Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 288 225

Количество 288 225

github логотип

GHSA-xxqf-cf9x-9rwq

около 3 лет назад

lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.

EPSS: Низкий
github логотип

GHSA-xxqf-46rv-f5hw

больше 3 лет назад

There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

EPSS: Низкий
github логотип

GHSA-xxqc-wcch-833f

3 месяца назад

A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /memoAjax/save. The manipulation of the argument ID leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xxqc-84hc-65cr

около 3 лет назад

CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of the X-Forwarded-Host HTTP header.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxqc-5rhp-jfq2

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descriptor in hub_port_init() Syzbot reported an out-of-bounds read in sysfs.c:read_descriptors(): BUG: KASAN: slab-out-of-bounds in read_descriptors+0x263/0x280 drivers/usb/core/sysfs.c:883 Read of size 8 at addr ffff88801e78b8c8 by task udevd/5011 CPU: 0 PID: 5011 Comm: udevd Not tainted 6.4.0-rc6-syzkaller-00195-g40f71e7cd3c6 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/27/2023 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0xd9/0x150 lib/dump_stack.c:106 print_address_description.constprop.0+0x2c/0x3c0 mm/kasan/report.c:351 print_report mm/kasan/report.c:462 [inline] kasan_report+0x11c/0x130 mm/kasan/report.c:572 read_descriptors+0x263/0x280 drivers/usb/core/sysfs.c:883 ... Allocated by task 758: ... __do_kmalloc_node mm/slab_common.c:966 [inline] __kmalloc+0x5e/0x190 mm/slab_common.c:97...

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xxq9-94ff-354x

около 1 года назад

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->num_intf_addr_present coming from userspace, which can lead to a heap overwrite.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xxq8-w68p-wqxp

больше 3 лет назад

Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xxq8-5mc3-63xg

больше 2 лет назад

IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xxq8-555q-w627

больше 3 лет назад

Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xxq7-hjr2-f27f

около 3 лет назад

Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxq5-xj37-9fx7

около 3 лет назад

It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxq5-c27j-953j

больше 1 года назад

Microsoft Outlook for Mac Spoofing Vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxq4-jv5p-cfwc

около 3 лет назад

In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xxq4-9c68-6533

11 месяцев назад

Windows Authentication Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxq4-3742-3h28

больше 3 лет назад

Generation of Error Message Containing Sensitive Information in microweber

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxq3-gj76-wh9v

больше 3 лет назад

PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

EPSS: Низкий
github логотип

GHSA-xxq3-764r-q6rm

около 3 лет назад

AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.

EPSS: Низкий
github логотип

GHSA-xxq2-74hw-vg6m

около 2 лет назад

Jenkins WSO2 Oauth Plugin Session Fixation vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxq2-62cv-vmcw

около 2 лет назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xxpx-w698-q23j

около 3 лет назад

When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxqf-cf9x-9rwq

lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.

0%
Низкий
около 3 лет назад
github логотип
GHSA-xxqf-46rv-f5hw

There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxqc-wcch-833f

A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /memoAjax/save. The manipulation of the argument ID leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
0%
Низкий
3 месяца назад
github логотип
GHSA-xxqc-84hc-65cr

CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of the X-Forwarded-Host HTTP header.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xxqc-5rhp-jfq2

In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descriptor in hub_port_init() Syzbot reported an out-of-bounds read in sysfs.c:read_descriptors(): BUG: KASAN: slab-out-of-bounds in read_descriptors+0x263/0x280 drivers/usb/core/sysfs.c:883 Read of size 8 at addr ffff88801e78b8c8 by task udevd/5011 CPU: 0 PID: 5011 Comm: udevd Not tainted 6.4.0-rc6-syzkaller-00195-g40f71e7cd3c6 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/27/2023 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0xd9/0x150 lib/dump_stack.c:106 print_address_description.constprop.0+0x2c/0x3c0 mm/kasan/report.c:351 print_report mm/kasan/report.c:462 [inline] kasan_report+0x11c/0x130 mm/kasan/report.c:572 read_descriptors+0x263/0x280 drivers/usb/core/sysfs.c:883 ... Allocated by task 758: ... __do_kmalloc_node mm/slab_common.c:966 [inline] __kmalloc+0x5e/0x190 mm/slab_common.c:97...

CVSS3: 6.4
0%
Низкий
около 1 года назад
github логотип
GHSA-xxq9-94ff-354x

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->num_intf_addr_present coming from userspace, which can lead to a heap overwrite.

CVSS3: 6.7
0%
Низкий
около 1 года назад
github логотип
GHSA-xxq8-w68p-wqxp

Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxq8-5mc3-63xg

IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449.

CVSS3: 3.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xxq8-555q-w627

Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxq7-hjr2-f27f

Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-xxq5-xj37-9fx7

It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-xxq5-c27j-953j

Microsoft Outlook for Mac Spoofing Vulnerability

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-xxq4-jv5p-cfwc

In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.

CVSS3: 3.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-xxq4-9c68-6533

Windows Authentication Information Disclosure Vulnerability

CVSS3: 5.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xxq4-3742-3h28

Generation of Error Message Containing Sensitive Information in microweber

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxq3-gj76-wh9v

PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-xxq3-764r-q6rm

AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.

1%
Низкий
около 3 лет назад
github логотип
GHSA-xxq2-74hw-vg6m

Jenkins WSO2 Oauth Plugin Session Fixation vulnerability

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xxq2-62cv-vmcw

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions.

CVSS3: 5.9
0%
Низкий
около 2 лет назад
github логотип
GHSA-xxpx-w698-q23j

When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below

CVSS3: 5.5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу