Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 323 571

Количество 323 571

github логотип

GHSA-xvx6-286h-35qm

11 месяцев назад

Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of employees. There is no impact on integrity and availability.

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-xvx5-4wp8-4f6g

почти 4 года назад

WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4759, CVE-2016-4765, CVE-2016-4766, and CVE-2016-4768.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvx4-v362-295f

больше 1 года назад

An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvx4-fr25-r858

почти 4 года назад

QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-xvx3-whgp-7rq7

почти 4 года назад

The mdjvu_bitmap_pack_row function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvx3-23h3-m25g

почти 4 года назад

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect availability via vectors related to XML Publisher.

EPSS: Низкий
github логотип

GHSA-xvx2-wqf5-jjgv

почти 4 года назад

typo3/cms-felogin Cross-site Scripting vulnerability

EPSS: Низкий
github логотип

GHSA-xvx2-w5pj-9472

почти 4 года назад

When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.

EPSS: Низкий
github логотип

GHSA-xvx2-r4w7-hx6q

почти 4 года назад

Improper input validation in the Intel(R) SGX Platform Software for Windows* may allow an authenticated user to potentially enable a denial of service via local access.

EPSS: Низкий
github логотип

GHSA-xvx2-mpv8-r9xf

больше 3 лет назад

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in mjs_execute() in mjs.c.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xvx2-hw78-h573

почти 4 года назад

Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from within the same Layer 2 network segment. Note that the attacker must be in the same Layer 2 network segment as the vulnerable appliance.

EPSS: Низкий
github логотип

GHSA-xvwx-g9pc-953x

почти 4 года назад

time server daemon timed allows remote attackers to cause a denial of service via malformed packets.

EPSS: Низкий
github логотип

GHSA-xvww-cpj4-267x

почти 4 года назад

Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read cookies by navigating to a Dojo file, related to an "open direct" issue.

EPSS: Низкий
github логотип

GHSA-xvww-87m7-74xx

почти 4 года назад

The version V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perform unauthorized operations.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvwv-6wvx-px9x

около 7 лет назад

Plone Open Redirect

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvwr-jcvg-47ph

больше 1 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder allows SQL Injection.This issue affects NEX-Forms – Ultimate Form Builder: from n/a through 8.7.8.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-xvwq-6652-7rm2

почти 4 года назад

Cross-site scripting (XSS) vulnerability in GMOD GBrowse before 1.69 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xvwp-q2w5-88cf

около 2 лет назад

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xvwp-h6jv-7472

больше 3 лет назад

FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvwm-fhx3-vrj9

почти 4 года назад

Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvx6-286h-35qm

Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of employees. There is no impact on integrity and availability.

CVSS3: 5.8
0%
Низкий
11 месяцев назад
github логотип
GHSA-xvx5-4wp8-4f6g

WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4759, CVE-2016-4765, CVE-2016-4766, and CVE-2016-4768.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xvx4-v362-295f

An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvx4-fr25-r858

QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address.

CVSS3: 3.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-xvx3-whgp-7rq7

The mdjvu_bitmap_pack_row function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xvx3-23h3-m25g

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect availability via vectors related to XML Publisher.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xvx2-wqf5-jjgv

typo3/cms-felogin Cross-site Scripting vulnerability

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvx2-w5pj-9472

When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvx2-r4w7-hx6q

Improper input validation in the Intel(R) SGX Platform Software for Windows* may allow an authenticated user to potentially enable a denial of service via local access.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvx2-mpv8-r9xf

An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in mjs_execute() in mjs.c.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvx2-hw78-h573

Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from within the same Layer 2 network segment. Note that the attacker must be in the same Layer 2 network segment as the vulnerable appliance.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvwx-g9pc-953x

time server daemon timed allows remote attackers to cause a denial of service via malformed packets.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xvww-cpj4-267x

Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read cookies by navigating to a Dojo file, related to an "open direct" issue.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvww-87m7-74xx

The version V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perform unauthorized operations.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xvwv-6wvx-px9x

Plone Open Redirect

CVSS3: 6.1
0%
Низкий
около 7 лет назад
github логотип
GHSA-xvwr-jcvg-47ph

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder allows SQL Injection.This issue affects NEX-Forms – Ultimate Form Builder: from n/a through 8.7.8.

CVSS3: 8.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvwq-6652-7rm2

Cross-site scripting (XSS) vulnerability in GMOD GBrowse before 1.69 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xvwp-q2w5-88cf

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later

CVSS3: 3.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-xvwp-h6jv-7472

FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess

CVSS3: 7.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xvwm-fhx3-vrj9

Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу