowed. If the `DISALLOW_FILE_EDIT` constant is set to `true` on the site _and_ FTP credentials are required when uploading a new theme or plugin, then this technically allows an
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-31210 was patched at 2024-05-08, 2024-05-15
1224.
Remote Code Execution - Samba (CVE-2002-2196) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-2196 was patched at 2024-05-15
1225.
Remote Code Execution - libvpx (CVE-2016-2464) - High [407]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | libvpx is a free software video codec library from Google and the Alliance for Open Media (AOMedia) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-2464 was patched at 2024-05-15
1226.
Unknown Vulnerability Type - Binutils (CVE-2020-35494) - High [407]
Description: {'vulners_cve_data_all': 'There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to data confidentiality. This flaw affects binutils versions prior to 2.34.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-35494 was patched at 2024-05-15
1227.
Unknown Vulnerability Type - OpenSSH (CVE-2013-4548) - High [407]
Description: {'vulners_cve_data_all': 'The mm_newkeys_from_blob function in monitor_wrap.c in sshd in OpenSSH 6.2 and 6.3, when an AES-GCM cipher is used, does not properly initialize memory for a MAC context data structure, which allows remote authenticated users to bypass intended ForceCommand and login-shell restrictions via packet data that provides a crafted callback address.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] IBM AIX/Virtual I/O Server OpenSSH AES-GCM密文特权提升漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-4548 was patched at 2024-05-15
1228.
Unknown Vulnerability Type - PHP (CVE-2005-3299) - High [407]
Description: {'vulners_cve_data_all': 'PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object) website | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-3299 was patched at 2024-05-15
1229.
Unknown Vulnerability Type - PHP (CVE-2009-2854) - High [407]
Description: {'vulners_cve_data_all': 'Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.php, (8) import.php, or (9) link-add.php in wp-admin/.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] WordPress wp-admin非授权管理访问漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2854 was patched at 2024-05-15
1230.
Unknown Vulnerability Type - PHP (CVE-2011-2505) - High [407]
Description: {'vulners_cve_data_all': 'libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
debian: CVE-2011-2505 was patched at 2024-05-15
1231.
Unknown Vulnerability Type - RPC (CVE-2008-0664) - High [407]
Description: {'vulners_cve_data_all': 'The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog users via unknown vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Wordpress XML-RPC接口非授权操作漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-0664 was patched at 2024-05-15
1232.
Unknown Vulnerability Type - RPC (CVE-2012-0215) - High [407]
Description: {'vulners_cve_data_all': 'model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Python 'trytond'模块'Many2Many'字段安全限制绕过漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-0215 was patched at 2024-05-15
1233.
Unknown Vulnerability Type - Safari (CVE-2009-1693) - High [407]
Description: {'vulners_cve_data_all': 'WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to read images from arbitrary web sites via a CANVAS element with an SVG image, related to a "cross-site image capture issue."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1693 was patched at 2024-05-15
1234.
Unknown Vulnerability Type - Safari (CVE-2009-1694) - High [407]
Description: {'vulners_cve_data_all': 'WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read images from arbitrary web sites via vectors involving a CANVAS element and redirection, related to a "cross-site image capture issue."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1694 was patched at 2024-05-15
1235.
Unknown Vulnerability Type - Samba (CVE-2009-0022) - High [407]
Description: {'vulners_cve_data_all': 'Samba 3.2.0 through 3.2.6, when registry shares are enabled, allows remote authenticated users to access the root filesystem via a crafted connection request that specifies a blank share name.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Samba注册表共享名非授权访问漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0022 was patched at 2024-05-15
1236.
Unknown Vulnerability Type - Samba (CVE-2014-2079) - High [407]
Description: {'vulners_cve_data_all': 'X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] X File Explorer 'FilePanel::onCmdNewFile'函数访问绕过漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-2079 was patched at 2024-05-15
1237.
Unknown Vulnerability Type - Samba (CVE-2019-3870) - High [407]
Description: {'vulners_cve_data_all': 'A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded installations it will have other permissions, such as 0755, because this was the default before Samba 4.8. Within this directory, files are created with mode 0666, which is world-writable, including a sample krb5.conf, and the list of DNS names and servicePrincipalName values to update.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-3870 was patched at 2024-05-15
1238.
Security Feature Bypass - Apache HTTP Server (CVE-2019-0190) - High [405]
Description: {'vulners_cve_data_all': 'A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-0190 was patched at 2024-05-15
1239.
Security Feature Bypass - Linux Kernel (CVE-2016-9919) - High [405]
Description: {'vulners_cve_data_all': 'The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-9919 was patched at 2024-05-15
1240.
Security Feature Bypass - Linux Kernel (CVE-2019-12456) - High [405]
Description: {'vulners_cve_data_all': 'An issue was discovered in the MPT3COMMAND case in _ctl_ioctl_main in drivers/scsi/mpt3sas/mpt3sas_ctl.c in the Linux kernel through 5.1.5. It allows local users to cause a denial of service or possibly have unspecified other impact by changing the value of ioc_number between two kernel reads of that value, aka a "double fetch" vulnerability. NOTE: a third party reports that this is unexploitable because the doubly fetched value is not used', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-12456 was patched at 2024-05-15
1241.
Security Feature Bypass - Linux Kernel (CVE-2021-3847) - High [405]
Description: {'vulners_cve_data_all': 'An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-3847 was patched at 2024-05-15
1242.
Cross Site Scripting - Unknown Product (CVE-2020-7676) - High [404]
Description: {'vulners_cve_data_all': 'angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes parsing behavior, leading to possibly unsanitizing code.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Cross-site Scripting in Angularjs Angular.Js) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-7676 was patched at 2024-05-15
1243.
Cross Site Scripting - Unknown Product (CVE-2021-38602) - High [404]
Description: {'vulners_cve_data_all': 'PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Cross-site Scripting in Pluxml) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-38602 was patched at 2024-05-15
1244.
Incorrect Calculation - Unknown Product (CVE-2024-34403) - High [404]
Description: {'vulners_cve_data_all': 'An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Incorrect Calculation | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-34403 was patched at 2024-05-15
1245.
Memory Corruption - Unknown Product (CVE-2024-29133) - High [404]
Description: {'vulners_cve_data_all': 'Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1.\n\nUsers are recommended to upgrade to version 2.10.1, which fixes the issue.\n\n', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-29133 was patched at 2024-05-15
1246.
Remote Code Execution - Kerberos (CVE-2004-0643) - High [404]
Description: Double free vulnerability in the krb5_rd_cred function for MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0643 was patched at 2024-05-15
1247.
Authentication Bypass - PHP (CVE-2004-2632) - High [403]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-2632 was patched at 2024-05-15
1248.
Authentication Bypass - PHP (CVE-2017-1000071) - High [403]
Description: Jasig
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-1000071 was patched at 2024-05-15
1249.
Authentication Bypass - RPC (CVE-2024-23324) - High [403]
Description: Envoy is a high-performance edge/middle/service proxy. External
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
redos: CVE-2024-23324 was patched at 2024-04-23
1250.
Remote Code Execution - FFmpeg (CVE-2011-3504) - High [402]
Description: The Matroska format decoder in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-3504 was patched at 2024-05-15
1251.
Remote Code Execution - FFmpeg (CVE-2012-5359) - High [402]
Description: Libavcodec in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-5359 was patched at 2024-05-15
1252.
Remote Code Execution - FFmpeg (CVE-2012-5360) - High [402]
Description: Libavcodec in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-5360 was patched at 2024-05-15
1253.
Remote Code Execution - FFmpeg (CVE-2014-4610) - High [402]
Description: Integer overflow in the get_len function in libavutil/lzo.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-4610 was patched at 2024-05-15
1254.
Remote Code Execution - vim (CVE-2008-3076) - High [402]
Description: The Netrw plugin 125 in netrw.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Vim is a free and open-source, screen-based text editor program | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3076 was patched at 2024-05-15
1255.
Unknown Vulnerability Type - BIND (CVE-2006-2194) - High [402]
Description: {'vulners_cve_data_all': 'The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] PPPD Winbind插件本地权限提升漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-2194 was patched at 2024-05-15
1256.
Unknown Vulnerability Type - BIND (CVE-2009-1894) - High [402]
Description: {'vulners_cve_data_all': 'Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, related to the application setting LD_BIND_NOW to 1, and then calling execv on the target of the /proc/self/exe symlink.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Linux Kernel tun_chr_pool()函数空指针引用漏洞, [seebug] GNU C library dynamic linker $ORIGIN expansion Vulnerability, [packetstorm] GNU C Library Dynamic Linker $ORIGIN Expansion Vulnerability, [exploitpack] GNU C library dynamic linker - $ORIGIN Expansion, [exploitdb] GNU C library dynamic linker - '$ORIGIN' Expansion) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1894 was patched at 2024-05-15
1257.
Unknown Vulnerability Type - MediaWiki (CVE-2012-4379) - High [402]
Description: {'vulners_cve_data_all': 'MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct clickjacking attacks via an embedded API response in an IFRAME element.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MediaWiki 1.x 跨站请求伪造漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-4379 was patched at 2024-05-15
1258.
Unknown Vulnerability Type - MediaWiki (CVE-2012-5391) - High [402]
Description: {'vulners_cve_data_all': 'Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the session_id.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MediaWiki 会话固定漏洞(CVE-2012-5391)) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-5391 was patched at 2024-05-15
1259.
Unknown Vulnerability Type - iOS (CVE-2008-1692) - High [402]
Description: {'vulners_cve_data_all': 'Eterm 0.9.4 opens a terminal window on :0 if -display is not specified and the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] rxvt终端X11显示任意代码执行漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1692 was patched at 2024-05-15
1260.
Code Injection - PHP (CVE-2006-2667) - High [401]
Description: Direct static
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-2667 was patched at 2024-05-15
1261.
Code Injection - PHP (CVE-2006-4674) - High [401]
Description: Direct static
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4674 was patched at 2024-05-15
1262.
Command Injection - Node.js (CVE-2016-2086) - High [401]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-2086 was patched at 2024-05-15
1263.
Security Feature Bypass - APT (CVE-2021-32642) - High [401]
Description: {'vulners_cve_data_all': 'radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validation in radsecproxy's `naptr-eduroam.sh` and `radsec-dynsrv.sh` scripts can lead to configuration injection via crafted radsec peer discovery DNS records. Users are subject to Information disclosure, Denial of Service, Redirection of Radius connection to a non-authenticated server leading to non-authenticated network access. Updated example scripts are available in the master branch and 1.9 release. Note that the scripts are not part of the installation package and are not updated automatically. If you are using the examples, you have to update them manually. The dyndisc scripts work independently of the radsecproxy code. The updated scripts can be used with any version of radsecproxy.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 0.9 | 10 | CVSS Base Score is 9.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32642 was patched at 2024-05-15
1264.
Security Feature Bypass - Chromium (CVE-2021-30618) - High [401]
Description: {'vulners_cve_data_all': 'Chromium: CVE-2021-30618 Inappropriate implementation in DevTools', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30618 was patched at 2024-05-15
1265.
Security Feature Bypass - Chromium (CVE-2021-30620) - High [401]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30620 was patched at 2024-05-15
1266.
Remote Code Execution - Apache HTTP Server (CVE-2007-1741) - High [400]
Description: Multiple race conditions in suexec in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-1741 was patched at 2024-05-15
1267.
Remote Code Execution - Apache HTTP Server (CVE-2009-3890) - High [400]
Description: Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3890 was patched at 2024-05-15
1268.
Remote Code Execution - Windows LDAP (CVE-2005-4744) - High [400]
Description: Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2.5-5, and possibly other versions including 1.0.4, might allow remote attackers to cause a denial of service (crash) and possibly
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Windows LDAP (Lightweight Directory Access Protocol) is an open and cross platform protocol used for directory services authentication | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-4744 was patched at 2024-05-15
1269.
Unknown Vulnerability Type - Apache HTTP Server (CVE-2007-6420) - High [400]
Description: {'vulners_cve_data_all': 'Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apache 'mod_proxy_balancer'存在多个漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-6420 was patched at 2024-05-15
1270.
Unknown Vulnerability Type - Linux Kernel (CVE-2013-1959) - High [400]
Description: {'vulners_cve_data_all': 'kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_map and gid_map files, which allows local users to gain privileges by opening a file within an unprivileged process and then modifying the file within a privileged process.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Linux Kernel Capability file_ns_capable() - Privilege Escalation) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-1959 was patched at 2024-05-15
1271.
Arbitrary File Writing - OpenSSH (CVE-2020-12062) - Medium [398]
Description: The scp client in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-12062 was patched at 2024-05-15
1272.
Denial of Service - Unknown Product (CVE-2011-4939) - Medium [398]
Description: {'vulners_cve_data_all': 'The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by changing a nickname while in an XMPP chat room.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Pidgin 2.x XMPP协议拒绝访问漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4939 was patched at 2024-05-15
1273.
Denial of Service - Unknown Product (CVE-2012-3495) - Medium [398]
Description: {'vulners_cve_data_all': 'The physdev_get_free_pirq hypercall in arch/x86/physdev.c in Xen 4.1.x and Citrix XenServer 6.0.2 and earlier uses the return value of the get_free_pirq function as an array index without checking that the return value indicates an error, which allows guest OS users to cause a denial of service (invalid memory write and host crash) and possibly gain privileges via unspecified vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] XenSource Xen 'physdev_get_free_pirq'拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-3495 was patched at 2024-05-15
1274.
Denial of Service - Unknown Product (CVE-2016-1885) - Medium [398]
Description: {'vulners_cve_data_all': 'Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 before p31, and 10.2 before p14 allows local users to cause a denial of service (kernel panic) via an i386_set_ldt system call, which triggers a heap-based buffer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-1885 was patched at 2024-05-15
1275.
Denial of Service - Unknown Product (CVE-2017-11331) - Medium [398]
Description: {'vulners_cve_data_all': 'The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Vorbis Tools oggenc 1.4.0 - .wav Denial of Service, [zdt] Vorbis Tools oggenc 1.4.0 - .wav Denial of Service Exploit, [exploitdb] Vorbis Tools oggenc 1.4.0 - '.wav' Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-11331 was patched at 2024-05-15
1276.
Denial of Service - Unknown Product (CVE-2017-11548) - Medium [398]
Description: {'vulners_cve_data_all': 'The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service (memory corruption) via a crafted MP3 file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] libao 1.2.0 - Denial of Service, [zdt] libao 1.2.0 - Denial of Service Exploit, [exploitdb] libao 1.2.0 - Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-11548 was patched at 2024-05-15
1277.
Denial of Service - Unknown Product (CVE-2017-9129) - Medium [398]
Description: {'vulners_cve_data_all': 'The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (large loop) via a crafted wav file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Freeware Advanced Audio Coder (FAAC) 1.28 - Denial of Service Vulnerability, [packetstorm] Freeware Advanced Audio Coder (FAAC) 1.28 Denial Of Service, [exploitpack] Freeware Advanced Audio Coder (FAAC) 1.28 - Denial of Service, [exploitdb] Freeware Advanced Audio Coder (FAAC) 1.28 - Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-9129 was patched at 2024-05-15
1278.
Denial of Service - Unknown Product (CVE-2017-9130) - Medium [398]
Description: {'vulners_cve_data_all': 'The faacEncOpen function in libfaac/frame.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted wav file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Freeware Advanced Audio Coder (FAAC) 1.28 Denial Of Service, [exploitpack] Freeware Advanced Audio Coder (FAAC) 1.28 - Denial of Service, [zdt] Freeware Advanced Audio Coder (FAAC) 1.28 - Denial of Service Vulnerability, [exploitdb] Freeware Advanced Audio Coder (FAAC) 1.28 - Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-9130 was patched at 2024-05-15
1279.
Denial of Service - Unknown Product (CVE-2017-9869) - Medium [398]
Description: {'vulners_cve_data_all': 'The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] LAME 3.99.5 - II_step_one Buffer Overflow Exploit) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-9869 was patched at 2024-05-15
1280.
Denial of Service - Unknown Product (CVE-2018-11771) - Medium [398]
Description: {'vulners_cve_data_all': 'When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the correct EOF indication after the end of the stream has been reached. When combined with a java.io.InputStreamReader this can lead to an infinite stream, which can be used to mount a denial of service attack against services that use Compress' zip package.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-11771 was patched at 2024-05-15
1281.
Denial of Service - Unknown Product (CVE-2018-1324) - Medium [398]
Description: {'vulners_cve_data_all': 'A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-1324 was patched at 2024-05-15
1282.
Denial of Service - Unknown Product (CVE-2018-16369) - Medium [398]
Description: {'vulners_cve_data_all': 'XRef::fetch in XRef.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (stack consumption) via a crafted pdf file, related to AcroForm::scanField, as demonstrated by pdftohtml. NOTE: this might overlap CVE-2018-7453.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-16369 was patched at 2024-05-15
1283.
Denial of Service - Unknown Product (CVE-2018-16517) - Medium [398]
Description: {'vulners_cve_data_all': 'asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Netwide Assembler (NASM) 2.14rc15 Null Pointer Dereference, [zdt] Netwide Assembler (NASM) 2.14rc15 - NULL Pointer Dereference Exploit, [exploitpack] Netwide Assembler (NASM) 2.14rc15 - NULL Pointer Dereference (PoC), [exploitdb] Netwide Assembler (NASM) 2.14rc15 - NULL Pointer Dereference (PoC)) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-16517 was patched at 2024-05-15
1284.
Denial of Service - Unknown Product (CVE-2020-18768) - Medium [398]
Description: {'vulners_cve_data_all': 'There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in libtiff 4.0.10, which allows an attacker to cause a denial-of-service through a crafted tiff file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-18768 was patched at 2024-05-15
1285.
Denial of Service - Unknown Product (CVE-2020-18971) - Medium [398]
Description: {'vulners_cve_data_all': 'Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/PdfDictionary.cpp:65'.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-18971 was patched at 2024-05-15
1286.
Denial of Service - Unknown Product (CVE-2020-18976) - Medium [398]
Description: {'vulners_cve_data_all': 'Buffer Overflow in Tcpreplay v4.3.2 allows attackers to cause a Denial of Service via the 'do_checksum' function in 'checksum.c'. It can be triggered by sending a crafted pcap file to the 'tcpreplay-edit' binary. This issue is different than CVE-2019-8381.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-18976 was patched at 2024-05-15
1287.
Denial of Service - Unknown Product (CVE-2020-19488) - Medium [398]
Description: {'vulners_cve_data_all': 'An issue was discovered in box_code_apple.c:119 in Gpac MP4Box 0.8.0, allows attackers to cause a Denial of Service due to an invalid read on function ilst_item_Read.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-19488 was patched at 2024-05-15
1288.
Denial of Service - Unknown Product (CVE-2020-21678) - Medium [398]
Description: {'vulners_cve_data_all': 'A global buffer overflow in the genmp_writefontmacro_latex component in genmp.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into mp format.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-21678 was patched at 2024-05-15
1289.
Denial of Service - Unknown Product (CVE-2020-21679) - Medium [398]
Description: {'vulners_cve_data_all': 'Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick 1.4 allows remote attackers to cause a denial of service via converting of crafted image file to pcx format.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-21679 was patched at 2024-05-15
1290.
Denial of Service - Unknown Product (CVE-2020-21680) - Medium [398]
Description: {'vulners_cve_data_all': 'A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-21680 was patched at 2024-05-15
1291.
Denial of Service - Unknown Product (CVE-2020-21681) - Medium [398]
Description: {'vulners_cve_data_all': 'A global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-21681 was patched at 2024-05-15
1292.
Denial of Service - Unknown Product (CVE-2020-21682) - Medium [398]
Description: {'vulners_cve_data_all': 'A global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ge format.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-21682 was patched at 2024-05-15
1293.
Denial of Service - Unknown Product (CVE-2020-21683) - Medium [398]
Description: {'vulners_cve_data_all': 'A global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-21683 was patched at 2024-05-15
1294.
Denial of Service - Unknown Product (CVE-2020-21684) - Medium [398]
Description: {'vulners_cve_data_all': 'A global buffer overflow in the put_font in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pict2e format.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-21684 was patched at 2024-05-15
1295.
Denial of Service - Unknown Product (CVE-2020-23273) - Medium [398]
Description: {'vulners_cve_data_all': 'Heap-buffer overflow in the randomize_iparp function in edit_packet.c. of Tcpreplay v4.3.2 allows attackers to cause a denial of service (DOS) via a crafted pcap.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23273 was patched at 2024-05-15
1296.
Denial of Service - Unknown Product (CVE-2020-23856) - Medium [398]
Description: {'vulners_cve_data_all': 'Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-23856 was patched at 2024-05-15
1297.
Denial of Service - Unknown Product (CVE-2020-24821) - Medium [398]
Description: {'vulners_cve_data_all': 'A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-24821 was patched at 2024-05-15
1298.
Denial of Service - Unknown Product (CVE-2020-24822) - Medium [398]
Description: {'vulners_cve_data_all': 'A vulnerability in the dwarf::cursor::uleb function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-24822 was patched at 2024-05-15
1299.
Denial of Service - Unknown Product (CVE-2020-24823) - Medium [398]
Description: {'vulners_cve_data_all': 'A vulnerability in the dwarf::to_string function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-24823 was patched at 2024-05-15
1300.
Denial of Service - Unknown Product (CVE-2020-24824) - Medium [398]
Description: {'vulners_cve_data_all': 'A global buffer overflow issue in the dwarf::line_table::line_table function of Libelfin v0.3 allows attackers to cause a denial of service (DOS).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-24824 was patched at 2024-05-15
1301.
Denial of Service - Unknown Product (CVE-2020-24825) - Medium [398]
Description: {'vulners_cve_data_all': 'A vulnerability in the line_table::line_table function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-24825 was patched at 2024-05-15
1302.
Denial of Service - Unknown Product (CVE-2020-24826) - Medium [398]
Description: {'vulners_cve_data_all': 'A vulnerability in the elf::section::as_strtab function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-24826 was patched at 2024-05-15
1303.
Denial of Service - Unknown Product (CVE-2020-24827) - Medium [398]
Description: {'vulners_cve_data_all': 'A vulnerability in the dwarf::cursor::skip_form function of Libelfin v0.3 allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted ELF file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-24827 was patched at 2024-05-15
1304.
Denial of Service - Unknown Product (CVE-2021-30027) - Medium [398]
Description: {'vulners_cve_data_all': 'md_analyze_line in md4c.c in md4c 0.4.7 allows attackers to trigger use of uninitialized memory, and cause a denial of service via a malformed Markdown document.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30027 was patched at 2024-05-15
1305.
Denial of Service - Unknown Product (CVE-2021-32275) - Medium [398]
Description: {'vulners_cve_data_all': 'An issue was discovered in faust through v2.30.5. A NULL pointer dereference exists in the function CosPrim::computeSigOutput() located in cosprim.hh. It allows an attacker to cause Denial of Service.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32275 was patched at 2024-05-15
1306.
Denial of Service - Unknown Product (CVE-2021-37529) - Medium [398]
Description: {'vulners_cve_data_all': 'A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which could cause a denial of service (context-dependent).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-37529 was patched at 2024-05-15
1307.
Denial of Service - Unknown Product (CVE-2021-37530) - Medium [398]
Description: {'vulners_cve_data_all': 'A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the open_stream function in readpics.c.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-37530 was patched at 2024-05-15
1308.
Denial of Service - Unknown Product (CVE-2021-4214) - Medium [398]
Description: {'vulners_cve_data_all': 'A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-4214 was patched at 2024-05-15
1309.
Denial of Service - Unknown Product (CVE-2023-42364) - Medium [398]
Description: {'vulners_cve_data_all': 'A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-42364 was patched at 2024-05-15
1310.
Incorrect Calculation - Unknown Product (CVE-2022-28048) - Medium [398]
Description: {'vulners_cve_data_all': 'STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Incorrect Calculation | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-28048 was patched at 2024-05-15
1311.
Information Disclosure - Unknown Product (CVE-2017-8761) - Medium [398]
Description: {'vulners_cve_data_all': 'In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-8761 was patched at 2024-05-15
1312.
Memory Corruption - Unknown Product (CVE-2017-2818) - Medium [398]
Description: {'vulners_cve_data_all': 'An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted PDF can cause an overly large number of color components during image rendering, resulting in heap corruption. An attacker controlled PDF file can be used to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Poppler PDF Image Display DCTStream::readProgressiveSOF() Code Execution Vulnerability(CVE-2017-2818)) | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2818 was patched at 2024-05-15
1313.
Memory Corruption - Unknown Product (CVE-2018-14550) - Medium [398]
Description: {'vulners_cve_data_all': 'An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-14550 was patched at 2024-05-15
1314.
Memory Corruption - Unknown Product (CVE-2018-20751) - Medium [398]
Description: {'vulners_cve_data_all': 'An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the function GetObject() being called for the pPage NULL pointer object. The value of pPage at this point is 0x0, which causes a NULL pointer dereference.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-20751 was patched at 2024-05-15
1315.
Memory Corruption - Unknown Product (CVE-2020-21547) - Medium [398]
Description: {'vulners_cve_data_all': 'Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-21547 was patched at 2024-05-15
1316.
Memory Corruption - Unknown Product (CVE-2020-21548) - Medium [398]
Description: {'vulners_cve_data_all': 'Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-21548 was patched at 2024-05-15
1317.
Memory Corruption - Unknown Product (CVE-2020-36403) - Medium [398]
Description: {'vulners_cve_data_all': 'HTSlib through 1.10.2 allows out-of-bounds write access in vcf_parse_format (called from vcf_parse and vcf_read).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-36403 was patched at 2024-05-15
1318.
Memory Corruption - Unknown Product (CVE-2020-36407) - Medium [398]
Description: {'vulners_cve_data_all': 'libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-36407 was patched at 2024-05-15
1319.
Memory Corruption - Unknown Product (CVE-2021-26195) - Medium [398]
Description: {'vulners_cve_data_all': 'An issue was discovered in JerryScript 2.4.0. There is a heap-buffer-overflow in lexer_parse_number in js-lexer.c file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-26195 was patched at 2024-05-15
1320.
Memory Corruption - Unknown Product (CVE-2021-32294) - Medium [398]
Description: {'vulners_cve_data_all': 'An issue was discovered in libgig through 20200507. A heap-buffer-overflow exists in the function RIFF::List::GetSubList located in RIFF.cpp. It allows an attacker to cause code Execution.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32294 was patched at 2024-05-15
1321.
Memory Corruption - Unknown Product (CVE-2023-5841) - Medium [398]
Description: {'vulners_cve_data_all': 'Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX\xa0image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions\xa0v3.2.2 and v3.1.12 of the affected library.\n', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-5841 was patched at 2024-05-15
1322.
Path Traversal - Unknown Product (CVE-2016-5537) - Medium [398]
Description: {'vulners_cve_data_all': 'Unspecified vulnerability in the NetBeans component in Oracle Fusion Middleware 8.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information is from the October 2016 CPU. Oracle has not commented on third-party claims that this issue is a directory traversal vulnerability which allows local users with certain permissions to write to arbitrary files and consequently gain privileges via a .. (dot dot) in a archive entry in a ZIP file imported as a project.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitdb] Oracle Netbeans IDE 8.1 - Directory Traversal, [exploitpack] Oracle Netbeans IDE 8.1 - Directory Traversal, [zdt] Oracle Netbeans IDE 8.1 Directory Traversal Vulnerability, [packetstorm] Oracle Netbeans IDE 8.1 Directory Traversal) | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-5537 was patched at 2024-05-15
1323.
Path Traversal - Unknown Product (CVE-2018-1002209) - Medium [398]
Description: {'vulners_cve_data_all': 'QuaZIP before 0.7.6 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-1002209 was patched at 2024-05-15
1324.
Elevation of Privilege - Linux Kernel (CVE-2020-25221) - Medium [397]
Description: get_gate_page in mm/gup.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-25221 was patched at 2024-05-15
1325.
Elevation of Privilege - Linux Kernel (CVE-2022-0998) - Medium [397]
Description: An integer overflow flaw was found in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-0998 was patched at 2024-05-15
1326.
Elevation of Privilege - Linux Kernel (CVE-2022-1976) - Medium [397]
Description: A flaw was found in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-1976 was patched at 2024-05-15
1327.
Elevation of Privilege - Linux Kernel (CVE-2022-3238) - Medium [397]
Description: A double-free flaw was found in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-3238 was patched at 2024-05-15
1328.
Elevation of Privilege - Linux Kernel (CVE-2022-3577) - Medium [397]
Description: An out-of-bounds memory write flaw was found in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-3577 was patched at 2024-05-15
1329.
Elevation of Privilege - Linux Kernel (CVE-2022-3910) - Medium [397]
Description: Use After Free vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-3910 was patched at 2024-05-15
1330.
Elevation of Privilege - Linux Kernel (CVE-2022-3977) - Medium [397]
Description: A use-after-free flaw was found in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-3977 was patched at 2024-05-15
1331.
Elevation of Privilege - Linux Kernel (CVE-2023-0030) - Medium [397]
Description: A use-after-free flaw was found in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-0030 was patched at 2024-05-15
1332.
Elevation of Privilege - Linux Kernel (CVE-2023-28464) - Medium [397]
Description: hci_conn_cleanup in net/bluetooth/hci_conn.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2023-28464 was patched at 2024-05-22
oraclelinux: CVE-2023-28464 was patched at 2024-05-02, 2024-05-23
redhat: CVE-2023-28464 was patched at 2024-05-22
1333.
Remote Code Execution - ImageMagick (CVE-2004-0981) - Medium [397]
Description: Buffer overflow in the EXIF parsing routine in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0981 was patched at 2024-05-15
1334.
Remote Code Execution - Perl (CVE-2002-1369) - Medium [397]
Description: jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-1369 was patched at 2024-05-15
1335.
Remote Code Execution - Perl (CVE-2003-0161) - Medium [397]
Description: The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0161 was patched at 2024-05-15
1336.
Remote Code Execution - Perl (CVE-2004-0414) - Medium [397]
Description: CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0414 was patched at 2024-05-15
1337.
Remote Code Execution - Perl (CVE-2004-0418) - Medium [397]
Description: serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0418 was patched at 2024-05-15
1338.
Remote Code Execution - Perl (CVE-2006-1615) - Medium [397]
Description: Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-1615 was patched at 2024-05-15
1339.
Remote Code Execution - Perl (CVE-2011-1930) - Medium [397]
Description: In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-1930 was patched at 2024-05-15
1340.
Remote Code Execution - Perl (CVE-2014-4657) - Medium [397]
Description: The safe_eval function in Ansible before 1.5.4 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-4657 was patched at 2024-05-15
1341.
Remote Code Execution - Perl (CVE-2014-4678) - Medium [397]
Description: The safe_eval function in Ansible before 1.6.4 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-4678 was patched at 2024-05-15
1342.
Remote Code Execution - Perl (CVE-2018-20752) - Medium [397]
Description: An issue was discovered in Recon-ng before 4.9.5. Lack of validation in the modules/reporting/csv.py file allows CSV injection. More specifically, when a Twitter user possesses an Excel macro for a username, it will not be pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-20752 was patched at 2024-05-15
1343.
Remote Code Execution - Perl (CVE-2018-9246) - Medium [397]
Description: The PGObject::Util::DBAdmin module before 0.120.0 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-9246 was patched at 2024-05-15
1344.
Remote Code Execution - Perl (CVE-2022-4170) - Medium [397]
Description: The rxvt-unicode package is vulnerable to a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-4170 was patched at 2024-05-15
1345.
Remote Code Execution - Python (CVE-2012-4406) - Medium [397]
Description: OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-4406 was patched at 2024-05-15
1346.
Remote Code Execution - Python (CVE-2014-3539) - Medium [397]
Description: base/oi/doa.py in the Rope library in C
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-3539 was patched at 2024-05-15
1347.
Remote Code Execution - Python (CVE-2016-4972) - Medium [397]
Description: OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-4972 was patched at 2024-05-15
1348.
Remote Code Execution - Python (CVE-2021-42343) - Medium [397]
Description: An issue was discovered in the Dask distributed package before 2021.10.0 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-42343 was patched at 2024-05-15
1349.
Remote Code Execution - Python (CVE-2023-37271) - Medium [397]
Description: Restricted
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 1.0 | 10 | CVSS Base Score is 9.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-37271 was patched at 2024-05-15
1350.
Remote Code Execution - Wireshark (CVE-2006-3628) - Medium [397]
Description: Multiple format string vulnerabilities in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3628 was patched at 2024-05-15
1351.
Remote Code Execution - Wireshark (CVE-2006-3632) - Medium [397]
Description: Buffer overflow in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3632 was patched at 2024-05-15
1352.
Remote Code Execution - libxml2 (CVE-2004-0989) - Medium [397]
Description: Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | libxml2 is an XML toolkit implemented in C, originally developed for the GNOME Project | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0989 was patched at 2024-05-15
1353.
Unknown Vulnerability Type - Bouncy Castle (CVE-2020-28052) - Medium [397]
Description: {'vulners_cve_data_all': 'An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for CVE-2020-28052, [githubexploit] Exploit for CVE-2020-28052) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Bouncy Castle is a collection of APIs used in cryptography | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-28052 was patched at 2024-05-15
1354.
Unknown Vulnerability Type - Eclipse Mosquitto (CVE-2021-34432) - Medium [397]
Description: {'vulners_cve_data_all': 'In Eclipse Mosquitto versions 2.07 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Eclipse Mosquitto provides a lightweight server implementation of the MQTT protocol that is suitable for all situations from full power machines to embedded and low power machines | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-34432 was patched at 2024-05-15
1355.
Unknown Vulnerability Type - Nokogiri (CVE-2022-29181) - Medium [397]
Description: {'vulners_cve_data_all': 'Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a `String` by calling `#to_s` or equivalent.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Nokogiri is an open source XML and HTML library for the Ruby programming language | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-29181 was patched at 2024-05-15
1356.
Unknown Vulnerability Type - Perl (CVE-2006-6171) - Medium [397]
Description: {'vulners_cve_data_all': 'ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which leads to an off-by-two buffer underflow. NOTE: in November 2006, the role of CommandBufferSize was originally associated with CVE-2006-5815, but this was an error stemming from a vague initial disclosure. NOTE: ProFTPD developers dispute this issue, saying that the relevant memory location is overwritten by assignment before further use within the affected function, so this is not a vulnerability', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] vd_proftpd.pm.txt, [packetstorm] ProFTPD 1.2 - 1.3.0 sreplace Buffer Overflow (Linux)) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-6171 was patched at 2024-05-15
1357.
Unknown Vulnerability Type - Perl (CVE-2009-2702) - Medium [397]
Description: {'vulners_cve_data_all': 'KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Mozilla Firefox NULL字符CA SSL证书验证安全绕过漏洞, [exploitdb] Mozilla NSS NULL Character CA SSL Certificate Validation Security Bypass Vulnerability) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2702 was patched at 2024-05-15
1358.
Unknown Vulnerability Type - Perl (CVE-2009-3475) - Medium [397]
Description: {'vulners_cve_data_all': 'Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly handle a '\\0' character in the subject or subjectAltName fields of a certificate, which allows remote man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Mozilla Firefox NULL字符CA SSL证书验证安全绕过漏洞, [seebug] Randombit Botan Library X509 Certificate Validation Bypass Vulnerability(CVE-2017-2801), [seebug] mozilla-thunderbird多个安全漏洞, [exploitdb] Mozilla NSS NULL Character CA SSL Certificate Validation Security Bypass Vulnerability) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3475 was patched at 2024-05-15
1359.
Unknown Vulnerability Type - Perl (CVE-2011-1762) - Medium [397]
Description: {'vulners_cve_data_all': 'A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object) website | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-1762 was patched at 2024-05-15
1360.
Unknown Vulnerability Type - Perl (CVE-2011-4116) - Medium [397]
Description: {'vulners_cve_data_all': '_is_safe in the File::Temp module for Perl does not properly handle symlinks.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4116 was patched at 2024-05-15
1361.
Unknown Vulnerability Type - Perl (CVE-2012-1102) - Medium [397]
Description: {'vulners_cve_data_all': 'It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depending on how the library is used.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1102 was patched at 2024-05-15
1362.
Unknown Vulnerability Type - Perl (CVE-2021-29424) - Medium [397]
Description: {'vulners_cve_data_all': 'The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-29424 was patched at 2024-05-15
1363.
Unknown Vulnerability Type - Perl (CVE-2021-29662) - Medium [397]
Description: {'vulners_cve_data_all': 'The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-29662 was patched at 2024-05-15
1364.
Unknown Vulnerability Type - Perl (CVE-2022-25640) - Medium [397]
Description: {'vulners_cve_data_all': 'In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handshake, and never present a certificate.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Improper Certificate Validation in Wolfssl) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-25640 was patched at 2024-05-15
1365.
Unknown Vulnerability Type - Wireshark (CVE-2017-9347) - Medium [397]
Description: {'vulners_cve_data_all': 'In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-template.c by validating an OID.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Wireshark 2.2.0 to 2.2.12 - ROS Dissector Denial of Service Vulnerability) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-9347 was patched at 2024-05-15
1366.
Unknown Vulnerability Type - Wireshark (CVE-2017-9353) - Medium [397]
Description: {'vulners_cve_data_all': 'In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by validating an IPv6 address.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Wireshark 2.2.6 - IPv6 Dissector Denial of Service Vulnerability) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-9353 was patched at 2024-05-15
1367.
Unknown Vulnerability Type - Wireshark (CVE-2020-7044) - Medium [397]
Description: {'vulners_cve_data_all': 'In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-7044 was patched at 2024-05-15
1368.
Security Feature Bypass - Apache Traffic Server (CVE-2015-5168) - Medium [396]
Description: {'vulners_cve_data_all': 'Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5206.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.7 | 14 | The Apache Traffic Server is a modular, high-performance reverse proxy and forward proxy server, generally comparable to Nginx and Squid | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-5168 was patched at 2024-05-15
1369.
Security Feature Bypass - Apache Traffic Server (CVE-2015-5206) - Medium [396]
Description: {'vulners_cve_data_all': 'Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5168.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.7 | 14 | The Apache Traffic Server is a modular, high-performance reverse proxy and forward proxy server, generally comparable to Nginx and Squid | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-5206 was patched at 2024-05-15
1370.
Arbitrary File Writing - Unknown Product (CVE-2004-0996) - Medium [395]
Description: {'vulners_cve_data_all': 'main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Mac OS X 2007-007更新修复多个安全漏洞) | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0 | 14 | Unknown Product | |
| 0.2 | 10 | CVSS Base Score is 2.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0996 was patched at 2024-05-15
1371.
Arbitrary File Writing - Unknown Product (CVE-2013-0162) - Medium [395]
Description: {'vulners_cve_data_all': 'The diff_pp function in lib/gauntlet_rubyparser.rb in the ruby_parser gem 3.1.1 and earlier for Ruby allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] RubyGems 'ruby_parser' 不安全临时文件创建漏洞(CVE-2013-0162)) | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0 | 14 | Unknown Product | |
| 0.2 | 10 | CVSS Base Score is 2.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-0162 was patched at 2024-05-15
1372.
Remote Code Execution - APT (CVE-2003-0542) - Medium [395]
Description: Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0542 was patched at 2024-05-15
1373.
Remote Code Execution - APT (CVE-2008-0302) - Medium [395]
Description: Untrusted search path vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-0302 was patched at 2024-05-15
1374.
Remote Code Execution - GNOME desktop (CVE-2007-6183) - Medium [395]
Description: Format string vulnerability in the mdiag_initialize function in gtk/src/rbgtkmessagedialog.c in Ruby-
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-6183 was patched at 2024-05-15
1375.
Remote Code Execution - GNOME desktop (CVE-2011-5244) - Medium [395]
Description: Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-5244 was patched at 2024-05-15
1376.
Remote Code Execution - GNU C Library (CVE-2007-3508) - Medium [395]
Description: Integer overflow in the process_envvars function in elf/rtld.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-3508 was patched at 2024-05-15
1377.
Remote Code Execution - GNU C Library (CVE-2008-2357) - Medium [395]
Description: Stack-based buffer overflow in the split_redraw function in split.c in mtr before 0.73, when invoked with the -p (aka --split) option, allows remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The GNU C Library, commonly known as glibc, is the GNU Project's implementation of the C standard library | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-2357 was patched at 2024-05-15
1378.
Remote Code Execution - Mozilla Firefox (CVE-2006-1733) - Medium [395]
Description: Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-1733 was patched at 2024-05-15
1379.
Remote Code Execution - Mozilla Firefox (CVE-2006-1734) - Medium [395]
Description: Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-1734 was patched at 2024-05-15
1380.
Remote Code Execution - Mozilla Firefox (CVE-2006-6497) - Medium [395]
Description: Multiple unspecified vulnerabilities in the layout engine for Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-6497 was patched at 2024-05-15
1381.
Remote Code Execution - Mozilla Firefox (CVE-2006-6498) - Medium [395]
Description: Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-6498 was patched at 2024-05-15
1382.
Remote Code Execution - Safari (CVE-2015-7096) - Medium [395]
Description: WebKit in Apple iOS before 9.2,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-7096 was patched at 2024-05-15
1383.
Remote Code Execution - Safari (CVE-2015-7098) - Medium [395]
Description: WebKit in Apple iOS before 9.2,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-7098 was patched at 2024-05-15
1384.
Remote Code Execution - Visual Basic for Applications (CVE-2011-1003) - Medium [395]
Description: Double free vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Visual Basic for Applications is a computer programming language developed and owned by Microsoft | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-1003 was patched at 2024-05-15
1385.
Remote Code Execution - WinRAR (CVE-2007-0855) - Medium [395]
Description: Stack-based buffer overflow in RARLabs Unrar, as packaged in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | WinRAR is a trialware file archiver utility for Windows, developed by Eugene Roshal of win.rar GmbH | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-0855 was patched at 2024-05-15
1386.
Unknown Vulnerability Type - APT (CVE-2009-3584) - Medium [395]
Description: {'vulners_cve_data_all': 'SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] SQL-Ledger ERP多个输入验证和绕过安全限制漏洞, [packetstorm] SQL-Ledger XSS / XSRF / SQL Injection / LFI) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3584 was patched at 2024-05-15
1387.
Unknown Vulnerability Type - GNOME desktop (CVE-2013-7220) - Medium [395]
Description: {'vulners_cve_data_all': 'js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with the keyboard focus on the Activities search.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] GNOME gnome-shell本地任意命令执行漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-7220 was patched at 2024-05-15
1388.
Unknown Vulnerability Type - OpenSSH (CVE-2003-0190) - Medium [395]
Description: {'vulners_cve_data_all': 'OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Portable OpenSSH 3.6.1p-PAM4.1-SuSE - Timing Attack, [packetstorm] openssh-timing.txt, [seebug] Portable OpenSSH <= 3.6.1p-PAM / 4.1-SUSE Timing Attack Exploit, [seebug] Portable OpenSSH <= 3.6.1p-PAM / 4.1-SUSE Timing Attack Exploit, [seebug] Portable OpenSSH <= 3.6.1p-PAM / 4.1-SUSE Timing Attack Exploit, [exploitdb] Portable OpenSSH 3.6.1p-PAM/4.1-SuSE - Timing Attack) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0190 was patched at 2024-05-15
1389.
Unknown Vulnerability Type - OpenSSH (CVE-2006-0225) - Medium [395]
Description: {'vulners_cve_data_all': 'scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Avaya CMS / IR Solaris scp命令行shell命令注入漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-0225 was patched at 2024-05-15
1390.
Unknown Vulnerability Type - OpenSSH (CVE-2007-2243) - Medium [395]
Description: {'vulners_cve_data_all': 'OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] OpenSSH s/key Weakness) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-2243 was patched at 2024-05-15
1391.
Unknown Vulnerability Type - OpenSSL (CVE-2009-0126) - Medium [395]
Description: {'vulners_cve_data_all': 'The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenSSL 'EVP_VerifyFinal'函数签名验证漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0126 was patched at 2024-05-15
1392.
Unknown Vulnerability Type - OpenSSL (CVE-2009-0127) - Medium [395]
Description: {'vulners_cve_data_all': 'M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a Linux vendor disputes the relevance of this report to the M2Crypto product because "these functions are not used anywhere in m2crypto.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenSSL 'EVP_VerifyFinal'函数签名验证漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0127 was patched at 2024-05-15
1393.
Unknown Vulnerability Type - OpenSSL (CVE-2009-0128) - Medium [395]
Description: {'vulners_cve_data_all': 'plugins/crypto/openssl/crypto_openssl.c in Simple Linux Utility for Resource Management (aka SLURM or slurm-llnl) does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenSSL 'EVP_VerifyFinal'函数签名验证漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0128 was patched at 2024-05-15
1394.
Unknown Vulnerability Type - OpenSSL (CVE-2009-0129) - Medium [395]
Description: {'vulners_cve_data_all': 'libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenSSL 'EVP_VerifyFinal'函数签名验证漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0129 was patched at 2024-05-15
1395.
Unknown Vulnerability Type - OpenSSL (CVE-2009-0130) - Medium [395]
Description: {'vulners_cve_data_all': 'lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a package maintainer disputes this issue, reporting that there is a proper check within the only code that uses the applicable part of crypto_drv.c, and thus "this report is invalid.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenSSL 'EVP_VerifyFinal'函数签名验证漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0130 was patched at 2024-05-15
1396.
Unknown Vulnerability Type - PHP (CVE-2009-4605) - Medium [395]
Description: {'vulners_cve_data_all': 'scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin unserialize()调用跨站请求伪造漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4605 was patched at 2024-05-15
1397.
Unknown Vulnerability Type - PHP (CVE-2011-4898) - Medium [395]
Description: {'vulners_cve_data_all': 'wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier generates different error messages for requests lacking a dbname parameter depending on whether the MySQL credentials are valid, which makes it easier for remote attackers to conduct brute-force attacks via a series of requests with different uname and pwd parameters. NOTE: the vendor disputes the significance of this issue; also, it is unclear whether providing intentionally vague error messages during installation would be reasonable from a usability perspective', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] WordPress 3.3.1 - Multiple Vulnerabilities, [seebug] wordpress <= 3.3.1 - Multiple Vulnerabilities, [seebug] WordPress 3.3.1 Code Execution / Cross Site Scripting, [packetstorm] WordPress 3.3.1 Code Execution / Cross Site Scripting, [exploitdb] WordPress Core 3.3.1 - Multiple Vulnerabilities) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4898 was patched at 2024-05-15
1398.
Unknown Vulnerability Type - PHP (CVE-2022-39291) - Medium [395]
Description: {'vulners_cve_data_all': 'ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are subject to a vulnerability which allows users with "View" system permissions to inject new data into the logs stored by Zoneminder. This was observed through an HTTP POST request containing log information to the "/zm/index.php" endpoint. Submission is not rate controlled and could affect database performance and/or consume all storage resources. Users are advised to upgrade. There are no known workarounds for this issue.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Zoneminder Log Injection / XSS / Cross Site Request Forgery, [zdt] Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass Exploit, [exploitdb] Zoneminder < v1.37.24 - Log Injection & Stored XSS & CSRF Bypass) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-39291 was patched at 2024-05-15
1399.
Unknown Vulnerability Type - Safari (CVE-2009-1696) - Medium [395]
Description: {'vulners_cve_data_all': 'WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 uses predictable random numbers in JavaScript applications, which makes it easier for remote web servers to track the behavior of a Safari user during a session.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Firefox JavaScript引擎Math.Random()跨域信息泄露漏洞, [seebug] Apple Safari 4.0多个安全漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1696 was patched at 2024-05-15
1400.
Unknown Vulnerability Type - Safari (CVE-2009-2841) - Medium [395]
Description: {'vulners_cve_data_all': 'The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before r49480, as used in Apple Safari before 4.0.4 on Mac OS X, does not perform the expected callbacks for HTML 5 media elements that have external URLs for media resources, which allows remote attackers to trigger sub-resource requests to arbitrary web sites via a crafted HTML document, as demonstrated by an HTML e-mail message that uses a media element for X-Confirm-Reading-To functionality, aka rdar problem 7271202.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] WebKit资源装载回调信息泄漏漏洞, [seebug] Safari 4.0.4版本修复多个安全漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2841 was patched at 2024-05-15
1401.
Authentication Bypass - Perl (CVE-2015-5053) - Medium [394]
Description: {'vulners_cve_data_all': 'The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for GRID vGPU and vSGA does not properly restrict access to third-party device IO memory, which allows attackers to gain privileges, cause a denial of service (resource consumption), or possibly have unspecified other impact via unknown vectors related to the follow_pfn kernel-mode API call.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-5053 was patched at 2024-05-15
1402.
Denial of Service - Linux Kernel (CVE-2016-10150) - Medium [394]
Description: Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-10150 was patched at 2024-05-15
1403.
Denial of Service - Linux Kernel (CVE-2018-5703) - Medium [394]
Description: The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-5703 was patched at 2024-05-15
1404.
Denial of Service - Windows Kernel (CVE-2016-4608) - Medium [394]
Description: libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | Windows Kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-4608 was patched at 2024-05-15
1405.
Path Traversal - Windows Kernel (CVE-2020-27304) - Medium [394]
Description: The CivetWeb web library does not validate uploaded filepaths when running on an OS other than
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.9 | 14 | Windows Kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-27304 was patched at 2024-05-15
1406.
Security Feature Bypass - Active Directory (CVE-2018-1140) - Medium [394]
Description: {'vulners_cve_data_all': 'A missing input sanitization flaw was found in the implementation of LDP database used for the LDAP server. An attacker could use this flaw to cause a denial of service against a samba server, used as a Active Directory Domain Controller. All versions of Samba from 4.8.0 onwards are vulnerable', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | Active Directory is a directory service developed by Microsoft for Windows domain networks | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-1140 was patched at 2024-05-15
1407.
Security Feature Bypass - Linux Kernel (CVE-2018-1000028) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-1000028 was patched at 2024-05-15
1408.
Arbitrary File Reading - Windows Kernel (CVE-2002-0661) - Medium [393]
Description: Directory traversal vulnerability in Apache 2.0 through 2.0.39 on
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.9 | 14 | Windows Kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-0661 was patched at 2024-05-15
1409.
Information Disclosure - Windows Kernel (CVE-2022-28183) - Medium [393]
Description: NVIDIA GPU Display Driver for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | Windows Kernel | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-28183 was patched at 2024-05-15
1410.
Code Injection - Perl (CVE-2023-26037) - Medium [392]
Description: ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 contain an
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-26037 was patched at 2024-05-15
1411.
Code Injection - ReadyMedia (CVE-2013-2738) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.6 | 14 | ReadyMedia (formerly known as MiniDLNA) is a simple media server software, with the aim of being fully compliant with DLNA/UPnP-AV clients | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-2738 was patched at 2024-05-15
1412.
Code Injection - ReadyMedia (CVE-2013-2745) - Medium [392]
Description: An
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.6 | 14 | ReadyMedia (formerly known as MiniDLNA) is a simple media server software, with the aim of being fully compliant with DLNA/UPnP-AV clients | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-2745 was patched at 2024-05-15
1413.
Command Injection - Python (CVE-2022-24065) - Medium [392]
Description: The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-24065 was patched at 2024-05-15
1414.
Cross Site Scripting - Unknown Product (CVE-2008-3328) - Medium [392]
Description: {'vulners_cve_data_all': 'Cross-site scripting (XSS) vulnerability in the wiki engine in Trac before 0.10.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Trac Wiki引擎跨站脚本执行漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3328 was patched at 2024-05-15
1415.
Cross Site Scripting - Unknown Product (CVE-2008-3714) - Medium [392]
Description: {'vulners_cve_data_all': 'Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] AWStats awstats.pl跨站脚本漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3714 was patched at 2024-05-15
1416.
Cross Site Scripting - Unknown Product (CVE-2009-2324) - Medium [392]
Description: {'vulners_cve_data_all': 'Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitrary web script or HTML via components in the samples (aka _samples) directory.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] FCKeditor connectors模块多个跨站脚本及目录遍历漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2324 was patched at 2024-05-15
1417.
Cross Site Scripting - Unknown Product (CVE-2009-3009) - Medium [392]
Description: {'vulners_cve_data_all': 'Cross-site scripting (XSS) vulnerability in Ruby on Rails 2.x before 2.2.3, and 2.3.x before 2.3.4, allows remote attackers to inject arbitrary web script or HTML by placing malformed Unicode strings into a form helper.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Ruby on Rails表单帮助程序Unicode字符串处理跨站脚本漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3009 was patched at 2024-05-15
1418.
Cross Site Scripting - Unknown Product (CVE-2011-0446) - Medium [392]
Description: {'vulners_cve_data_all': 'Multiple cross-site scripting (XSS) vulnerabilities in the mail_to helper in Ruby on Rails before 2.3.11, and 3.x before 3.0.4, when javascript encoding is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) name or (2) email value.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Ruby on Rails跨站脚本执行及跨站请求伪造漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-0446 was patched at 2024-05-15
1419.
Cross Site Scripting - Unknown Product (CVE-2011-4024) - Medium [392]
Description: {'vulners_cve_data_all': 'Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] OCS Inventory NG 2.0.1 - Persistent Cross-Site Scripting, [packetstorm] OCS Inventory NG 2.0.1 Cross Site Scripting, [seebug] OCS Inventory NG 2.0.1 Persistent XSS, [exploitdb] OCS Inventory NG 2.0.1 - Persistent Cross-Site Scripting) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4024 was patched at 2024-05-15
1420.
Cross Site Scripting - Unknown Product (CVE-2011-4969) - Medium [392]
Description: {'vulners_cve_data_all': 'Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4969 was patched at 2024-05-15
1421.
Cross Site Scripting - Unknown Product (CVE-2012-3414) - Medium [392]
Description: {'vulners_cve_data_all': 'Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Dotclear XSS Vulnerabilities, [zdt] Wordpress Plugin (wp-e-commerce v3.8.9.5) Multiple Vulnerabilities, [seebug] Turbomail邮件系统XSS-1, [packetstorm] WordPress 3.3.1 swfupload.swf Cross Site Scripting, [packetstorm] SWF Upload Cross Site Scripting, [packetstorm] Dotclear 2.4.4 Cross Site Scripting / Content Spoofing, [packetstorm] WordPress E-Commerce 3.8.9.5 File Upload / XSS / CSRF / Code Execution) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-3414 was patched at 2024-05-15
1422.
Cross Site Scripting - Unknown Product (CVE-2012-3442) - Medium [392]
Description: {'vulners_cve_data_all': 'The (1) django.http.HttpResponseRedirect and (2) django.http.HttpResponsePermanentRedirect classes in Django before 1.3.2 and 1.4.x before 1.4.1 do not validate the scheme of a redirect target, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via a data: URL.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Django跨站脚本执行和两个拒绝服务漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-3442 was patched at 2024-05-15
1423.
Cross Site Scripting - Unknown Product (CVE-2012-3465) - Medium [392]
Description: {'vulners_cve_data_all': 'Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Ruby on Rails 'strip_tags()'跨站脚本执行漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-3465 was patched at 2024-05-15
1424.
Cross Site Scripting - Unknown Product (CVE-2012-4751) - Medium [392]
Description: {'vulners_cve_data_all': 'Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x before 3.0.17, and 3.1.x before 3.1.11 allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with whitespace before a javascript: URL in the SRC attribute of an element, as demonstrated by an IFRAME element.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] OTRS 3.1 Cross Site Scripting) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-4751 was patched at 2024-05-15
1425.
Cross Site Scripting - Unknown Product (CVE-2012-6550) - Medium [392]
Description: {'vulners_cve_data_all': 'Cross-site scripting (XSS) vulnerability in ZeroClipboard before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via "the clipText returned from the flash object," a different vulnerability than CVE-2013-1808.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([wpexploit] slidedeck2 < 2.1.20130313 - XSS in ZeroClipboard, [packetstorm] ZeroClipbord.swf Cross Site Scripting / Path Disclosure, [zdt] ZeroClipboard Wordpress plugin XSS / FPD Vulnerabilities) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-6550 was patched at 2024-05-15
1426.
Cross Site Scripting - Unknown Product (CVE-2013-1808) - Medium [392]
Description: {'vulners_cve_data_all': 'Cross-site scripting (XSS) vulnerability in ZeroClipboard.swf and ZeroClipboard10.swf in ZeroClipboard before 1.0.8, as used in em-shorty, RepRapCalculator, Fulcrum, Django, aCMS, and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this is might be the same vulnerability as CVE-2013-1463. If so, it is likely that CVE-2013-1463 will be REJECTed.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([wpexploit] slidedeck2 < 2.1.20130313 - XSS in ZeroClipboard, [packetstorm] ZeroClipbord.swf Cross Site Scripting / Path Disclosure, [packetstorm] WordPress WP-Table-Reloaded Cross Site Scripting, [zdt] ZeroClipboard Wordpress plugin XSS / FPD Vulnerabilities) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-1808 was patched at 2024-05-15
1427.
Cross Site Scripting - Unknown Product (CVE-2013-4249) - Medium [392]
Description: {'vulners_cve_data_all': 'Cross-site scripting (XSS) vulnerability in the AdminURLFieldWidget widget in contrib/admin/widgets.py in Django 1.5.x before 1.5.2 and 1.6.x before 1.6 beta 2 allows remote attackers to inject arbitrary web script or HTML via a URLField.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Django is_safe_url() 跨站脚本 和 URLField 脚本插入漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-4249 was patched at 2024-05-15
1428.
Cross Site Scripting - Unknown Product (CVE-2014-0157) - Medium [392]
Description: {'vulners_cve_data_all': 'Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenStack Horizon Orchestration Dashboard栈模版描述字段存储型跨站脚本漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-0157 was patched at 2024-05-15
1429.
Elevation of Privilege - RPC (CVE-2021-37219) - Medium [392]
Description: HashiCorp Consul and Consul Enterprise 1.10.1 Raft
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-37219 was patched at 2024-05-15
1430.
Remote Code Execution - Kerberos (CVE-2010-1320) - Medium [392]
Description: Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.4 | 10 | CVSS Base Score is 4.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-1320 was patched at 2024-05-15
1431.
Unknown Vulnerability Type - Cacti (CVE-2009-4112) - Medium [392]
Description: {'vulners_cve_data_all': 'Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memory Usage" setting to contain arbitrary commands.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] New cacti packages fix insufficient input sanitising) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.9 | 10 | CVSS Base Score is 9.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4112 was patched at 2024-05-15
1432.
XXE Injection - Apache ActiveMQ (CVE-2014-3600) - Medium [392]
Description: XML external entity (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | XXE Injection | |
| 0.6 | 14 | Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-3600 was patched at 2024-05-15
1433.
Authentication Bypass - Chromium (CVE-2021-30619) - Medium [391]
Description: {'vulners_cve_data_all': 'Chromium: CVE-2021-30619 UI Spoofing in Autofill', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30619 was patched at 2024-05-15
1434.
Authentication Bypass - Chromium (CVE-2021-30621) - Medium [391]
Description: {'vulners_cve_data_all': 'Chromium: CVE-2021-30621 UI Spoofing in Autofill', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30621 was patched at 2024-05-15
1435.
Remote Code Execution - Babel (CVE-2022-37331) - Medium [390]
Description: An out-of-bounds write vulnerability exists in the Gaussian format orientation functionality of Open
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-37331 was patched at 2024-05-15
1436.
Remote Code Execution - Babel (CVE-2022-43607) - Medium [390]
Description: An out-of-bounds write vulnerability exists in the MOL2 format attribute and value functionality of Open
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-43607 was patched at 2024-05-15
1437.
Remote Code Execution - Curl (CVE-2005-3185) - Medium [390]
Description: Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2)
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Curl is a command-line tool for transferring data specified with URL syntax | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-3185 was patched at 2024-05-15
1438.
Remote Code Execution - FFmpeg (CVE-2006-4800) - Medium [390]
Description: Multiple buffer overflows in libavcodec in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4800 was patched at 2024-05-15
1439.
Remote Code Execution - FFmpeg (CVE-2011-4351) - Medium [390]
Description: Buffer overflow in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4351 was patched at 2024-05-15
1440.
Remote Code Execution - FFmpeg (CVE-2012-5361) - Medium [390]
Description: Libavcodec in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-5361 was patched at 2024-05-15
1441.
Remote Code Execution - FFmpeg (CVE-2016-6671) - Medium [390]
Description: The raw_decode function in libavcodec/rawdec.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-6671 was patched at 2024-05-15
1442.
Remote Code Execution - MediaWiki (CVE-2004-1405) - Medium [390]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-1405 was patched at 2024-05-15
1443.
Remote Code Execution - QEMU (CVE-2024-3446) - Medium [390]
Description: A double free vulnerability was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | QEMU is a generic and open source machine & userspace emulator and virtualizer | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-3446 was patched at 2024-05-15
debian: CVE-2024-34462 was patched at 2024-05-15
1444.
Remote Code Execution - SQLite (CVE-2007-1888) - Medium [390]
Description: Buffer overflow in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | SQLite is a database engine written in the C programming language | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-1888 was patched at 2024-05-15
1445.
Unknown Vulnerability Type - MediaWiki (CVE-2014-2243) - Medium [390]
Description: {'vulners_cve_data_all': 'includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 terminates validation of a user token upon encountering the first incorrect character, which makes it easier for remote attackers to obtain access via a brute-force attack that relies on timing differences in responses to incorrect token guesses.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MediaWiki 'theloadFromSession'函数信息泄露漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-2243 was patched at 2024-05-15
1446.
Security Feature Bypass - APT (CVE-2016-8614) - Medium [389]
Description: A flaw was found in Ansible before version 2.2.0. The
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-8614 was patched at 2024-05-15
1447.
Security Feature Bypass - APT (CVE-2021-36367) - Medium [389]
Description: {'vulners_cve_data_all': 'PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a later spoofed authentication prompt (that the attacker can use to capture credential data, and use that data for purposes that are undesired by the client user).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-36367 was patched at 2024-05-15
1448.
Security Feature Bypass - Google Chrome (CVE-2021-30577) - Medium [389]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30577 was patched at 2024-05-15
1449.
Security Feature Bypass - OpenSSL (CVE-2017-3733) - Medium [389]
Description: {'vulners_cve_data_all': 'During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-3733 was patched at 2024-05-15
1450.
Security Feature Bypass - PHP (CVE-2017-7189) - Medium [389]
Description: {'vulners_cve_data_all': 'main/streams/xp_socket.c in PHP 7.x before 2017-03-07 misparses fsockopen calls, such as by interpreting fsockopen('127.0.0.1:80', 443) as if the address/port were 127.0.0.1:80:443, which is later truncated to 127.0.0.1:80. This behavior has a security risk if the explicitly provided port number (i.e., 443 in this example) is hardcoded into an application as a security policy, but the hostname argument (i.e., 127.0.0.1:80 in this example) is obtained from untrusted input.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-7189 was patched at 2024-05-15
1451.
Elevation of Privilege - Kubernetes (CVE-2017-1000056) - Medium [387]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.7 | 14 | Kubernetes is an open-source container orchestration system for automating software deployment, scaling, and management | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-1000056 was patched at 2024-05-15
1452.
Arbitrary File Writing - APT (CVE-2008-4987) - Medium [386]
Description: xastir 1.9.2 allows local users to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-4987 was patched at 2024-05-15
1453.
Authentication Bypass - BIND (CVE-2014-0074) - Medium [386]
Description: Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-0074 was patched at 2024-05-15
1454.
Authentication Bypass - BIND (CVE-2014-3999) - Medium [386]
Description: The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-3999 was patched at 2024-05-15
1455.
Authentication Bypass - BIND (CVE-2017-14623) - Medium [386]
Description: {'vulners_cve_data_all': 'In the ldap.v2 (aka go-ldap) package through 2.5.0 for Go, an attacker may be able to login with an empty password. This issue affects an application using this package if these conditions are met: (1) it relies only on the return error of the Bind function call to determine whether a user is authorized (i.e., a nil return value is interpreted as successful authorization) and (2) it is used with an LDAP server allowing unauthenticated bind.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-14623 was patched at 2024-05-15
1456.
Denial of Service - Kerberos (CVE-2010-0283) - Medium [386]
Description: The Key Distribution Center (KDC) in MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-0283 was patched at 2024-05-15
1457.
Denial of Service - Kerberos (CVE-2011-4151) - Medium [386]
Description: The krb5_db2_lockout_audit function in the Key Distribution Center (KDC) in MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4151 was patched at 2024-05-15
1458.
Denial of Service - Kerberos (CVE-2018-16807) - Medium [386]
Description: In Bro through 2.5.5, there is a memory leak potentially leading to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-16807 was patched at 2024-05-15
1459.
Denial of Service - Kerberos (CVE-2018-16853) - Medium [386]
Description: Samba from version 4.7.0 has a vulnerability that allows a user in a Samba AD domain
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-16853 was patched at 2024-05-15
1460.
Denial of Service - Kerberos (CVE-2019-12175) - Medium [386]
Description: In Zeek Network Security Monitor (formerly known as Bro) before 2.6.2, a NULL pointer dereference in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-12175 was patched at 2024-05-15
1461.
Denial of Service - Unknown Product (CVE-2003-0108) - Medium [386]
Description: {'vulners_cve_data_all': 'isakmp_sub_print in tcpdump 3.6 through 3.7.1 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed ISAKMP packet to UDP port 500, which causes tcpdump to enter an infinite loop.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] tcpdump - ISAKMP Identification Payload Integer Overflow, [seebug] tcpdump ISAKMP Identification payload Integer Overflow Exploit, [exploitdb] tcpdump - ISAKMP Identification Payload Integer Overflow) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0108 was patched at 2024-05-15
1462.
Denial of Service - Unknown Product (CVE-2003-0540) - Medium [386]
Description: {'vulners_cve_data_all': 'The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Postfix 1.1.x - Denial of Service (2), [exploitpack] Postfix 1.1.x - Denial of Service (1), [seebug] Postfix 1.1.x Denial of Service Vulnerabilities (1), [seebug] Postfix 1.1.x Denial of Service Vulnerabilities (2), [exploitdb] Postfix 1.1.x - Denial of Service (1), [exploitdb] Postfix 1.1.x - Denial of Service (2)) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0540 was patched at 2024-05-15
1463.
Denial of Service - Unknown Product (CVE-2004-0184) - Medium [386]
Description: {'vulners_cve_data_all': 'Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] tcpdump - ISAKMP Identification Payload Integer Overflow, [seebug] tcpdump ISAKMP Identification payload Integer Overflow Exploit, [exploitdb] tcpdump - ISAKMP Identification Payload Integer Overflow) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0184 was patched at 2024-05-15
1464.
Denial of Service - Unknown Product (CVE-2004-0230) - Medium [386]
Description: {'vulners_cve_data_all': 'TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0230 was patched at 2024-05-15
1465.
Denial of Service - Unknown Product (CVE-2004-0942) - Medium [386]
Description: {'vulners_cve_data_all': 'Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apache <= 2.0.52 HTTP GET request Denial of Service Exploit, [seebug] Apache <= 2.0.52 HTTP GET request Denial of Service Exploit, [packetstorm] slmail5x.txt, [exploitpack] Apache 2.0.52 - GET Denial of Service, [exploitdb] Apache 2.0.52 - GET Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0942 was patched at 2024-05-15
1466.
Denial of Service - Unknown Product (CVE-2005-3357) - Medium [386]
Description: {'vulners_cve_data_all': 'mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apache Mod_SSL可定制错误文档拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-3357 was patched at 2024-05-15
1467.
Denial of Service - Unknown Product (CVE-2006-4334) - Medium [386]
Description: {'vulners_cve_data_all': 'Unspecified vulnerability in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (crash) via a crafted GZIP (gz) archive, which results in a NULL dereference.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2006-007存在多个安全漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4334 was patched at 2024-05-15
1468.
Denial of Service - Unknown Product (CVE-2006-4338) - Medium [386]
Description: {'vulners_cve_data_all': 'unlzh.c in the LHZ component in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted GZIP archive.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2006-007存在多个安全漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4338 was patched at 2024-05-15
1469.
Denial of Service - Unknown Product (CVE-2007-3126) - Medium [386]
Description: {'vulners_cve_data_all': 'Gimp before 2.8.22 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a similar issue to CVE-2007-2237.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MS Windows GDI+ ICO File - Remote Denial of Service Exploit, [seebug] MS Windows GDI+ ICO File Remote Denial of Service Exploit, [exploitpack] Microsoft Windows - GDI+ .ICO File Remote Denial of Service, [exploitdb] Microsoft Windows - GDI+ '.ICO' File Remote Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-3126 was patched at 2024-05-15
1470.
Denial of Service - Unknown Product (CVE-2007-3764) - Medium [386]
Description: {'vulners_cve_data_all': 'The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a certain data length value in a crafted packet, which results in an "overly large memcpy."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Asterisk多个远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-3764 was patched at 2024-05-15
1471.
Denial of Service - Unknown Product (CVE-2007-3765) - Medium [386]
Description: {'vulners_cve_data_all': 'The STUN implementation in Asterisk 1.4.x before 1.4.8, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted STUN length attribute in a STUN packet sent on an RTP port.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Asterisk多个远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-3765 was patched at 2024-05-15
1472.
Denial of Service - Unknown Product (CVE-2007-6341) - Medium [386]
Description: {'vulners_cve_data_all': 'Net/DNS/RR/A.pm in Net::DNS 0.60 build 654, as used in packages such as SpamAssassin and OTRS, allows remote attackers to cause a denial of service (program "croak") via a crafted DNS response.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Perl Net::DNS DNS应答远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-6341 was patched at 2024-05-15
1473.
Denial of Service - Unknown Product (CVE-2008-0095) - Medium [386]
Description: {'vulners_cve_data_all': 'The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revision 95946, and Appliance s800i 1.0.x before 1.0.3.4 allows remote attackers to cause a denial of service (daemon crash) via a BYE message with an Also (Also transfer) header, which triggers a NULL pointer dereference.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Asterisk 1.x - BYE Message Remote Denial of Service Vulnerability) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-0095 was patched at 2024-05-15
1474.
Denial of Service - Unknown Product (CVE-2008-1389) - Medium [386]
Description: {'vulners_cve_data_all': 'libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an "invalid memory access."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ClamAV 'chmunpack.c'非法内存访问远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1389 was patched at 2024-05-15
1475.
Denial of Service - Unknown Product (CVE-2008-1928) - Medium [386]
Description: {'vulners_cve_data_all': 'Buffer overflow in Imager 0.42 through 0.63 allows attackers to cause a denial of service (crash) via an image based fill in which the number of input channels is different from the number of output channels.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Imager基于图形填充堆溢出漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1928 was patched at 2024-05-15
1476.
Denial of Service - Unknown Product (CVE-2008-2109) - Medium [386]
Description: {'vulners_cve_data_all': 'field.c in the libid3tag 0.15.0b library allows context-dependent attackers to cause a denial of service (CPU consumption) via an ID3_FIELD_TYPE_STRINGLIST field that ends in '\\0', which triggers an infinite loop.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] libid3tag拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-2109 was patched at 2024-05-15
1477.
Denial of Service - Unknown Product (CVE-2008-2713) - Medium [386]
Description: {'vulners_cve_data_all': 'libclamav/petite.c in ClamAV before 0.93.1 allows remote attackers to cause a denial of service via a crafted Petite file that triggers an out-of-bounds read.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ClamAV petite.c无效内存访问绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-2713 was patched at 2024-05-15
1478.
Denial of Service - Unknown Product (CVE-2008-3215) - Medium [386]
Description: {'vulners_cve_data_all': 'libclamav/petite.c in ClamAV before 0.93.3 allows remote attackers to cause a denial of service via a malformed Petite file that triggers an out-of-bounds memory access. NOTE: this issue exists because of an incomplete fix for CVE-2008-2713.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ClamAV petite.c无效内存访问绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3215 was patched at 2024-05-15
1479.
Denial of Service - Unknown Product (CVE-2008-3350) - Medium [386]
Description: {'vulners_cve_data_all': 'dnsmasq 2.43 allows remote attackers to cause a denial of service (daemon crash) by (1) sending a DHCPINFORM while lacking a DHCP lease, or (2) attempting to renew a nonexistent DHCP lease for an invalid subnet as an "unknown client," a different vulnerability than CVE-2008-3214.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Dnsmasq DCHP租期多个远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3350 was patched at 2024-05-15
1480.
Denial of Service - Unknown Product (CVE-2008-3912) - Medium [386]
Description: {'vulners_cve_data_all': 'libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ClamAV多个未明内存破坏漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3912 was patched at 2024-05-15
1481.
Denial of Service - Unknown Product (CVE-2008-3913) - Medium [386]
Description: {'vulners_cve_data_all': 'Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ClamAV多个未明内存破坏漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3913 was patched at 2024-05-15
1482.
Denial of Service - Unknown Product (CVE-2009-0478) - Medium [386]
Description: {'vulners_cve_data_all': 'Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Squid < 3.1 5 - HTTP Version Number Parsing Denial of Service Exploit, [seebug] Squid < 3.1 5 HTTP Version Number Parsing Denial of Service Exploit, [seebug] Squid Web代理缓存HTTP版本号解析拒绝服务漏洞, [exploitpack] Squid 3.1 5 - HTTP Version Number Parsing Denial of Service, [packetstorm] Squid Denial Of Service, [exploitdb] Squid < 3.1 5 - HTTP Version Number Parsing Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0478 was patched at 2024-05-15
1483.
Denial of Service - Unknown Product (CVE-2009-0661) - Medium [386]
Description: {'vulners_cve_data_all': 'Wee Enhanced Environment for Chat (WeeChat) 0.2.6 allows remote attackers to cause a denial of service (crash) via an IRC PRIVMSG command containing crafted color codes that trigger an out-of-bounds read.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] WeeChat IRC消息远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0661 was patched at 2024-05-15
1484.
Denial of Service - Unknown Product (CVE-2009-0751) - Medium [386]
Description: {'vulners_cve_data_all': 'Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Yaws 1.80 - Multiple Headers Remote Denial of Service Vulnerabilities, [seebug] Yaws < 1.80 (multiple headers) Remote Denial of Service Exploit, [seebug] Yaws < 1.80 (multiple headers) Remote Denial of Service Exploit, [packetstorm] Yaws Denial Of Service, [exploitdb] Yaws < 1.80 - Multiple Headers Remote Denial of Service Vulnerabilities) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0751 was patched at 2024-05-15
1485.
Denial of Service - Unknown Product (CVE-2009-1196) - Medium [386]
Description: {'vulners_cve_data_all': 'The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon outage or crash) via manipulations of the timing of CUPS browse packets, related to a "pointer use-after-delete flaw."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] CUPS调度程序目录服务远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1196 was patched at 2024-05-15
1486.
Denial of Service - Unknown Product (CVE-2009-1371) - Medium [386]
Description: {'vulners_cve_data_all': 'The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ClamAV UPack拒绝服务和cli_url_canon()栈溢出漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1371 was patched at 2024-05-15
1487.
Denial of Service - Unknown Product (CVE-2009-1374) - Medium [386]
Description: {'vulners_cve_data_all': 'Buffer overflow in the decrypt_out function in Pidgin (formerly Gaim) before 2.5.6 allows remote attackers to cause a denial of service (application crash) via a QQ packet.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Pidgin多个缓冲区溢出漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1374 was patched at 2024-05-15
1488.
Denial of Service - Unknown Product (CVE-2009-1889) - Medium [386]
Description: {'vulners_cve_data_all': 'The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] pidgin特制ICQ Web消息拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1889 was patched at 2024-05-15
1489.
Denial of Service - Unknown Product (CVE-2009-1892) - Medium [386]
Description: {'vulners_cve_data_all': 'dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ethernet configuration settings are both used, allows remote attackers to cause a denial of service (daemon crash) via unspecified requests.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ISC DHCP服务器主机定义远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1892 was patched at 2024-05-15
1490.
Denial of Service - Unknown Product (CVE-2009-2703) - Medium [386]
Description: {'vulners_cve_data_all': 'libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and application crash) via a TOPIC message that lacks a topic string.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Pidgin Libpurple库多个拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2703 was patched at 2024-05-15
1491.
Denial of Service - Unknown Product (CVE-2009-3615) - Medium [386]
Description: {'vulners_cve_data_all': 'The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] New pidgin packages fix arbitrary code execution, [seebug] Pidgin OSCAR插件非法内存访问拒绝服务漏洞, [seebug] Adium ICQ消息拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3615 was patched at 2024-05-15
1492.
Denial of Service - Unknown Product (CVE-2010-0277) - Medium [386]
Description: {'vulners_cve_data_all': 'slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed MSNSLP INVITE request in an SLP message, a different issue than CVE-2010-0013.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Pidgin多个拒绝服务漏洞, [seebug] Pidgin MSN <= 2.6.4 File Download Vulnerability, [packetstorm] Pidgin MSN 2.6.4 File Download, [exploitpack] Pidgin MSN 2.6.4 - File Download, [exploitdb] Pidgin MSN 2.6.4 - File Download) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-0277 was patched at 2024-05-15
1493.
Denial of Service - Unknown Product (CVE-2010-0292) - Medium [386]
Description: {'vulners_cve_data_all': 'The read_from_cmd_socket function in cmdmon.c in chronyd in Chrony before 1.23.1, and 1.24-pre1, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a spoofed cmdmon packet that triggers a continuous exchange of NOHOSTACCESS messages between two daemons, a related issue to CVE-2009-3563.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] NTP MODE_PRIVATE报文远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-0292 was patched at 2024-05-15
1494.
Denial of Service - Unknown Product (CVE-2010-0295) - Medium [386]
Description: {'vulners_cve_data_all': 'lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a denial of service (memory consumption) by breaking a request into small pieces that are sent at a slow rate.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] lighttpd畸形HTTP请求远程拒绝服务漏洞, [seebug] lighttpd < 1.4.25-r1 Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-0295 was patched at 2024-05-15
1495.
Denial of Service - Unknown Product (CVE-2010-0423) - Medium [386]
Description: {'vulners_cve_data_all': 'gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Pidgin多个拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-0423 was patched at 2024-05-15
1496.
Denial of Service - Unknown Product (CVE-2010-0639) - Medium [386]
Description: {'vulners_cve_data_all': 'The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Squid Web代理缓存HTCP请求远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-0639 was patched at 2024-05-15
1497.
Denial of Service - Unknown Product (CVE-2011-4362) - Medium [386]
Description: {'vulners_cve_data_all': 'Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 and 1.5 before SVN revision 2806 allows remote attackers to cause a denial of service (segmentation fault) via crafted base64 input that triggers an out-of-bounds read with a negative index.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] lighttpd Denial of Service Vulnerability PoC, [seebug] Lighttpd 1.4.30 / 1.5 Denial Of Service, [seebug] Lighttpd Proof of Concept code for CVE-2011-4362, [seebug] lighttpd mod_auth模块base64 拒绝服务漏洞, [exploitpack] lighttpd - Denial of Service (PoC), [exploitdb] lighttpd - Denial of Service (PoC)) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4362 was patched at 2024-05-15
1498.
Denial of Service - Unknown Product (CVE-2011-4603) - Medium [386]
Description: {'vulners_cve_data_all': 'The silc_channel_message function in ops.c in the SILC protocol plugin in libpurple in Pidgin before 2.10.1 does not perform the expected UTF-8 validation on message data, which allows remote attackers to cause a denial of service (application crash) via a crafted message, a different vulnerability than CVE-2011-3594.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Pidgin "silc_private_message()"拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4603 was patched at 2024-05-15
1499.
Denial of Service - Unknown Product (CVE-2012-2098) - Medium [386]
Description: {'vulners_cve_data_all': 'Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apache Commons Compress和Apache Ant拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-2098 was patched at 2024-05-15
1500.
Denial of Service - Unknown Product (CVE-2012-3443) - Medium [386]
Description: {'vulners_cve_data_all': 'The django.forms.ImageField class in the form system in Django before 1.3.2 and 1.4.x before 1.4.1 completely decompresses image data during image validation, which allows remote attackers to cause a denial of service (memory consumption) by uploading an image file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Django跨站脚本执行和两个拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-3443 was patched at 2024-05-15
1501.
Denial of Service - Unknown Product (CVE-2012-3444) - Medium [386]
Description: {'vulners_cve_data_all': 'The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Django跨站脚本执行和两个拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-3444 was patched at 2024-05-15
1502.
Denial of Service - Unknown Product (CVE-2012-5533) - Medium [386]
Description: {'vulners_cve_data_all': 'The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] lighttpd畸形HTTP Connection域处理拒绝服务漏洞, [seebug] lighttpd 1.4.31 Denial of Service PoC, [exploitpack] lighttpd 1.4.31 - Denial of Service (PoC), [packetstorm] Simple Lighttpd 1.4.31 Denial Of Service, [exploitdb] lighttpd 1.4.31 - Denial of Service (PoC)) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-5533 was patched at 2024-05-15
1503.
Denial of Service - Unknown Product (CVE-2013-0189) - Medium [386]
Description: {'vulners_cve_data_all': 'cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and other versions, allows remote attackers to cause a denial of service (resource consumption) via a crafted request. NOTE: this issue is due to an incorrect fix for CVE-2012-5643, possibly involving an incorrect order of arguments or incorrect comparison.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Squid 'cachemgr.cgi'不完整修复远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-0189 was patched at 2024-05-15
1504.
Denial of Service - Unknown Product (CVE-2013-0306) - Medium [386]
Description: {'vulners_cve_data_all': 'The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Django 1.3/1.4 拒绝服务和信息泄露漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-0306 was patched at 2024-05-15
1505.
Denial of Service - Unknown Product (CVE-2013-2494) - Medium [386]
Description: {'vulners_cve_data_all': 'libdns in ISC DHCP 4.2.x before 4.2.5-P1 allows remote name servers to cause a denial of service (memory consumption) via vectors involving a regular expression, as demonstrated by a memory-exhaustion attack against a machine running a dhcpd process, a related issue to CVE-2013-2266.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ISC BIND 9 'libdns' 远程拒绝服务漏洞(CVE-2013-2266)) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-2494 was patched at 2024-05-15
1506.
Denial of Service - Unknown Product (CVE-2014-0333) - Medium [386]
Description: {'vulners_cve_data_all': 'The png_push_read_chunk function in pngpread.c in the progressive decoder in libpng 1.6.x through 1.6.9 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an IDAT chunk with a length of zero.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] libpng拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-0333 was patched at 2024-05-15
1507.
Denial of Service - Unknown Product (CVE-2021-29060) - Medium [386]
Description: {'vulners_cve_data_all': 'A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below which occurs when the application is provided and checks a crafted invalid HWB string.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-29060 was patched at 2024-05-15
1508.
Denial of Service - Unknown Product (CVE-2024-21503) - Medium [386]
Description: {'vulners_cve_data_all': 'Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_expanded function in the strings.py file. An attacker could exploit this vulnerability by crafting a malicious input that causes a denial of service.\r\rExploiting this vulnerability is possible when running Black on untrusted input, or if you habitually put thousands of leading tab characters in your docstrings.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-21503 was patched at 2024-05-15
1509.
Incorrect Calculation - Unknown Product (CVE-2006-3464) - Medium [386]
Description: {'vulners_cve_data_all': 'TIFF library (libtiff) before 3.8.2 allows context-dependent attackers to pass numeric range checks and possibly execute code, and trigger assert errors, via large offset values in a TIFF directory that lead to an integer overflow and other unspecified vectors involving "unchecked arithmetic operations".', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Libtiff图形库多个安全漏洞) | |
| 0.5 | 15 | Incorrect Calculation | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3464 was patched at 2024-05-15
1510.
Incorrect Calculation - Unknown Product (CVE-2012-5340) - Medium [386]
Description: {'vulners_cve_data_all': 'SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corrupt PDF file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] SumatraPDF 2.1.1/MuPDF 1.0 Integer Overflow, [exploitpack] SumatraPDF 2.1.1MuPDF 1.0 - Integer Overflow, [exploitdb] SumatraPDF 2.1.1/MuPDF 1.0 - Integer Overflow) | |
| 0.5 | 15 | Incorrect Calculation | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-5340 was patched at 2024-05-15
1511.
Information Disclosure - Unknown Product (CVE-2008-3962) - Medium [386]
Description: {'vulners_cve_data_all': 'The from_format function in ssmtp.c in ssmtp 2.61 and 2.62, in certain configurations, uses uninitialized memory for the From: field of an e-mail message, which might allow remote attackers to obtain sensitive information (memory contents) in opportunistic circumstances by reading a message.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] sSMTP 'from_format()'未初始化内存信息泄漏漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 2.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3962 was patched at 2024-05-15
1512.
Information Disclosure - Unknown Product (CVE-2021-31153) - Medium [386]
Description: {'vulners_cve_data_all': 'please before 0.4 allows a local unprivileged attacker to gain knowledge about the existence of files or directories in privileged locations via the search_path function, the --check option, or the -d option.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-31153 was patched at 2024-05-15
1513.
Memory Corruption - Unknown Product (CVE-2008-1289) - Medium [386]
Description: {'vulners_cve_data_all': 'Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0.x before 1.0.2, Appliance Developer Kit before 1.4 revision 109386, and s800i 1.1.x before 1.1.0.2 allow remote attackers to (1) write a zero to an arbitrary memory location via a large RTP payload number, related to the ast_rtp_unset_m_type function in main/rtp.c; or (2) write certain integers to an arbitrary memory location via a large number of RTP payloads, related to the process_sdp function in channels/chan_sip.c.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Asterisk RTP Codec负载处理多个溢出漏洞) | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1289 was patched at 2024-05-15
1514.
Memory Corruption - Unknown Product (CVE-2017-20006) - Medium [386]
Description: {'vulners_cve_data_all': 'UnRAR 5.6.1.2 and 5.6.1.3 has a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExtract::ExtractCurrentFile).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-20006 was patched at 2024-05-15
1515.
Memory Corruption - Unknown Product (CVE-2017-9445) - Medium [386]
Description: {'vulners_cve_data_all': 'In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] systemd CVE-2017-9445 Out-Of-Bounds Write Remote Code Execution Vulnerability) | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-9445 was patched at 2024-05-15
1516.
Memory Corruption - Unknown Product (CVE-2018-16742) - Medium [386]
Description: {'vulners_cve_data_all': 'An issue was discovered in mgetty before 1.2.1. In contrib/scrts.c, a stack-based buffer overflow can be triggered via a command-line parameter.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] mgetty 1.2.0 Buffer Overflow / Privilege Escalation Vulnerabilities) | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-16742 was patched at 2024-05-15
1517.
Memory Corruption - Unknown Product (CVE-2018-16743) - Medium [386]
Description: {'vulners_cve_data_all': 'An issue was discovered in mgetty before 1.2.1. In contrib/next-login/login.c, the command-line parameter username is passed unsanitized to strcpy(), which can cause a stack-based buffer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] mgetty 1.2.0 Buffer Overflow / Privilege Escalation Vulnerabilities) | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-16743 was patched at 2024-05-15
1518.
Memory Corruption - Unknown Product (CVE-2018-16745) - Medium [386]
Description: {'vulners_cve_data_all': 'An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized. It could allow a buffer overflow if long untrusted input can reach it.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] mgetty 1.2.0 Buffer Overflow / Privilege Escalation Vulnerabilities) | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-16745 was patched at 2024-05-15
1519.
Memory Corruption - Unknown Product (CVE-2018-25018) - Medium [386]
Description: {'vulners_cve_data_all': 'UnRAR 5.6.1.7 through 5.7.4 and 6.0.3 has an out-of-bounds write during a memcpy in QuickOpen::ReadRaw when called from QuickOpen::ReadNext.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-25018 was patched at 2024-05-15
1520.
Memory Corruption - Unknown Product (CVE-2019-16226) - Medium [386]
Description: {'vulners_cve_data_all': 'An issue was discovered in py-lmdb 0.97. mdb_node_del does not validate a memmove in the case of an unexpected node->mn_hi, leading to an invalid write operation. NOTE: this outcome occurs when accessing a data.mdb file supplied by an attacker.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-16226 was patched at 2024-05-15
1521.
Memory Corruption - Unknown Product (CVE-2019-25050) - Medium [386]
Description: {'vulners_cve_data_all': 'netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in uffd_cleanup (called from netCDFDataset::~netCDFDataset and netCDFDataset::~netCDFDataset).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-25050 was patched at 2024-05-15
1522.
Memory Corruption - Unknown Product (CVE-2020-19752) - Medium [386]
Description: {'vulners_cve_data_all': 'The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-19752 was patched at 2024-05-15
1523.
Memory Corruption - Unknown Product (CVE-2020-36280) - Medium [386]
Description: {'vulners_cve_data_all': 'Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-36280 was patched at 2024-05-15
1524.
Memory Corruption - Unknown Product (CVE-2020-36401) - Medium [386]
Description: {'vulners_cve_data_all': 'mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-36401 was patched at 2024-05-15
1525.
Memory Corruption - Unknown Product (CVE-2021-28216) - Medium [386]
Description: {'vulners_cve_data_all': 'BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-28216 was patched at 2024-05-15
1526.
Memory Corruption - Unknown Product (CVE-2021-32286) - Medium [386]
Description: {'vulners_cve_data_all': 'An issue was discovered in hcxtools through 6.1.6. A global-buffer-overflow exists in the function pcapngoptionwalk located in hcxpcapngtool.c. It allows an attacker to cause code Execution.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32286 was patched at 2024-05-15
1527.
Memory Corruption - Unknown Product (CVE-2021-42704) - Medium [386]
Description: {'vulners_cve_data_all': 'Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-42704 was patched at 2024-05-15
1528.
Memory Corruption - Unknown Product (CVE-2023-4235) - Medium [386]
Description: {'vulners_cve_data_all': 'A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_deliver_report().', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-4235 was patched at 2024-05-15
1529.
Path Traversal - Unknown Product (CVE-2009-3583) - Medium [386]
Description: {'vulners_cve_data_all': 'Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the countrycode field.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] SQL-Ledger ERP多个输入验证和绕过安全限制漏洞, [packetstorm] SQL-Ledger XSS / XSRF / SQL Injection / LFI) | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3583 was patched at 2024-05-15
1530.
Path Traversal - Unknown Product (CVE-2021-32746) - Medium [386]
Description: {'vulners_cve_data_all': 'Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Between versions 2.3.0 and 2.8.2, the `doc` module of Icinga Web 2 allows to view documentation directly in the UI. It must be enabled manually by an administrator and users need explicit access permission to use it. Then, by visiting a certain route, it is possible to gain access to arbitrary files readable by the web-server user. The issue has been fixed in the 2.9.0, 2.8.3, and 2.7.5 releases. As a workaround, an administrator may disable the `doc` module or revoke permission to use it from all users.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32746 was patched at 2024-05-15
1531.
Path Traversal - Unknown Product (CVE-2023-7207) - Medium [386]
Description: {'vulners_cve_data_all': 'Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] Zimbra Collaboration Suite TAR Path Traversal Exploit, [packetstorm] Zimbra Collaboration Suite TAR Path Traversal, [metasploit] TAR Path Traversal in Zimbra (CVE-2022-41352)) | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-7207 was patched at 2024-05-15
ubuntu: CVE-2023-7207 was patched at 2024-04-29
1532.
Elevation of Privilege - Linux Kernel (CVE-2022-2961) - Medium [385]
Description: A use-after-free flaw was found in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-2961 was patched at 2024-05-15
1533.
Remote Code Execution - ImageMagick (CVE-2007-0770) - Medium [385]
Description: Buffer overflow in GraphicsMagick and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-0770 was patched at 2024-05-15
1534.
Remote Code Execution - Jetty (CVE-2022-41678) - Medium [385]
Description: Once an user is authenticated on Jolokia, he can potentially trigger arbitrary
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Jetty is a Java based web server and servlet engine | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-41678 was patched at 2024-05-15
1535.
Remote Code Execution - Perl (CVE-2007-0002) - Medium [385]
Description: Multiple heap-based buffer overflows in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allow user-assisted remote attackers to cause a denial of service (application crash) and possibly
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-0002 was patched at 2024-05-15
1536.
Remote Code Execution - Perl (CVE-2008-1109) - Medium [385]
Description: Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1109 was patched at 2024-05-15
1537.
Remote Code Execution - Perl (CVE-2008-3971) - Medium [385]
Description: Heap-based buffer overflow in the open_man_file function in callbacks.c in gmanedit 0.4.1 allows remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-3971 was patched at 2024-05-15
1538.
Remote Code Execution - Python (CVE-2024-23346) - Medium [385]
Description: Pymatgen (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-23346 was patched at 2024-05-15
1539.
Remote Code Execution - Redis (CVE-2021-29478) - Medium [385]
Description: Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis 6.2 before 6.2.3 could be exploited to corrupt the heap and potentially result with
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Redis is an open-source in-memory storage, used as a distributed, in-memory key–value database, cache and message broker, with optional durability | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-29478 was patched at 2024-05-15
1540.
Remote Code Execution - Redis (CVE-2021-32625) - Medium [385]
Description: Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis version 6.0 or newer, could be exploited using the STRALGO LCS command to corrupt the heap and potentially result with
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Redis is an open-source in-memory storage, used as a distributed, in-memory key–value database, cache and message broker, with optional durability | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32625 was patched at 2024-05-15
1541.
Remote Code Execution - Wireshark (CVE-2014-4174) - Medium [385]
Description: wiretap/libpcap.c in the libpcap file parser in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-4174 was patched at 2024-05-15
1542.
Unknown Vulnerability Type - Perl (CVE-2008-1804) - Medium [385]
Description: {'vulners_cve_data_all': 'preprocessors/spp_frag3.c in Sourcefire Snort before 2.8.1 does not properly identify packet fragments that have dissimilar TTL values, which allows remote attackers to bypass detection rules by using a different TTL for each fragment.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Snort碎片重组TTL值导致漏报漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1804 was patched at 2024-05-15
1543.
Unknown Vulnerability Type - Perl (CVE-2009-0667) - Medium [385]
Description: {'vulners_cve_data_all': 'Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl module in an arbitrary directory.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OCS Inventory NG代理Backend.pm Perl模块处理代码执行漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0667 was patched at 2024-05-15
1544.
Unknown Vulnerability Type - Perl (CVE-2010-1192) - Medium [385]
Description: {'vulners_cve_data_all': 'libESMTP, probably 1.0.4 and earlier, does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Mozilla Firefox NULL字符CA SSL证书验证安全绕过漏洞, [seebug] Randombit Botan Library X509 Certificate Validation Bypass Vulnerability(CVE-2017-2801), [seebug] mozilla-thunderbird多个安全漏洞, [exploitdb] Mozilla NSS NULL Character CA SSL Certificate Validation Security Bypass Vulnerability) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-1192 was patched at 2024-05-15
1545.
Unknown Vulnerability Type - Perl (CVE-2011-0447) - Medium [385]
Description: {'vulners_cve_data_all': 'Ruby on Rails 2.1.x, 2.2.x, and 2.3.x before 2.3.11, and 3.x before 3.0.4, does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via forged (1) AJAX or (2) API requests that leverage "combinations of browser plugins and HTTP redirects," a related issue to CVE-2011-0696.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Ruby on Rails跨站脚本执行及跨站请求伪造漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-0447 was patched at 2024-05-15
1546.
Unknown Vulnerability Type - Perl (CVE-2011-0696) - Medium [385]
Description: {'vulners_cve_data_all': 'Django 1.1.x before 1.1.4 and 1.2.x before 1.2.5 does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via forged AJAX requests that leverage a "combination of browser plugins and redirects," a related issue to CVE-2011-0447.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Ruby on Rails跨站脚本执行及跨站请求伪造漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-0696 was patched at 2024-05-15
1547.
Unknown Vulnerability Type - Perl (CVE-2011-2507) - Medium [385]
Description: {'vulners_cve_data_all': 'libraries/server_synchronize.lib.php in the Synchronize implementation in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly quote regular expressions, which allows remote authenticated users to inject a PCRE e (aka PREG_REPLACE_EVAL) modifier, and consequently execute arbitrary PHP code, by leveraging the ability to modify the SESSION superglobal array.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([dsquare] Phpmyadmin 3.x RCE, [seebug] phpMyAdmin 3.x 多个安全漏洞, [seebug] phpMyAdmin 3.x Multiple Remote Code Executions, [packetstorm] phpMyAdmin 3.x Remote Code Execution) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-2507 was patched at 2024-05-15
1548.
Arbitrary File Writing - Unknown Product (CVE-2005-3011) - Medium [383]
Description: {'vulners_cve_data_all': 'The sort_offline function for texindex in texinfo 4.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2007-005多个安全漏洞) | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0 | 14 | Unknown Product | |
| 0.1 | 10 | CVSS Base Score is 1.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-3011 was patched at 2024-05-15
1549.
Cross Site Scripting - PHP (CVE-2007-2865) - Medium [383]
Description: Cross-site scripting (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-2865 was patched at 2024-05-15
1550.
Remote Code Execution - PHP (CVE-2008-5621) - Medium [383]
Description: Cross-site request forgery (CSRF) vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5621 was patched at 2024-05-15
1551.
Unknown Vulnerability Type - OpenSSH (CVE-2007-2768) - Medium [383]
Description: {'vulners_cve_data_all': 'OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] OpenSSH s/key Weakness) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-2768 was patched at 2024-05-15
1552.
Unknown Vulnerability Type - OpenSSL (CVE-2009-0050) - Medium [383]
Description: {'vulners_cve_data_all': 'Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenSSL 'EVP_VerifyFinal'函数签名验证漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0050 was patched at 2024-05-15
1553.
Unknown Vulnerability Type - PHP (CVE-2005-3348) - Medium [383]
Description: {'vulners_cve_data_all': 'HTTP response splitting vulnerability in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egroupware before 1.0.0.009, allows remote attackers to spoof web content and poison web caches via CRLF sequences in the charset parameter.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Hardened-PHP Project Security Advisory 2005-21.81) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-3348 was patched at 2024-05-15
1554.
Unknown Vulnerability Type - PHP (CVE-2016-10148) - Medium [383]
Description: {'vulners_cve_data_all': 'The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related issue to CVE-2016-6896.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([metasploit] WordPress Traversal Directory DoS, [exploitpack] WordPress 4.5.3 - Directory Traversal Denial of Service, [zdt] WordPress 4.5.3 - Directory Traversal / Denial of Service, [exploitdb] WordPress Core 4.5.3 - Directory Traversal / Denial of Service) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-10148 was patched at 2024-05-15
1555.
Unknown Vulnerability Type - PHP (CVE-2017-5930) - Medium [383]
Description: {'vulners_cve_data_all': 'The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object) website | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.3 | 10 | CVSS Base Score is 2.7. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-5930 was patched at 2024-05-15
1556.
Unknown Vulnerability Type - Safari (CVE-2009-1681) - Medium [383]
Description: {'vulners_cve_data_all': 'WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not prevent web sites from loading third-party content into a subframe, which allows remote attackers to bypass the Same Origin Policy and conduct "clickjacking" attacks via a crafted HTML document.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1681 was patched at 2024-05-15
1557.
Unknown Vulnerability Type - Safari (CVE-2009-1700) - Medium [383]
Description: {'vulners_cve_data_all': 'The XSLT implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read XML content from arbitrary web pages via a crafted document.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1700 was patched at 2024-05-15
1558.
Authentication Bypass - Perl (CVE-2009-3232) - Medium [382]
Description: pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3232 was patched at 2024-05-15
1559.
Security Feature Bypass - Linux Kernel (CVE-2021-46911) - Medium [382]
Description: {'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nch_ktls: Fix kernel panic\n\nTaking page refcount is not ideal and causes kernel panic\nsometimes. It's better to take tx_ctx lock for the complete\nskb transmit, to avoid page cleanup if ACK received in middle.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-46911 was patched at 2024-05-15
redos: CVE-2021-46911 was patched at 2024-04-18
1560.
Security Feature Bypass - Linux Kernel (CVE-2021-46913) - Medium [382]
Description: {'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nftables: clone set element expression template\n\nmemcpy() breaks when using connlimit in set elements. Use\nnft_expr_clone() to initialize the connlimit expression list, otherwise\nconnlimit garbage collector crashes when walking on the list head copy.\n\n[ 493.064656] Workqueue: events_power_efficient nft_rhash_gc [nf_tables]\n[ 493.064685] RIP: 0010:find_or_evict+0x5a/0x90 [nf_conncount]\n[ 493.064694] Code: 2b 43 40 83 f8 01 77 0d 48 c7 c0 f5 ff ff ff 44 39 63 3c 75 df 83 6d 18 01 48 8b 43 08 48 89 de 48 8b 13 48 8b 3d ee 2f 00 00 <48> 89 42 08 48 89 10 48 b8 00 01 00 00 00 00 ad de 48 89 03 48 83\n[ 493.064699] RSP: 0018:ffffc90000417dc0 EFLAGS: 00010297\n[ 493.064704] RAX: 0000000000000000 RBX: ffff888134f38410 RCX: 0000000000000000\n[ 493.064708] RDX: 0000000000000000 RSI: ffff888134f38410 RDI: ffff888100060cc0\n[ 493.064711] RBP: ffff88812ce594a8 R08: ffff888134f38438 R09: 00000000ebb9025c\n[ 493.064714] R10: ffffffff8219f838 R11: 0000000000000017 R12: 0000000000000001\n[ 493.064718] R13: ffffffff82146740 R14: ffff888134f38410 R15: 0000000000000000\n[ 493.064721] FS: 0000000000000000(0000) GS:ffff88840e440000(0000) knlGS:0000000000000000\n[ 493.064725] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 493.064729] CR2: 0000000000000008 CR3: 00000001330aa002 CR4: 00000000001706e0\n[ 493.064733] Call Trace:\n[ 493.064737] nf_conncount_gc_list+0x8f/0x150 [nf_conncount]\n[ 493.064746] nft_rhash_gc+0x106/0x390 [nf_tables]', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-46913 was patched at 2024-05-15
redos: CVE-2021-46913 was patched at 2024-04-18
1561.
Security Feature Bypass - Linux Kernel (CVE-2021-46919) - Medium [382]
Description: {'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: fix wq size store permission state\n\nWQ size can only be changed when the device is disabled. Current code\nallows change when device is enabled but wq is disabled. Change the check\nto detect device state.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-46919 was patched at 2024-05-15
redos: CVE-2021-46919 was patched at 2024-04-18
1562.
Security Feature Bypass - Linux Kernel (CVE-2021-46920) - Medium [382]
Description: {'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: Fix clobbering of SWERR overflow bit on writeback\n\nCurrent code blindly writes over the SWERR and the OVERFLOW bits. Write\nback the bits actually read instead so the driver avoids clobbering the\nOVERFLOW bit that comes after the register is read.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-46920 was patched at 2024-05-15
redos: CVE-2021-46920 was patched at 2024-04-18
1563.
Security Feature Bypass - Linux Kernel (CVE-2023-0615) - Medium [382]
Description: {'vulners_cve_data_all': 'A memory leak flaw and potential divide by zero and Integer overflow was found in the Linux kernel V4L2 and vivid test code functionality. This issue occurs when a user triggers ioctls, such as VIDIOC_S_DV_TIMINGS ioctl. This could allow a local user to crash the system if vivid test code enabled.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-0615 was patched at 2024-05-15
1564.
Security Feature Bypass - Linux Kernel (CVE-2024-26603) - Medium [382]
Description: {'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nx86/fpu: Stop relying on userspace for info to fault in xsave buffer\n\nBefore this change, the expected size of the user space buffer was\ntaken from fx_sw->xstate_size. fx_sw->xstate_size can be changed\nfrom user-space, so it is possible construct a sigreturn frame where:\n\n * fx_sw->xstate_size is smaller than the size required by valid bits in\n fx_sw->xfeatures.\n * user-space unmaps parts of the sigrame fpu buffer so that not all of\n the buffer required by xrstor is accessible.\n\nIn this case, xrstor tries to restore and accesses the unmapped area\nwhich results in a fault. But fault_in_readable succeeds because buf +\nfx_sw->xstate_size is within the still mapped area, so it goes back and\ntries xrstor again. It will spin in this loop forever.\n\nInstead, fault in the maximum size which can be touched by XRSTOR (taken\nfrom fpstate->user_size).\n\n[ dhansen: tweak subject / changelog ]', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2024-26603 was patched at 2024-06-05
debian: CVE-2024-26603 was patched at 2024-05-15
oraclelinux: CVE-2024-26603 was patched at 2024-06-05
redhat: CVE-2024-26603 was patched at 2024-06-05
ubuntu: CVE-2024-26603 was patched at 2024-06-07, 2024-06-10, 2024-06-11, 2024-06-14
1565.
Information Disclosure - Linux Kernel (CVE-2023-6240) - Medium [381]
Description: {'vulners_cve_data_all': 'A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2023-6240 was patched at 2024-06-05
debian: CVE-2023-6240 was patched at 2024-05-15
oraclelinux: CVE-2023-6240 was patched at 2024-05-08, 2024-06-05
redhat: CVE-2023-6240 was patched at 2024-04-18, 2024-05-28, 2024-06-05
1566.
Information Disclosure - Linux Kernel (CVE-2024-0564) - Medium [381]
Description: {'vulners_cve_data_all': 'A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the same host and the default setting of KSM is "max page sharing=256", it is possible for the attacker to time the unmap to merge with the victim's page. The unmapping time depends on whether it merges with the victim's page and additional physical pages are created beyond the KSM's "max page share". Through these operations, the attacker can leak the victim's page.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-0564 was patched at 2024-05-15
1567.
Command Injection - Python (CVE-2020-13124) - Medium [380]
Description: SABnzbd 2.3.9 and 3.0.0Alpha2 has a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-13124 was patched at 2024-05-15
1568.
Cross Site Scripting - Unknown Product (CVE-2009-0359) - Medium [380]
Description: {'vulners_cve_data_all': 'Multiple cross-site scripting (XSS) vulnerabilities in Samizdat before 0.6.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) message title or (2) user full name.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Samizdat 0.6.1 Cross Site Scripting) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-0359 was patched at 2024-05-15
1569.
Cross Site Scripting - Unknown Product (CVE-2009-3581) - Medium [380]
Description: {'vulners_cve_data_all': 'Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbitrary web script or HTML via (1) the DCN Description field in the Accounts Receivables menu item for Add Transaction, (2) the Description field in the Accounts Payable menu item for Add Transaction, or the name field in (3) the Customers menu item for Add Customer or (4) the Vendor menu item for Add Vendor.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] SQL-Ledger ERP多个输入验证和绕过安全限制漏洞, [packetstorm] SQL-Ledger XSS / XSRF / SQL Injection / LFI) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3581 was patched at 2024-05-15
1570.
Cross Site Scripting - Unknown Product (CVE-2011-1058) - Medium [380]
Description: {'vulners_cve_data_all': 'Cross-site scripting (XSS) vulnerability in the reStructuredText (rst) parser in parser/text_rst.py in MoinMoin before 1.9.3, when docutils is installed or when "format rst" is set, allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in the refuri attribute. NOTE: some of these details are obtained from third party information.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Moinmoin Cross Site Scripting) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 2.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-1058 was patched at 2024-05-15
1571.
Cross Site Scripting - Unknown Product (CVE-2011-1401) - Medium [380]
Description: {'vulners_cve_data_all': 'ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ikiwiki 'htmlscrubber'插件跨站脚本漏洞) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-1401 was patched at 2024-05-15
1572.
Cross Site Scripting - Unknown Product (CVE-2012-4037) - Medium [380]
Description: {'vulners_cve_data_all': 'Multiple cross-site scripting (XSS) vulnerabilities in the web client in Transmission before 2.61 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) created by, or (3) name field in a torrent file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Transmission BitTorrent Cross Site Scripting) | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 2.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-4037 was patched at 2024-05-15
1573.
Remote Code Execution - Cacti (CVE-2017-12065) - Medium [380]
Description: spikekill.php in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-12065 was patched at 2024-05-15
1574.
Remote Code Execution - TLS (CVE-2016-1000030) - Medium [380]
Description: Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnu
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | TLS | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-1000030 was patched at 2024-05-15
1575.
Remote Code Execution - TLS (CVE-2019-11873) - Medium [380]
Description: wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | TLS | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-11873 was patched at 2024-05-15
1576.
Security Feature Bypass - Unknown Product (CVE-2013-7426) - Medium [380]
Description: {'vulners_cve_data_all': 'Insecure Temporary file vulnerability in /tmp/kamailio_fifo in kamailio 4.0.1.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-7426 was patched at 2024-05-15
1577.
Unknown Vulnerability Type - Cacti (CVE-2023-37543) - Medium [380]
Description: {'vulners_cve_data_all': 'Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php. This is a different vulnerability than CVE-2019-16723.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-37543 was patched at 2024-05-15
1578.
Unknown Vulnerability Type - GDI (CVE-2005-0116) - Medium [380]
Description: {'vulners_cve_data_all': 'AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] AWStats configdir Remote Command Execution, [saint] AWStats configdir parameter command execution, [saint] AWStats configdir parameter command execution, [saint] AWStats configdir parameter command execution, [saint] AWStats configdir parameter command execution) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | GDI | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-0116 was patched at 2024-05-15
1579.
Unknown Vulnerability Type - HID (CVE-2008-1926) - Medium [380]
Description: {'vulners_cve_data_all': 'Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] util-linux-ng登录远程日志注入漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | HID | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1926 was patched at 2024-05-15
1580.
Unknown Vulnerability Type - HID (CVE-2021-27211) - Medium [380]
Description: {'vulners_cve_data_all': 'steghide 0.5.1 relies on a certain 32-bit seed value, which makes it easier for attackers to detect hidden data.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([githubexploit] Exploit for Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) in Steghide Project Steghide) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | HID | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-27211 was patched at 2024-05-15
1581.
Unknown Vulnerability Type - TLS (CVE-2022-38152) - Medium [380]
Description: {'vulners_cve_data_all': 'An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is called on its session, the server crashes with a segmentation fault. This occurs in the second session, which is created through TLS session resumption and reuses the initial struct WOLFSSL. If the server reuses the previous session structure (struct WOLFSSL) by calling wolfSSL_clear(WOLFSSL* ssl) on it, the next received Client Hello (that resumes the previous session) crashes the server. Note that this bug is only triggered when resuming sessions using TLS session resumption. Only servers that use wolfSSL_clear instead of the recommended SSL_free; SSL_new sequence are affected. Furthermore, wolfSSL_clear is part of wolfSSL's compatibility layer and is not enabled by default. It is not part of wolfSSL's native API.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([zdt] wolfSSL 5.5.0 Session Resumption Denial Of Service Vulnerability) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | TLS | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-38152 was patched at 2024-05-15
1582.
Security Feature Bypass - Bouncy Castle (CVE-2018-1000613) - Medium [379]
Description: {'vulners_cve_data_all': 'Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result in the execution of unexpected code. This attack appear to be exploitable via A handcrafted private key can include references to unexpected classes which will be picked up from the class path for the executing application. This vulnerability appears to have been fixed in 1.60 and later.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Bouncy Castle is a collection of APIs used in cryptography | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-1000613 was patched at 2024-05-15
1583.
Remote Code Execution - FFmpeg (CVE-2011-3362) - Medium [378]
Description: Integer signedness error in the decode_residual_block function in cavsdec.c in libavcodec in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-3362 was patched at 2024-05-15
1584.
Remote Code Execution - FFmpeg (CVE-2011-3929) - Medium [378]
Description: The avpriv_dv_produce_packet function in libavcodec in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-3929 was patched at 2024-05-15
1585.
Remote Code Execution - FFmpeg (CVE-2011-3947) - Medium [378]
Description: Buffer overflow in mjpegbdec.c in libavcodec in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-3947 was patched at 2024-05-15
1586.
Remote Code Execution - FFmpeg (CVE-2011-3951) - Medium [378]
Description: The dpcm_decode_frame function in dpcm.c in libavcodec in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-3951 was patched at 2024-05-15
1587.
Remote Code Execution - FFmpeg (CVE-2011-3952) - Medium [378]
Description: The decode_init function in kmvc.c in libavcodec in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-3952 was patched at 2024-05-15
1588.
Remote Code Execution - FFmpeg (CVE-2011-4364) - Medium [378]
Description: Buffer overflow in the Sierra VMD decoder in libavcodec in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4364 was patched at 2024-05-15
1589.
Remote Code Execution - FFmpeg (CVE-2012-0851) - Medium [378]
Description: The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-0851 was patched at 2024-05-15
1590.
Remote Code Execution - FFmpeg (CVE-2012-0852) - Medium [378]
Description: The adpcm_decode_frame function in adpcm.c in libavcodec in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-0852 was patched at 2024-05-15
1591.
Remote Code Execution - FFmpeg (CVE-2012-0853) - Medium [378]
Description: The decodeTonalComponents function in the Actrac3 codec (atrac3.c) in libavcodec in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-0853 was patched at 2024-05-15
1592.
Remote Code Execution - FFmpeg (CVE-2012-0858) - Medium [378]
Description: The Shorten codec (shorten.c) in libavcodec in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-0858 was patched at 2024-05-15
1593.
Remote Code Execution - MediaWiki (CVE-2013-2114) - Medium [378]
Description: Unrestricted file upload vulnerability in the chunk upload API in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-2114 was patched at 2024-05-15
1594.
Remote Code Execution - QEMU (CVE-2007-5729) - Medium [378]
Description: The NE2000 emulator in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | QEMU is a generic and open source machine & userspace emulator and virtualizer | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-5729 was patched at 2024-05-15
1595.
Remote Code Execution - QEMU (CVE-2020-35506) - Medium [378]
Description: A use-after-free vulnerability was found in the am53c974 SCSI host bus adapter emulation of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | QEMU is a generic and open source machine & userspace emulator and virtualizer | |
| 0.7 | 10 | CVSS Base Score is 6.7. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-35506 was patched at 2024-05-15
1596.
Remote Code Execution - iOS (CVE-2011-2903) - Medium [378]
Description: Heap-based buffer overflow in tcptrack before 1.4.2 might allow attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-2903 was patched at 2024-05-15
1597.
Unknown Vulnerability Type - Apache Tomcat (CVE-2024-21733) - Medium [378]
Description: {'vulners_cve_data_all': 'Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43.\n\nUsers are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.\n\n', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Apache Tomcat 8.5.63 / 9.0.43 HTTP Response Smuggling, [zdt] Apache Tomcat 8.5.63 / 9.0.43 HTTP Response Smuggling Vulnerability) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-21733 was patched at 2024-05-15
1598.
Unknown Vulnerability Type - MediaWiki (CVE-2010-1189) - Medium [378]
Description: {'vulners_cve_data_all': 'MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MediaWiki >= 1.5 CSS验证信息泄露漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-1189 was patched at 2024-05-15
1599.
Unknown Vulnerability Type - vim (CVE-2002-1377) - Medium [378]
Description: {'vulners_cve_data_all': 'vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] Vim 8.1.1365 Neovim 0.3.6 - Arbitrary Code Execution, [exploitdb] Vim < 8.1.1365 / Neovim < 0.3.6 - Arbitrary Code Execution) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Vim is a free and open-source, screen-based text editor program | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-1377 was patched at 2024-05-15
1600.
Command Injection - Node.js (CVE-2023-28155) - Medium [377]
Description: The Request package through 2.88.1 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-28155 was patched at 2024-05-15
1601.
Command Injection - RPC (CVE-2013-0235) - Medium [377]
Description: The XML
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-0235 was patched at 2024-05-15
1602.
Denial of Service - PHP (CVE-2008-6767) - Medium [377]
Description: wp-admin/upgrade.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-6767 was patched at 2024-05-15
1603.
Denial of Service - Safari (CVE-2017-17821) - Medium [377]
Description: WTF/wtf/FastBitVector.h in WebKit, as distributed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-17821 was patched at 2024-05-15
1604.
Security Feature Bypass - Google Chrome (CVE-2021-30580) - Medium [377]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30580 was patched at 2024-05-15
1605.
Security Feature Bypass - Google Chrome (CVE-2021-30582) - Medium [377]
Description: Inappropriate implementation in Animation in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30582 was patched at 2024-05-15
1606.
Security Feature Bypass - Google Chrome (CVE-2021-30583) - Medium [377]
Description: Insufficient policy enforcement in image handling in iOS in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30583 was patched at 2024-05-15
1607.
Security Feature Bypass - Samba (CVE-2018-16857) - Medium [377]
Description: {'vulners_cve_data_all': 'Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of passwords) in a window of more than 3 minutes may not watch for bad passwords at all. The primary risk from this issue is with regards to domains that have been upgraded from Samba 4.8 and earlier. In these cases the manual testing done to confirm an organisation's password policies apply as expected may not have been re-done after the upgrade.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-16857 was patched at 2024-05-15
1608.
Arbitrary File Reading - PHP (CVE-2008-0194) - Medium [376]
Description: Directory traversal vulnerability in wp-db-backup.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-0194 was patched at 2024-05-15
1609.
Information Disclosure - APT (CVE-2023-50781) - Medium [376]
Description: {'vulners_cve_data_all': 'A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-50781 was patched at 2024-05-15
redos: CVE-2023-50781 was patched at 2024-05-21
1610.
Information Disclosure - Netty (CVE-2015-2156) - Medium [376]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Netty is a non-blocking I/O client-server framework for the development of Java network applications such as protocol servers and clients | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-2156 was patched at 2024-05-15
1611.
Information Disclosure - Node.js (CVE-2021-32050) - Medium [376]
Description: {'vulners_cve_data_all': 'Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed.\n\nWithout due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default).\n\nThis issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0).\n\n', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-32050 was patched at 2024-05-15
1612.
Unknown Vulnerability Type - Git (CVE-2022-1996) - Medium [376]
Description: {'vulners_cve_data_all': 'Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.4 | 14 | Git | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-1996 was patched at 2024-05-15
1613.
Unknown Vulnerability Type - Linux Kernel (CVE-2013-1958) - Medium [376]
Description: {'vulners_cve_data_all': 'The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.8.6 does not properly enforce capability requirements for controlling the PID value associated with a UNIX domain socket, which allows local users to bypass intended access restrictions by leveraging the time interval during which a user namespace has been created but a PID namespace has not been created.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Linux内核scm_check_creds安全绕过漏洞(CVE-2013-1958)) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.2 | 10 | CVSS Base Score is 1.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-1958 was patched at 2024-05-15
1614.
Authentication Bypass - iOS (CVE-2019-5061) - Medium [375]
Description: {'vulners_cve_data_all': 'An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This could lead to different denial of service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clients in other nearby Aps of the same wireless infrastructure. An attacker can forge Authentication and Association Request packets to trigger this vulnerability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-5061 was patched at 2024-05-15
1615.
Denial of Service - Kerberos (CVE-2018-5710) - Medium [375]
Description: An issue was discovered in MIT
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-5710 was patched at 2024-05-15
1616.
Denial of Service - Unknown Product (CVE-2007-6718) - Medium [375]
Description: {'vulners_cve_data_all': 'MPlayer, possibly 1.0rc1, allows remote attackers to cause a denial of service (SIGSEGV and application crash) via (1) a malformed MP3 file, as demonstrated by lol-mplayer.mp3; (2) a malformed Ogg Vorbis file, as demonstrated by lol-mplayer.ogg; (3) a malformed MPEG-1 file, as demonstrated by lol-mplayer.mpg; (4) a malformed MPEG-2 file, as demonstrated by lol-mplayer.m2v; (5) a malformed MPEG-4 AVI file, as demonstrated by lol-mplayer.avi; (6) a malformed FLAC file, as demonstrated by lol-mplayer.flac; (7) a malformed Ogg Theora file, as demonstrated by lol-mplayer.ogm; (8) a malformed WMV file, as demonstrated by lol-mplayer.wmv; or (9) a malformed AAC file, as demonstrated by lol-mplayer.aac. NOTE: vector 5 might overlap CVE-2007-4938, and vector 6 might overlap CVE-2008-0486.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] MPlayer demux_audio.c远程栈溢出漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-6718 was patched at 2024-05-15
1617.
Denial of Service - Unknown Product (CVE-2008-1387) - Medium [375]
Description: {'vulners_cve_data_all': 'ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU consumption) via a crafted ARJ archive, as demonstrated by the PROTOS GENOME test suite for Archive Formats.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ClamAV ARJ文件解析拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1387 was patched at 2024-05-15
1618.
Denial of Service - Unknown Product (CVE-2008-1531) - Medium [375]
Description: {'vulners_cve_data_all': 'The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Lighttpd SSL错误拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1531 was patched at 2024-05-15
1619.
Denial of Service - Unknown Product (CVE-2008-1897) - Medium [375]
Description: {'vulners_cve_data_all': 'The IAX2 channel driver (chan_iax2) in Asterisk Open Source 1.0.x, 1.2.x before 1.2.28, and 1.4.x before 1.4.19.1; Business Edition A.x.x, B.x.x before B.2.5.2, and C.x.x before C.1.8.1; AsteriskNOW before 1.0.3; Appliance Developer Kit 0.x.x; and s800i before 1.1.0.3, when configured to allow unauthenticated calls, does not verify that an ACK response contains a call number matching the server's reply to a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed ACK response that does not complete a 3-way handshake. NOTE: this issue exists because of an incomplete fix for CVE-2008-1923.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Asterisk IAX2报文放大远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1897 was patched at 2024-05-15
1620.
Denial of Service - Unknown Product (CVE-2008-2119) - Medium [375]
Description: {'vulners_cve_data_all': 'Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic parsing (aka pedanticsipchecking) is enabled, allows remote attackers to cause a denial of service (daemon crash) via a SIP INVITE message that lacks a From header, related to invocations of the ast_uri_decode function, and improper handling of (1) an empty const string and (2) a NULL pointer.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Asterisk SIP通道驱动远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-2119 was patched at 2024-05-15
1621.
Denial of Service - Unknown Product (CVE-2008-5514) - Medium [375]
Description: {'vulners_cve_data_all': 'Off-by-one error in the rfc822_output_char function in the RFC822BUFFER routines in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit before imap-2007e and other applications, allows context-dependent attackers to cause a denial of service (crash) via an e-mail message that triggers a buffer overflow.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] UW-IMAP c-client库单字节溢出漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5514 was patched at 2024-05-15
1622.
Denial of Service - Unknown Product (CVE-2009-1789) - Medium [375]
Description: {'vulners_cve_data_all': 'mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Eggdrop servmsg.c远程拒绝服务漏洞, [seebug] Eggdrop/Windrop 1.6.19 ctcpbuf Remote Crash Vulnerability, [packetstorm] Eggdrop/Windrop 1.6.19 Denial Of Service, [exploitpack] EggdropWindrop 1.6.19 - ctcpbuf Remote Crash, [exploitdb] Eggdrop/Windrop 1.6.19 - ctcpbuf Remote Crash) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1789 was patched at 2024-05-15
1623.
Denial of Service - Unknown Product (CVE-2009-2286) - Medium [375]
Description: {'vulners_cve_data_all': 'Buffer overflow in compface 1.5.2 and earlier allows user-assisted attackers to cause a denial of service (crash) via a long declaration in a .xbm file. NOTE: this issue only affects compface on distributions that used a certain patch.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Compface '.xbm'文件缓冲区溢出漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-2286 was patched at 2024-05-15
1624.
Denial of Service - Unknown Product (CVE-2009-3627) - Medium [375]
Description: {'vulners_cve_data_all': 'The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] libhtml-parser-perl vulnerability USN-855-1) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3627 was patched at 2024-05-15
1625.
Denial of Service - Unknown Product (CVE-2011-1922) - Medium [375]
Description: {'vulners_cve_data_all': 'daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Unbound DNS Resolver远程拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-1922 was patched at 2024-05-15
1626.
Denial of Service - Unknown Product (CVE-2011-2713) - Medium [375]
Description: {'vulners_cve_data_all': 'oowriter in OpenOffice.org 3.3.0 and LibreOffice before 3.4.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted DOC file that triggers an out-of-bounds read in the DOC sprm parser.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] OpenOffice Microsoft Word文件格式输入程序多个安全漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-2713 was patched at 2024-05-15
1627.
Denial of Service - Unknown Product (CVE-2011-3594) - Medium [375]
Description: {'vulners_cve_data_all': 'The g_markup_escape_text function in the SILC protocol plug-in in libpurple 2.10.0 and earlier, as used in Pidgin and possibly other products, allows remote attackers to cause a denial of service (crash) via invalid UTF-8 sequences that trigger use of invalid pointers and an out-of-bounds read, related to interactions with certain versions of glib2.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Pidgin "silc_private_message()"拒绝服务漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-3594 was patched at 2024-05-15
1628.
Denial of Service - Unknown Product (CVE-2012-3236) - Medium [375]
Description: {'vulners_cve_data_all': 'fits-io.c in GIMP before 2.8.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a malformed XTENSION header of a .fit file, as demonstrated using a long string.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] GIMP 2.8.0 - .FIT File Format Denial of Service, [seebug] GIMP 2.8.0 FIT File Format DoS, [exploitdb] GIMP 2.8.0 - '.FIT' File Format Denial of Service) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-3236 was patched at 2024-05-15
1629.
Denial of Service - Unknown Product (CVE-2012-5470) - Medium [375]
Description: {'vulners_cve_data_all': 'libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted PNG file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] VLC Media Player 读访问冲突任意代码执行漏洞(CVE-2012-5470)) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-5470 was patched at 2024-05-15
1630.
Denial of Service - Unknown Product (CVE-2014-1684) - Medium [375]
Description: {'vulners_cve_data_all': 'The ASF_ReadObject_file_properties function in modules/demux/asf/libasf.c in the ASF Demuxer in VideoLAN VLC Media Player before 2.1.3 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a zero minimum and maximum data packet size in an ASF file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-1684 was patched at 2024-05-15
1631.
Incorrect Calculation - Kerberos (CVE-2007-5902) - Medium [375]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 1 | 14 | Kerberos is a protocol for authenticating service requests between trusted hosts across an untrusted network, such as the internet | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-5902 was patched at 2024-05-15
1632.
Memory Corruption - Unknown Product (CVE-2007-2835) - Medium [375]
Description: {'vulners_cve_data_all': 'Multiple stack-based buffer overflows in (1) CCE_pinyin.c and (2) xl_pinyin.c in ImmModules/cce/ in unicon-imc2 3.0.4, as used by zhcon and other applications, allow local users to gain privileges via a long HOME environment variable.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Unicon-imc2环境变量本地缓冲区溢出漏洞) | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-2835 was patched at 2024-05-15
1633.
Memory Corruption - Unknown Product (CVE-2019-20005) - Medium [375]
Description: {'vulners_cve_data_all': 'An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to a heap-based buffer over-read while running strchr() starting with a pointer after a '\\0' character (where the processing of a string was finished).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-20005 was patched at 2024-05-15
1634.
Memory Corruption - Unknown Product (CVE-2019-20199) - Medium [375]
Description: {'vulners_cve_data_all': 'An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling, leading to NULL pointer dereference while running strlen() on a NULL pointer.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-20199 was patched at 2024-05-15
1635.
Memory Corruption - Unknown Product (CVE-2019-6129) - Medium [375]
Description: {'vulners_cve_data_all': 'png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-6129 was patched at 2024-05-15
1636.
Memory Corruption - Unknown Product (CVE-2019-6442) - Medium [375]
Description: {'vulners_cve_data_all': 'An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, related to config_remotely in ntp_config.c, yyparse in ntp_parser.tab.c, and yyerror in ntp_parser.y.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-6442 was patched at 2024-05-15
1637.
Memory Corruption - Unknown Product (CVE-2020-21050) - Medium [375]
Description: {'vulners_cve_data_all': 'Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-21050 was patched at 2024-05-15
1638.
Memory Corruption - Unknown Product (CVE-2020-24119) - Medium [375]
Description: {'vulners_cve_data_all': 'A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-24119 was patched at 2024-05-15
1639.
Memory Corruption - Unknown Product (CVE-2021-21417) - Medium [375]
Description: {'vulners_cve_data_all': 'fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free violation was discovered in fluidsynth, that can be triggered when loading an invalid SoundFont file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-21417 was patched at 2024-05-15
1640.
Memory Corruption - Unknown Product (CVE-2021-26194) - Medium [375]
Description: {'vulners_cve_data_all': 'An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_is_lexical_environment in the ecma-helpers.c file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-26194 was patched at 2024-05-15
1641.
Memory Corruption - Unknown Product (CVE-2021-26198) - Medium [375]
Description: {'vulners_cve_data_all': 'An issue was discovered in JerryScript 2.4.0. There is a SEVG in ecma_deref_bigint in ecma-helpers.c file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-26198 was patched at 2024-05-15
1642.
Memory Corruption - Unknown Product (CVE-2021-26199) - Medium [375]
Description: {'vulners_cve_data_all': 'An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_bytecode_ref in ecma-helpers.c file.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-26199 was patched at 2024-05-15
1643.
Memory Corruption - Unknown Product (CVE-2021-42716) - Medium [375]
Description: {'vulners_cve_data_all': 'An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially have crashed a service using stb_image, or read up to 1024 bytes of non-consecutive heap data without control over the read location.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-42716 was patched at 2024-05-15
1644.
Memory Corruption - Unknown Product (CVE-2022-30045) - Medium [375]
Description: {'vulners_cve_data_all': 'An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling while parsing crafted XML files, leading to a heap out-of-bounds read.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-30045 was patched at 2024-05-15
1645.
Memory Corruption - Unknown Product (CVE-2023-4969) - Medium [375]
Description: {'vulners_cve_data_all': 'A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-4969 was patched at 2024-05-15
1646.
Remote Code Execution - Unknown Product (CVE-2023-44451) - Medium [375]
Description: {'vulners_cve_data_all': 'Linux Mint Xreader EPUB File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of EPUB files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-21897.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
redos: CVE-2023-44451 was patched at 2024-04-18
1647.
Arbitrary File Writing - PHP (CVE-2006-5705) - Medium [374]
Description: Multiple directory traversal vulnerabilities in plugins/wp-db-backup.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-5705 was patched at 2024-05-15
1648.
Information Disclosure - Unknown Product (CVE-2008-1033) - Medium [374]
Description: {'vulners_cve_data_all': 'The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading the log data, related to "authentication environment variables."', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2008-003更新修复多个安全漏洞) | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.2 | 10 | CVSS Base Score is 2.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-1033 was patched at 2024-05-15
1649.
Command Injection - iOS (CVE-2020-6581) - Medium [373]
Description: Nag
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-6581 was patched at 2024-05-15
1650.
Remote Code Execution - Exim (CVE-2004-0399) - Medium [373]
Description: Stack-based buffer overflow in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Exim is a mail transfer agent (MTA) used on Unix-like operating systems | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0399 was patched at 2024-05-15
1651.
Remote Code Execution - Exim (CVE-2004-0400) - Medium [373]
Description: Stack-based buffer overflow in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Exim is a mail transfer agent (MTA) used on Unix-like operating systems | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0400 was patched at 2024-05-15
1652.
Remote Code Execution - Exim (CVE-2004-2571) - Medium [373]
Description: Multiple buffer overflows in EnderUNIX isoqlog 2.1.1 allow remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Exim is a mail transfer agent (MTA) used on Unix-like operating systems | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-2571 was patched at 2024-05-15
1653.
Remote Code Execution - Exim (CVE-2011-1407) - Medium [373]
Description: The DKIM implementation in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Exim is a mail transfer agent (MTA) used on Unix-like operating systems | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-1407 was patched at 2024-05-15
1654.
Remote Code Execution - Exim (CVE-2011-1764) - Medium [373]
Description: Format string vulnerability in the dkim_
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Exim is a mail transfer agent (MTA) used on Unix-like operating systems | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-1764 was patched at 2024-05-15
1655.
Remote Code Execution - ImageMagick (CVE-2004-0827) - Medium [373]
Description: Multiple buffer overflows in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2004-0827 was patched at 2024-05-15
1656.
Remote Code Execution - ImageMagick (CVE-2005-0005) - Medium [373]
Description: Heap-based buffer overflow in psd.c for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-0005 was patched at 2024-05-15
1657.
Remote Code Execution - ImageMagick (CVE-2005-0397) - Medium [373]
Description: Format string vulnerability in the SetImageInfo function in image.c for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-0397 was patched at 2024-05-15
1658.
Remote Code Execution - ImageMagick (CVE-2005-0762) - Medium [373]
Description: Heap-based buffer overflow in the SGI parser in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-0762 was patched at 2024-05-15
1659.
Remote Code Execution - ImageMagick (CVE-2006-2440) - Medium [373]
Description: Heap-based buffer overflow in the libMagick component of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-2440 was patched at 2024-05-15
1660.
Remote Code Execution - ImageMagick (CVE-2006-3376) - Medium [373]
Description: Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype, (4) gimp, (5) libgsf, and (6)
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3376 was patched at 2024-05-15
1661.
Remote Code Execution - ImageMagick (CVE-2010-2233) - Medium [373]
Description: tif_getimage.c in LibTIFF 3.9.0 and 3.9.2 on 64-bit platforms, as used in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-2233 was patched at 2024-05-15
1662.
Remote Code Execution - ImageMagick (CVE-2012-1185) - Medium [373]
Description: Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1185 was patched at 2024-05-15
1663.
Remote Code Execution - Perl (CVE-2002-0916) - Medium [373]
Description: Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-0916 was patched at 2024-05-15
1664.
Remote Code Execution - Perl (CVE-2002-1174) - Medium [373]
Description: Buffer overflows in Fetchmail 6.0.0 and earlier allow remote attackers to cause a denial of service (crash) or
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-1174 was patched at 2024-05-15
1665.
Remote Code Execution - Perl (CVE-2002-1200) - Medium [373]
Description: Balabit Syslog-NG 1.4.x before 1.4.15, and 1.5.x before 1.5.20, when using template filenames or output, does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-1200 was patched at 2024-05-15
1666.
Remote Code Execution - Perl (CVE-2002-1277) - Medium [373]
Description: Buffer overflow in Window Maker (wmaker) 0.80.0 and earlier may allow remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-1277 was patched at 2024-05-15
1667.
Remote Code Execution - Perl (CVE-2002-1371) - Medium [373]
Description: filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-1371 was patched at 2024-05-15
1668.
Remote Code Execution - Perl (CVE-2003-0212) - Medium [373]
Description: handleAccept in rinetd before 0.62 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0212 was patched at 2024-05-15
1669.
Remote Code Execution - Perl (CVE-2003-0323) - Medium [373]
Description: Multiple buffer overflows in ircII 20020912 allows remote malicious IRC servers to cause a denial of service (crash) and possibly
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0323 was patched at 2024-05-15
1670.
Remote Code Execution - Perl (CVE-2003-0324) - Medium [373]
Description: Buffer overflows in EPIC IRC Client (EPIC4) 1.0.1 allows remote malicious IRC servers to cause a denial of service (crash) and possibly
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0324 was patched at 2024-05-15
1671.
Remote Code Execution - Perl (CVE-2003-0826) - Medium [373]
Description: lsh daemon (lshd) does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2003-0826 was patched at 2024-05-15
1672.
Remote Code Execution - Perl (CVE-2005-0687) - Medium [373]
Description: Format string vulnerability in Hashcash 1.16 allows remote attackers to cause a denial of service (memory consumption) and possibly
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-0687 was patched at 2024-05-15
1673.
Remote Code Execution - Perl (CVE-2005-2550) - Medium [373]
Description: Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-2550 was patched at 2024-05-15
1674.
Remote Code Execution - Perl (CVE-2005-2772) - Medium [373]
Description: Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-2772 was patched at 2024-05-15
1675.
Remote Code Execution - Perl (CVE-2005-3487) - Medium [373]
Description: Multiple buffer overflows in Scorched 3D 39.1 (bf) and earlier allow remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-3487 was patched at 2024-05-15
1676.
Remote Code Execution - Perl (CVE-2006-3355) - Medium [373]
Description: Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3355 was patched at 2024-05-15
1677.
Remote Code Execution - Perl (CVE-2006-4251) - Medium [373]
Description: Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4251 was patched at 2024-05-15
1678.
Remote Code Execution - Perl (CVE-2007-2459) - Medium [373]
Description: Heap-based buffer overflow in the BMP reader (bmp.c) in Imager
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-2459 was patched at 2024-05-15
1679.
Remote Code Execution - Perl (CVE-2007-4766) - Medium [373]
Description: Multiple integer overflows in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-4766 was patched at 2024-05-15
1680.
Remote Code Execution - Perl (CVE-2008-5695) - Medium [373]
Description: wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 8.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-5695 was patched at 2024-05-15
1681.
Remote Code Execution - Perl (CVE-2010-2628) - Medium [373]
Description: The IKE daemon in strongSwan 4.3.x before 4.3.7 and 4.4.x before 4.4.1 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-2628 was patched at 2024-05-15
1682.
Remote Code Execution - Perl (CVE-2012-5854) - Medium [373]
Description: Heap-based buffer overflow in WeeChat 0.3.6 through 0.3.9 allows remote attackers to cause a denial of service (crash or hang) and possibly
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-5854 was patched at 2024-05-15
1683.
Remote Code Execution - Perl (CVE-2013-1768) - Medium [373]
Description: The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-1768 was patched at 2024-05-15
1684.
Remote Code Execution - Perl (CVE-2016-1866) - Medium [373]
Description: Salt 2015.8.x before 2015.8.4 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-1866 was patched at 2024-05-15
1685.
Remote Code Execution - Python (CVE-2005-2491) - Medium [373]
Description: Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-2491 was patched at 2024-05-15
1686.
Remote Code Execution - Python (CVE-2011-4357) - Medium [373]
Description: Format string vulnerability in the p_cgi_error function in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4357 was patched at 2024-05-15
1687.
Remote Code Execution - Python (CVE-2018-7889) - Medium [373]
Description: gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-7889 was patched at 2024-05-15
1688.
Remote Code Execution - Python (CVE-2023-41334) - Medium [373]
Description: Astropy is a project for astronomy in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-41334 was patched at 2024-05-15
1689.
Remote Code Execution - Python (CVE-2023-45805) - Medium [373]
Description: pdm is a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-45805 was patched at 2024-05-15
1690.
Remote Code Execution - Wireshark (CVE-2012-4297) - Medium [373]
Description: Buffer overflow in the dissect_gsm_rlcmac_downlink function in epan/dissectors/packet-gsm_rlcmac.c in the GSM RLC MAC dissector in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-4297 was patched at 2024-05-15
1691.
Remote Code Execution - ownCloud (CVE-2021-44537) - Medium [373]
Description: ownCloud
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | ownCloud is an open-source software product for sharing and syncing of files in distributed and federated enterprise scenarios | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-44537 was patched at 2024-05-15
1692.
Unknown Vulnerability Type - Perl (CVE-2009-3639) - Medium [373]
Description: {'vulners_cve_data_all': 'The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] ProFTPD mod_tls模块CA SSL证书验证漏洞, [seebug] Mozilla Firefox NULL字符CA SSL证书验证安全绕过漏洞, [seebug] Randombit Botan Library X509 Certificate Validation Bypass Vulnerability(CVE-2017-2801), [seebug] mozilla-thunderbird多个安全漏洞, [exploitdb] Mozilla NSS NULL Character CA SSL Certificate Validation Security Bypass Vulnerability) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-3639 was patched at 2024-05-15
1693.
Unknown Vulnerability Type - Perl (CVE-2011-2719) - Medium [373]
Description: {'vulners_cve_data_all': 'libraries/auth/swekey/swekey.auth.lib.php in phpMyAdmin 3.x before 3.3.10.3 and 3.4.x before 3.4.3.2 does not properly manage sessions associated with Swekey authentication, which allows remote attackers to modify the SESSION superglobal array, other superglobal arrays, and certain swekey.auth.lib.php local variables via a crafted query string, a related issue to CVE-2011-2505.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
debian: CVE-2011-2719 was patched at 2024-05-15
1694.
Unknown Vulnerability Type - Perl (CVE-2013-0155) - Medium [373]
Description: {'vulners_cve_data_all': 'Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660 and CVE-2012-2694.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Ruby on Rails不安全查询生成漏洞, [seebug] Ruby on Rails嵌套参数SQL注入漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-0155 was patched at 2024-05-15
1695.
Unknown Vulnerability Type - Perl (CVE-2013-2503) - Medium [373]
Description: {'vulners_cve_data_all': 'Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Privoxy 3.0.20-1 Credential Exposure) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-2503 was patched at 2024-05-15
1696.
Unknown Vulnerability Type - Perl (CVE-2013-4729) - Medium [373]
Description: {'vulners_cve_data_all': 'import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file format, which allows remote authenticated users to modify the GLOBALS superglobal array, and consequently change the configuration, via a crafted request.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] phpMyAdmin <= 4.0.4.1 import.php GLOBALS变量注入漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-4729 was patched at 2024-05-15
1697.
Unknown Vulnerability Type - Python (CVE-2008-4099) - Medium [373]
Description: {'vulners_cve_data_all': 'PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
debian: CVE-2008-4099 was patched at 2024-05-15
1698.
Unknown Vulnerability Type - Python (CVE-2008-4126) - Medium [373]
Description: {'vulners_cve_data_all': 'PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not use random transaction IDs for DNS retries, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4099.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
debian: CVE-2008-4126 was patched at 2024-05-15
1699.
Security Feature Bypass - BIND (CVE-2021-3127) - Medium [372]
Description: NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-3127 was patched at 2024-05-15
1700.
Security Feature Bypass - FFmpeg (CVE-2015-8219) - Medium [372]
Description: {'vulners_cve_data_all': 'The init_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.2 does not enforce minimum-value and maximum-value constraints on tile coordinates, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-8219 was patched at 2024-05-15
1701.
Security Feature Bypass - Kubernetes (CVE-2022-0759) - Medium [372]
Description: {'vulners_cve_data_all': 'A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby applications that leverage kubeclient to parse kubeconfig files are susceptible to Man-in-the-middle attacks (MITM).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.7 | 14 | Kubernetes is an open-source container orchestration system for automating software deployment, scaling, and management | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-0759 was patched at 2024-05-15
1702.
Remote Code Execution - APT (CVE-2012-2942) - Medium [371]
Description: Buffer overflow in the trash buffer in the header c
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-2942 was patched at 2024-05-15
1703.
Remote Code Execution - Binutils (CVE-2005-1704) - Medium [371]
Description: Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The GNU Binary Utilities, or binutils, are a set of programming tools for creating and managing binary programs, object files, libraries, profile data, and assembly source code | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-1704 was patched at 2024-05-15
1704.
Remote Code Execution - GNOME desktop (CVE-2002-0838) - Medium [371]
Description: Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4)
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | GNOME originally an acronym for GNU Network Object Model Environment, is a free and open-source desktop environment for Linux and other Unix-like operating systems | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2002-0838 was patched at 2024-05-15
1705.
Remote Code Execution - Mozilla Firefox (CVE-2006-0297) - Medium [371]
Description: Multiple integer overflows in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-0297 was patched at 2024-05-15
1706.
Remote Code Execution - Mozilla Firefox (CVE-2006-2778) - Medium [371]
Description: The crypto.signText function in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-2778 was patched at 2024-05-15
1707.
Remote Code Execution - Mozilla Firefox (CVE-2006-3803) - Medium [371]
Description: Race condition in the JavaScript garbage collection in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-3803 was patched at 2024-05-15
1708.
Remote Code Execution - Mozilla Firefox (CVE-2006-5633) - Medium [371]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-5633 was patched at 2024-05-15
1709.
Remote Code Execution - Mozilla Firefox (CVE-2006-5748) - Medium [371]
Description: Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-5748 was patched at 2024-05-15
1710.
Remote Code Execution - PHP (CVE-2007-4840) - Medium [371]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-4840 was patched at 2024-05-15
1711.
Remote Code Execution - PHP (CVE-2008-0782) - Medium [371]
Description: Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the MOIN_ID user ID in a cookie for a userform action. NOTE: this issue can be leveraged for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-0782 was patched at 2024-05-15
1712.
Remote Code Execution - Samba (CVE-2005-0022) - Medium [371]
Description: Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-0022 was patched at 2024-05-15
1713.
Remote Code Execution - Zoom (CVE-2005-3178) - Medium [371]
Description: Buffer overflow in xloadimage 4.1 and earlier, and xli, might allow user-assisted attackers to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Zoom is the leader in modern enterprise video communications | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-3178 was patched at 2024-05-15
1714.
Unknown Vulnerability Type - Safari (CVE-2009-1710) - Medium [371]
Description: {'vulners_cve_data_all': 'WebKit in Apple Safari before 4.0 allows remote attackers to spoof the browser's display of (1) the host name, (2) security indicators, and unspecified other UI elements via a custom cursor in conjunction with a modified CSS3 hotspot property.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Safari 4.0多个安全漏洞) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.3 | 10 | CVSS Base Score is 2.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-1710 was patched at 2024-05-15
1715.
Authentication Bypass - Oracle Java SE (CVE-2018-2941) - Medium [370]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | Oracle Java SE | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-2941 was patched at 2024-05-15
1716.
Authentication Bypass - Oracle Java SE (CVE-2018-3209) - Medium [370]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | Oracle Java SE | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-3209 was patched at 2024-05-15
1717.
Authentication Bypass - Oracle Java SE (CVE-2020-14664) - Medium [370]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | Oracle Java SE | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-14664 was patched at 2024-05-15
1718.
Authentication Bypass - Perl (CVE-2011-2766) - Medium [370]
Description: The FCGI (aka Fast CGI) module 0.70 through 0.73 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-2766 was patched at 2024-05-15
1719.
Authentication Bypass - Perl (CVE-2013-2120) - Medium [370]
Description: The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-2120 was patched at 2024-05-15
1720.
Authentication Bypass - wpa_supplicant (CVE-2019-9496) - Medium [370]
Description: {'vulners_cve_data_all': 'An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerable. An attacker may force the hostapd process to terminate, performing a denial of service attack. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | wpa_supplicant is a free software implementation of an IEEE 802.11i supplicant for Linux, FreeBSD, NetBSD, QNX, AROS, Microsoft Windows, Solaris, OS/2 (including ArcaOS and eComStation) and Haiku | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-9496 was patched at 2024-05-15
1721.
Denial of Service - Apache HTTP Server (CVE-2007-0086) - Medium [370]
Description: The
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-0086 was patched at 2024-05-15
1722.
Denial of Service - Apache HTTP Server (CVE-2018-8011) - Medium [370]
Description: By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-8011 was patched at 2024-05-15
1723.
Denial of Service - GNU Bash (CVE-2012-6711) - Medium [370]
Description: A heap-based buffer overflow exists in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | Bash is the shell, or command language interpreter, for the GNU operating system | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-6711 was patched at 2024-05-15
1724.
Denial of Service - HTTP/2 (CVE-2017-10908) - Medium [370]
Description: H2O version 2.2.3 and earlier allows remote attackers to cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | HTTP/2 is a major revision of the HTTP network protocol used by the World Wide Web | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-10908 was patched at 2024-05-15
1725.
Denial of Service - HTTP/2 (CVE-2021-41524) - Medium [370]
Description: While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | HTTP/2 is a major revision of the HTTP network protocol used by the World Wide Web | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-41524 was patched at 2024-05-15
1726.
Denial of Service - Linux Kernel (CVE-2012-6703) - Medium [370]
Description: Integer overflow in the snd_compr_allocate_buffer function in sound/core/compress_offload.c in the ALSA subsystem in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-6703 was patched at 2024-05-15
1727.
Denial of Service - Linux Kernel (CVE-2013-7445) - Medium [370]
Description: The Direct Rendering Manager (DRM) subsystem in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-7445 was patched at 2024-05-15
1728.
Denial of Service - Linux Kernel (CVE-2014-9914) - Medium [370]
Description: Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-9914 was patched at 2024-05-15
1729.
Denial of Service - Linux Kernel (CVE-2015-8961) - Medium [370]
Description: The __ext4_journal_stop function in fs/ext4/ext4_jbd2.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-8961 was patched at 2024-05-15
1730.
Denial of Service - Linux Kernel (CVE-2016-10153) - Medium [370]
Description: The crypto scatterlist API in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-10153 was patched at 2024-05-15
1731.
Denial of Service - Linux Kernel (CVE-2016-2070) - Medium [370]
Description: The tcp_cwnd_reduction function in net/ipv4/tcp_input.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-2070 was patched at 2024-05-15
1732.
Denial of Service - Linux Kernel (CVE-2016-9120) - Medium [370]
Description: Race condition in the ion_ioctl function in drivers/staging/android/ion/ion.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-9120 was patched at 2024-05-15
1733.
Denial of Service - Linux Kernel (CVE-2016-9313) - Medium [370]
Description: security/keys/big_key.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-9313 was patched at 2024-05-15
1734.
Denial of Service - Linux Kernel (CVE-2016-9777) - Medium [370]
Description: KVM in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-9777 was patched at 2024-05-15
1735.
Denial of Service - Linux Kernel (CVE-2017-14497) - Medium [370]
Description: The tpacket_rcv function in net/packet/af_packet.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-14497 was patched at 2024-05-15
1736.
Denial of Service - Linux Kernel (CVE-2017-17852) - Medium [370]
Description: kernel/bpf/verifier.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-17852 was patched at 2024-05-15
1737.
Denial of Service - Linux Kernel (CVE-2017-17853) - Medium [370]
Description: kernel/bpf/verifier.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-17853 was patched at 2024-05-15
1738.
Denial of Service - Linux Kernel (CVE-2017-17854) - Medium [370]
Description: kernel/bpf/verifier.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-17854 was patched at 2024-05-15
1739.
Denial of Service - Linux Kernel (CVE-2017-17855) - Medium [370]
Description: kernel/bpf/verifier.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-17855 was patched at 2024-05-15
1740.
Denial of Service - Linux Kernel (CVE-2017-17856) - Medium [370]
Description: kernel/bpf/verifier.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-17856 was patched at 2024-05-15
1741.
Denial of Service - Linux Kernel (CVE-2017-17857) - Medium [370]
Description: The check_stack_boundary function in kernel/bpf/verifier.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-17857 was patched at 2024-05-15
1742.
Denial of Service - Linux Kernel (CVE-2017-5547) - Medium [370]
Description: drivers/hid/hid-corsair.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-5547 was patched at 2024-05-15
1743.
Denial of Service - Linux Kernel (CVE-2017-5548) - Medium [370]
Description: drivers/net/ieee802154/atusb.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-5548 was patched at 2024-05-15
1744.
Denial of Service - Linux Kernel (CVE-2017-8061) - Medium [370]
Description: drivers/media/usb/dvb-usb/dvb-usb-firmware.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-8061 was patched at 2024-05-15
1745.
Denial of Service - Linux Kernel (CVE-2017-8062) - Medium [370]
Description: drivers/media/usb/dvb-usb/dw2102.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-8062 was patched at 2024-05-15
1746.
Denial of Service - Linux Kernel (CVE-2017-8063) - Medium [370]
Description: drivers/media/usb/dvb-usb/cxusb.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-8063 was patched at 2024-05-15
1747.
Denial of Service - Linux Kernel (CVE-2017-8066) - Medium [370]
Description: drivers/net/can/usb/gs_usb.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-8066 was patched at 2024-05-15
1748.
Denial of Service - Linux Kernel (CVE-2017-8067) - Medium [370]
Description: drivers/char/virtio_console.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-8067 was patched at 2024-05-15
1749.
Denial of Service - Linux Kernel (CVE-2017-8068) - Medium [370]
Description: drivers/net/usb/pegasus.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-8068 was patched at 2024-05-15
1750.
Denial of Service - Linux Kernel (CVE-2017-8069) - Medium [370]
Description: drivers/net/usb/rtl8150.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-8069 was patched at 2024-05-15
1751.
Denial of Service - Linux Kernel (CVE-2017-8070) - Medium [370]
Description: drivers/net/usb/catc.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-8070 was patched at 2024-05-15
1752.
Denial of Service - Linux Kernel (CVE-2017-9986) - Medium [370]
Description: The intr function in sound/oss/msnd_pinnacle.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-9986 was patched at 2024-05-15
1753.
Denial of Service - Linux Kernel (CVE-2019-12615) - Medium [370]
Description: An issue was discovered in get_vdev_port_node_info in arch/sparc/kernel/mdesc.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-12615 was patched at 2024-05-15
1754.
Denial of Service - Linux Kernel (CVE-2019-12881) - Medium [370]
Description: i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-12881 was patched at 2024-05-15
1755.
Denial of Service - Linux Kernel (CVE-2019-18807) - Medium [370]
Description: Two memory leaks in the sja1105_static_config_upload() function in drivers/net/dsa/sja1105/sja1105_spi.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-18807 was patched at 2024-05-15
1756.
Denial of Service - Linux Kernel (CVE-2019-18812) - Medium [370]
Description: A memory leak in the sof_dfsentry_write() function in sound/soc/sof/debug.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-18812 was patched at 2024-05-15
1757.
Denial of Service - Linux Kernel (CVE-2019-19070) - Medium [370]
Description: A memory leak in the spi_gpio_probe() function in drivers/spi/spi-gpio.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-19070 was patched at 2024-05-15
1758.
Denial of Service - Linux Kernel (CVE-2021-20226) - Medium [370]
Description: A use-after-free flaw was found in the io_uring in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-20226 was patched at 2024-05-15
1759.
Denial of Service - Linux Kernel (CVE-2021-26934) - Medium [370]
Description: {'vulners_cve_data_all': 'An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration, but this wasn't stated accordingly in its support status entry.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-26934 was patched at 2024-05-15
1760.
Denial of Service - Windows LDAP (CVE-2011-4082) - Medium [370]
Description: A local file inclusion flaw was found in the way the php
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | Windows LDAP (Lightweight Directory Access Protocol) is an open and cross platform protocol used for directory services authentication | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4082 was patched at 2024-05-15
1761.
Denial of Service - Windows LDAP (CVE-2017-17740) - Medium [370]
Description: contrib/slapd-modules/nops/nops.c in Open
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | Windows LDAP (Lightweight Directory Access Protocol) is an open and cross platform protocol used for directory services authentication | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-17740 was patched at 2024-05-15
1762.
Path Traversal - Windows LDAP (CVE-2009-4427) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.9 | 14 | Windows LDAP (Lightweight Directory Access Protocol) is an open and cross platform protocol used for directory services authentication | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4427 was patched at 2024-05-15
1763.
Security Feature Bypass - Apache HTTP Server (CVE-2019-17567) - Medium [370]
Description: {'vulners_cve_data_all': 'Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-17567 was patched at 2024-05-15
1764.
Security Feature Bypass - GitLab (CVE-2019-19260) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | GitLab is a DevOps software package that combines the ability to develop, secure, and operate software in a single application | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-19260 was patched at 2024-05-15
1765.
Security Feature Bypass - Linux Kernel (CVE-2013-6380) - Medium [370]
Description: {'vulners_cve_data_all': 'The aac_send_raw_srb function in drivers/scsi/aacraid/commctrl.c in the Linux kernel through 3.12.1 does not properly validate a certain size value, which allows local users to cause a denial of service (invalid pointer dereference) or possibly have unspecified other impact via an FSACTL_SEND_RAW_SRB ioctl call that triggers a crafted SRB command.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2013-6380 was patched at 2024-05-15
1766.
Security Feature Bypass - Windows Kernel (CVE-2023-45284) - Medium [370]
Description: {'vulners_cve_data_all': 'On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local. With fix, IsLocal now correctly reports these names as non-local.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | Windows Kernel | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-45284 was patched at 2024-05-15
1767.
Arbitrary File Writing - QEMU (CVE-2008-4553) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0.7 | 14 | QEMU is a generic and open source machine & userspace emulator and virtualizer | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-4553 was patched at 2024-05-15
1768.
Information Disclosure - Intel(R) Processor (CVE-2023-38575) - Medium [369]
Description: Non-transparent sharing of return predictor targets between contexts in some
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | Intel's processors from the pioneering 4-bit 4004 (1971) to the present high-end offerings | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-38575 was patched at 2024-05-15
ubuntu: CVE-2023-38575 was patched at 2024-05-29
1769.
Information Disclosure - Linux Kernel (CVE-2011-4916) - Medium [369]
Description: {'vulners_cve_data_all': 'Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4916 was patched at 2024-05-15
1770.
Information Disclosure - Linux Kernel (CVE-2011-4917) - Medium [369]
Description: In the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-4917 was patched at 2024-05-15
1771.
Information Disclosure - Linux Kernel (CVE-2014-9892) - Medium [369]
Description: The snd_compr_tstamp function in sound/core/compress_offload.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-9892 was patched at 2024-05-15
1772.
Information Disclosure - Linux Kernel (CVE-2015-8950) - Medium [369]
Description: arch/arm64/mm/dma-mapping.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2015-8950 was patched at 2024-05-15
1773.
Information Disclosure - Linux Kernel (CVE-2017-13693) - Medium [369]
Description: The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-13693 was patched at 2024-05-15
1774.
Information Disclosure - Linux Kernel (CVE-2017-13694) - Medium [369]
Description: The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-13694 was patched at 2024-05-15
1775.
Information Disclosure - Linux Kernel (CVE-2021-20320) - Medium [369]
Description: {'vulners_cve_data_all': 'A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-20320 was patched at 2024-05-15
1776.
Information Disclosure - Linux Kernel (CVE-2021-3736) - Medium [369]
Description: {'vulners_cve_data_all': 'A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in Virtual Function I/O (VFIO) Mediated devices. This flaw could allow a local attacker to leak internal kernel information.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-3736 was patched at 2024-05-15
1777.
Information Disclosure - Linux Kernel (CVE-2021-4023) - Medium [369]
Description: {'vulners_cve_data_all': 'A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-uring operations during a shortage of free space. This flaw allows a local user with permissions to execute io-uring requests to possibly crash the system.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-4023 was patched at 2024-05-15
1778.
Information Disclosure - Linux Kernel (CVE-2021-46906) - Medium [369]
Description: {'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nHID: usbhid: fix info leak in hid_submit_ctrl\n\nIn hid_submit_ctrl(), the way of calculating the report length doesn't\ntake into account that report->size can be zero. When running the\nsyzkaller reproducer, a report of size 0 causes hid_submit_ctrl) to\ncalculate transfer_buffer_length as 16384. When this urb is passed to\nthe usb core layer, KMSAN reports an info leak of 16384 bytes.\n\nTo fix this, first modify hid_report_len() to account for the zero\nreport size case by using DIV_ROUND_UP for the division. Then, call it\nfrom hid_submit_ctrl().', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-46906 was patched at 2024-05-15
1779.
Information Disclosure - Linux Kernel (CVE-2021-46917) - Medium [369]
Description: {'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: fix wq cleanup of WQCFG registers\n\nA pre-release silicon erratum workaround where wq reset does not clear\nWQCFG registers was leaked into upstream code. Use wq reset command\ninstead of blasting the MMIO region. This also address an issue where\nwe clobber registers in future devices.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-46917 was patched at 2024-05-15
redos: CVE-2021-46917 was patched at 2024-04-18
1780.
Information Disclosure - Windows Kernel (CVE-2024-0075) - Medium [369]
Description: NVIDIA GPU Display Driver for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | Windows Kernel | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-0075 was patched at 2024-05-15
1781.
Remote Code Execution - Cacti (CVE-2020-7058) - Medium [369]
Description: data_input.php in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-7058 was patched at 2024-05-15
1782.
Remote Code Execution - Cacti (CVE-2020-7237) - Medium [369]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-7237 was patched at 2024-05-15
1783.
Remote Code Execution - Libarchive (CVE-2007-3641) - Medium [369]
Description: archive_read_support_format_tar.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Multi-format archive and compression library | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-3641 was patched at 2024-05-15
1784.
Remote Code Execution - Scripting Engine (CVE-2018-1999023) - Medium [369]
Description: The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Scripting Engine | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-1999023 was patched at 2024-05-15
1785.
Remote Code Execution - TRIE (CVE-2020-17354) - Medium [369]
Description: LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scope, as demonstrated by dangerous Scheme code in a .ly file that causes arbitrary
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | TRIE | |
| 0.9 | 10 | CVSS Base Score is 8.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-17354 was patched at 2024-05-15
1786.
Unknown Vulnerability Type - nginx (CVE-2009-4487) - Medium [369]
Description: {'vulners_cve_data_all': 'nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([packetstorm] Nginx, Varnish, Cherokee, etc Log Injection) | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2009-4487 was patched at 2024-05-15
1787.
Code Injection - Perl (CVE-2005-0436) - Medium [368]
Description: Direct
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2005-0436 was patched at 2024-05-15
1788.
XXE Injection - Perl (CVE-2016-4434) - Medium [368]
Description: Apache Tika before 1.13 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | XXE Injection | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-4434 was patched at 2024-05-15
1789.
XXE Injection - Python (CVE-2021-29421) - Medium [368]
Description: models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | XXE Injection | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-29421 was patched at 2024-05-15
1790.
XXE Injection - Python (CVE-2023-45139) - Medium [368]
Description: fontTools is a library for manipulating fonts, written in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | XXE Injection | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-45139 was patched at 2024-05-15
1791.
XXE Injection - ownCloud (CVE-2014-2055) - Medium [368]
Description: SabreDAV before 1.7.11, as used in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | XXE Injection | |
| 0.6 | 14 | ownCloud is an open-source software product for sharing and syncing of files in distributed and federated enterprise scenarios | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-2055 was patched at 2024-05-15
1792.
Authentication Bypass - PHP (CVE-2010-4481) - Medium [367]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2010-4481 was patched at 2024-05-15
1793.
Information Disclosure - Perl (CVE-2007-2488) - Medium [367]
Description: The IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not pro
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-2488 was patched at 2024-05-15
1794.
Information Disclosure - wpa_supplicant (CVE-2022-23303) - Medium [367]
Description: {'vulners_cve_data_all': 'The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | wpa_supplicant is a free software implementation of an IEEE 802.11i supplicant for Linux, FreeBSD, NetBSD, QNX, AROS, Microsoft Windows, Solaris, OS/2 (including ArcaOS and eComStation) and Haiku | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-23303 was patched at 2024-05-15
1795.
Information Disclosure - wpa_supplicant (CVE-2022-23304) - Medium [367]
Description: {'vulners_cve_data_all': 'The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | wpa_supplicant is a free software implementation of an IEEE 802.11i supplicant for Linux, FreeBSD, NetBSD, QNX, AROS, Microsoft Windows, Solaris, OS/2 (including ArcaOS and eComStation) and Haiku | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-23304 was patched at 2024-05-15
1796.
Security Feature Bypass - Perl (CVE-2021-22573) - Medium [367]
Description: {'vulners_cve_data_all': 'The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sure that the token's payload comes from valid provider, not from someone else. An attacker can provide a compromised token with custom payload. The token will pass the validation on the client side. We recommend upgrading to version 1.33.3 or above', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-22573 was patched at 2024-05-15
1797.
Security Feature Bypass - Python (CVE-2019-13611) - Medium [367]
Description: {'vulners_cve_data_all': 'An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-13611 was patched at 2024-05-15
1798.
Command Injection - RPC (CVE-2019-15164) - Medium [366]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2019-15164 was patched at 2024-05-15
1799.
Remote Code Execution - .NET and Visual Studio (CVE-2024-30045) - Medium [366]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | .NET and Visual Studio | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2024-30045 was patched at 2024-05-14, 2024-05-15, 2024-05-23
oraclelinux: CVE-2024-30045 was patched at 2024-05-14, 2024-05-29
redhat: CVE-2024-30045 was patched at 2024-05-14, 2024-05-15, 2024-05-23
ubuntu: CVE-2024-30045 was patched at 2024-05-16
1800.
Remote Code Execution - Confluence (CVE-2022-1231) - Medium [366]
Description: XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Confluence is a web-based corporate wiki | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-1231 was patched at 2024-05-15
1801.
Remote Code Execution - SQLite (CVE-2021-20227) - Medium [366]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | SQLite is a database engine written in the C programming language | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-20227 was patched at 2024-05-15
1802.
Remote Code Execution - iOS (CVE-2012-0219) - Medium [366]
Description: Heap-based buffer overflow in the x
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | iOS is an operating system developed and marketed by Apple Inc | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-0219 was patched at 2024-05-15
1803.
Denial of Service - Google Chrome (CVE-2011-0480) - Medium [365]
Description: Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Google Chrome is a popular, free web browser developed by Google. It was first released in 2008 and is available for various operating systems, including Microsoft Windows, Apple macOS, Linux, Android, and iOS. | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2011-0480 was patched at 2024-05-15
1804.
Denial of Service - Mozilla Firefox (CVE-2006-1737) - Medium [365]
Description: Integer overflow in Mozilla
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-1737 was patched at 2024-05-15
1805.
Denial of Service - Safari (CVE-2018-4214) - Medium [365]
Description: An issue was discovered in certain Apple products. iOS before 11.4 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-4214 was patched at 2024-05-15
1806.
Path Traversal - PHP (CVE-2008-4769) - Medium [365]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2008-4769 was patched at 2024-05-15
1807.
Security Feature Bypass - APT (CVE-2014-3607) - Medium [365]
Description: DefaultHostnameVerifier in Ld
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | A free-software user interface that works with core libraries to handle the installation and removal of software on Debian | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2014-3607 was patched at 2024-05-15
1808.
Security Feature Bypass - OpenSSL (CVE-2016-2390) - Medium [365]
Description: {'vulners_cve_data_all': 'The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when built with the --with-openssl option, which allows remote attackers to cause a denial of service (application crash) via a plaintext HTTP message.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-2390 was patched at 2024-05-15
1809.
Security Feature Bypass - OpenSSL (CVE-2018-0733) - Medium [365]
Description: {'vulners_cve_data_all': 'Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that would be considered as authenticated in an amount of tries lower than that guaranteed by the security claims of the scheme. The module can only be compiled by the HP-UX assembler, so that only HP-UX PA-RISC targets are affected. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g).', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-0733 was patched at 2024-05-15
1810.
Cross Site Scripting - Windows LDAP (CVE-2012-1114) - Medium [364]
Description: A
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.9 | 14 | Windows LDAP (Lightweight Directory Access Protocol) is an open and cross platform protocol used for directory services authentication | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1114 was patched at 2024-05-15
1811.
Cross Site Scripting - Windows LDAP (CVE-2012-1115) - Medium [364]
Description: A
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.9 | 14 | Windows LDAP (Lightweight Directory Access Protocol) is an open and cross platform protocol used for directory services authentication | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2012-1115 was patched at 2024-05-15
1812.
Information Disclosure - Chromium (CVE-2021-30615) - Medium [364]
Description: {'vulners_cve_data_all': 'Chromium: CVE-2021-30615 Cross-origin data leak in Navigation', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-30615 was patched at 2024-05-15
1813.
Information Disclosure - PHP (CVE-2007-1599) - Medium [364]
Description: wp-login.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2007-1599 was patched at 2024-05-15
1814.
Information Disclosure - PHP (CVE-2023-49006) - Medium [364]
Description: Cross Site Request Forgery (CSRF) vulnerability in Phpsysinfo version 3.4.3 allows a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-49006 was patched at 2024-05-15
1815.
Information Disclosure - Safari (CVE-2016-4743) - Medium [364]
Description: An issue was discovered in certain Apple products. iOS before 10.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-4743 was patched at 2024-05-15
1816.
Information Disclosure - Safari (CVE-2016-7598) - Medium [364]
Description: An issue was discovered in certain Apple products. iOS before 10.2 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-7598 was patched at 2024-05-15
1817.
Information Disclosure - Safari (CVE-2017-2424) - Medium [364]
Description: An issue was discovered in certain Apple products. iOS before 10.3 is affected.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-2424 was patched at 2024-05-15
1818.
Remote Code Execution - Azure (CVE-2024-21646) - Medium [364]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | Azure | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-21646 was patched at 2024-05-15
1819.
Remote Code Execution - Azure (CVE-2024-27099) - Medium [364]
Description: The uAMQP is a C library for AMQP 1.0 communication to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | Azure | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2024-27099 was patched at 2024-05-15
1820.
Remote Code Execution - GPAC (CVE-2021-28300) - Medium [364]
Description: NULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrack()" function of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-28300 was patched at 2024-05-15
1821.
Remote Code Execution - Git (CVE-2016-7794) - Medium [364]
Description: sociomantic-tsunami
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | Git | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2016-7794 was patched at 2024-05-15
1822.
Remote Code Execution - Git (CVE-2021-3028) - Medium [364]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | Git | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2021-3028 was patched at 2024-05-15
1823.
Remote Code Execution - Git (CVE-2022-1212) - Medium [364]
Description: Use-After-Free in str_escape in mruby/mruby in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | Git | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-1212 was patched at 2024-05-15
1824.
Remote Code Execution - Git (CVE-2022-1286) - Medium [364]
Description: heap-buffer-overflow in mrb_vm_exec in mruby/mruby in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | Git | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2022-1286 was patched at 2024-05-15
1825.
Remote Code Execution - Git (CVE-2023-49569) - Medium [364]
Description: A path traversal vulnerability was discovered in go-
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | Git | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-49569 was patched at 2024-05-15
redhat: CVE-2023-49569 was patched at 2024-05-01
1826.
Denial of Service - Unknown Product (CVE-2006-4573) - Medium [363]
Description: {'vulners_cve_data_all': 'Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen before 4.0.3 allows user-assisted attackers to cause a denial of service (crash or hang) via certain UTF8 sequences.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([seebug] Apple Mac OS X 2007-005多个安全漏洞) | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 2.6. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2006-4573 was patched at 2024-05-15
1827.
Denial of Service - Unknown Product (CVE-2020-14354) - Medium [363]
Description: {'vulners_cve_data_all': 'A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddrinfo() completing. This flaw possibly allows an attacker to crash the service that uses c-ares lib. The highest threat from this vulnerability is to this service availability.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-14354 was patched at 2024-05-15
1828.
Denial of Service - Unknown Product (CVE-2020-18974) - Medium [363]
Description: {'vulners_cve_data_all': 'Buffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the component 'nasmlib/crc64'. This issue is different than CVE-2019-7147.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2020-18974 was patched at 2024-05-15
1829.
Elevation of Privilege - BIND (CVE-2018-9465) - Medium [363]
Description: In task_get_unused_fd_flags of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The exploit's existence is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.7 | 14 | BIND is a suite of software for interacting with the Domain Name System | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-9465 was patched at 2024-05-15
1830.
Memory Corruption - Unknown Product (CVE-2017-15046) - Medium [363]
Description: {'vulners_cve_data_all': 'LAME 3.99.5, 3.99.4, 3.98.4, 3.98.2, 3.98 and 3.97 have a stack-based buffer overflow in unpack_read_samples in frontend/get_audio.c, a different vulnerability than CVE-2017-9412.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners website ([exploitpack] LAME 3.99.5 - Multiple Vulnerabilities, [zdt] LAME 3.99.5 - Multiple Vulnerabilities, [exploitdb] LAME 3.99.5 - Multiple Vulnerabilities) | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2017-15046 was patched at 2024-05-15
1831.
Memory Corruption - Unknown Product (CVE-2018-19517) - Medium [363]
Description: {'vulners_cve_data_all': 'An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a memset call, as demonstrated by sadf.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2018-19517 was patched at 2024-05-15
1832.
Memory Corruption - Unknown Product (CVE-2023-24056) - Medium [363]
Description: {'vulners_cve_data_all': 'In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-24056 was patched at 2024-05-15
1833.
Memory Corruption - Unknown Product (CVE-2023-42365) - Medium [363]
Description: {'vulners_cve_data_all': 'A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-42365 was patched at 2024-05-15
1834.
Memory Corruption - Unknown Product (CVE-2023-42366) - Medium [363]
Description: {'vulners_cve_data_all': 'A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-42366 was patched at 2024-05-15
1835.
Memory Corruption - Unknown Product (CVE-2023-45897) - Medium [363]
Description: {'vulners_cve_data_all': 'exfatprogs before 1.2.2 allows out-of-bounds memory access, such as in read_file_dentry_set.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
almalinux: CVE-2023-45897 was patched at 2024-04-30
debian: CVE-2023-45897 was patched at 2024-05-15
oraclelinux: CVE-2023-45897 was patched at 2024-05-02
redhat: CVE-2023-45897 was patched at 2024-04-30
redos: CVE-2023-45897 was patched at 2024-04-18
1836.
Remote Code Execution - Unknown Product (CVE-2023-27349) - Medium [363]
Description: {'vulners_cve_data_all': 'BlueZ Audio Profile AVRCP Improper Validation of Array Index Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.\n\nThe specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19908.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-27349 was patched at 2024-05-15
ubuntu: CVE-2023-27349 was patched at 2024-06-05
1837.
Remote Code Execution - Unknown Product (CVE-2023-44431) - Medium [363]
Description: {'vulners_cve_data_all': 'BlueZ Audio Profile AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code via Bluetooth on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious device.\n\nThe specific flaw exists within the handling of the AVRCP protocol. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19909.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS data is not available |
debian: CVE-2023-44431 was patched at 2024-05-15
1838.
Remote Code Execution - Unknown Product (CVE-2023-50230) - Medium [363]
Description: {'vulners_cve_data_all': 'BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. User interaction is required to exploit this vulnerability in that the target must connect to a malicious Bluetooth device.\n\nThe specific flaw exists within the handling of the Phone Book Access profile. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20938.', 'bdu_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | < |