Writeup Exploits

68,147 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-14194 WRITEUP CRITICAL
Das U-Boot < 2019.07 - Out-of-bounds Write via NFSv2 Reply Handling
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv2 case.
CVSS 9.8
CVE-2019-14193 WRITEUP CRITICAL
Das U-Boot < 2019.07 - Out-of-bounds Write in NFS Readlink Reply
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with an unvalidated length at nfs_readlink_reply, in the "if" block after calculating the new path length.
CVSS 9.8
CVE-2019-14192 WRITEUP CRITICAL
Das U-Boot < 2019.07 - Integer Underflow via UDP Packet Processing
An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an nc_input_packet call.
CVSS 9.8
CVE-2022-30790 WRITEUP HIGH
Das U-Boot 2022.01 - Buffer Overflow
Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
CVSS 7.8
CVE-2022-30552 WRITEUP MEDIUM
Das U-Boot 2022.01 - Buffer Overflow
Das U-Boot 2022.01 has a Buffer Overflow.
CVSS 5.5
CVE-2021-27138 WRITEUP HIGH
Das U-Boot <2021.04-rc2 - Use After Free
The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT.
CVSS 7.8
CVE-2021-27138 WRITEUP HIGH
Das U-Boot <2021.04-rc2 - Use After Free
The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT.
CVSS 7.8
CVE-2021-27097 WRITEUP HIGH
Das U-Boot <2021.04-rc2 - Buffer Overflow
The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT.
CVSS 7.8
CVE-2021-27097 WRITEUP HIGH
Das U-Boot <2021.04-rc2 - Buffer Overflow
The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT.
CVSS 7.8
CVE-2024-42040 WRITEUP HIGH
DENX U-Boot < 2025.10 - Buffer Overflow in net/bootp.c via DHCP Response
Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.
CVSS 8.1
CVE-2019-14802 WRITEUP MEDIUM
HashiCorp Nomad 0.5.0-0.9.4 - Exposure of Sensitive Information via Template Rendering
HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GHSA-6hv3-7c34-4hx8. This applies to nomad/client/allocrunner/taskrunner/template.
CVSS 5.3
CVE-2019-15741 WRITEUP CRITICAL
GitLab Omnibus 7.4-12.2.1 - Privilege Escalation via Logrotate Interaction
An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation
CVSS 9.8
CVE-2019-15740 WRITEUP MEDIUM
GitLab 7.9.0-12.2.1 - Exposure of Sensitive Information via EXIF Geolocation Data
An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not being removed from certain image uploads.
CVSS 5.3
CVE-2019-15739 WRITEUP MEDIUM
GitLab 8.1-12.2.1 - Stored Cross-Site Scripting in Markdown Renderer
An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads.
CVSS 6.1
CVE-2019-15738 WRITEUP MEDIUM
GitLab 12.0-12.2.1 - Unauthorized Exposure of Merge Request IDs via Email
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email.
CVSS 5.3
CVE-2019-15737 WRITEUP MEDIUM
GitLab < 12.2.1 - Authentication and Session Management Issue
An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Certain account actions needed improved authentication and session management.
CVSS 6.5
CVE-2019-15736 WRITEUP HIGH
GitLab < 12.2.1 - Denial of Service via CI Pipeline Resource Exhaustion
An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Under certain circumstances, CI pipelines could potentially be used in a denial of service attack.
CVSS 7.5
CVE-2019-15734 WRITEUP MEDIUM
GitLab 8.6.0-12.2.1 - Unauthorized Exposure of Sensitive Commit and Comment Data
An issue was discovered in GitLab Community and Enterprise Edition 8.6 through 12.2.1. Under very specific conditions, commit titles and team member comments could become viewable to users who did not have permission to access these.
CVSS 4.3
CVE-2019-15733 WRITEUP MEDIUM
GitLab 7.12-12.2.1 - Unauthorized Exposure of Default Branch Name
An issue was discovered in GitLab Community and Enterprise Edition 7.12 through 12.2.1. The specified default branch name could be exposed to unauthorized users.
CVSS 4.3
CVE-2019-15732 WRITEUP MEDIUM
GitLab CE/EE <12.2.1 - Info Disclosure
An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions.
CVSS 5.3
CVE-2019-15731 WRITEUP MEDIUM
GitLab 12.0-12.2.1 - Unauthenticated Merge Request Comment Access
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Non-members were able to comment on merge requests despite the repository being set to allow only project members to do so.
CVSS 5.3
CVE-2019-15730 WRITEUP HIGH
GitLab 8.14.0-12.2.1 - Server-Side Request Forgery via Jira Integration
An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1. The Jira integration contains a SSRF vulnerability as a result of a bypass of the current protection mechanisms against this type of attack, which would allow sending requests to any resources accessible in the local network by the GitLab server.
CVSS 7.5
CVE-2019-15729 WRITEUP HIGH
GitLab 8.18-12.2.1 - Information Disclosure via Merge Request Pipeline Endpoint
An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information about the last pipeline that ran for a merge request.
CVSS 7.5
CVE-2019-15728 WRITEUP HIGH
GitLab 10.1-12.2.1 - Server-Side Request Forgery via Kubernetes Integration
An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.
CVSS 7.5
CVE-2019-15727 WRITEUP MEDIUM
GitLab 11.2.0-12.2.1 - Unauthorized Exposure of CI Metrics Data
An issue was discovered in GitLab Community and Enterprise Edition 11.2 through 12.2.1. Insufficient permission checks were being applied when displaying CI results, potentially exposing some CI metrics data to unauthorized users.
CVSS 5.3