Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 322 820

Количество 322 820

github логотип

GHSA-xxqf-cf9x-9rwq

почти 4 года назад

lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.

EPSS: Низкий
github логотип

GHSA-xxqf-46rv-f5hw

около 4 лет назад

There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

EPSS: Низкий
github логотип

GHSA-xxqc-wcch-833f

11 месяцев назад

A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /memoAjax/save. The manipulation of the argument ID leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-xxqc-84hc-65cr

почти 4 года назад

CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of the X-Forwarded-Host HTTP header.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxqc-5rhp-jfq2

больше 1 года назад

In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descriptor in hub_port_init() Syzbot reported an out-of-bounds read in sysfs.c:read_descriptors(): BUG: KASAN: slab-out-of-bounds in read_descriptors+0x263/0x280 drivers/usb/core/sysfs.c:883 Read of size 8 at addr ffff88801e78b8c8 by task udevd/5011 CPU: 0 PID: 5011 Comm: udevd Not tainted 6.4.0-rc6-syzkaller-00195-g40f71e7cd3c6 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/27/2023 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0xd9/0x150 lib/dump_stack.c:106 print_address_description.constprop.0+0x2c/0x3c0 mm/kasan/report.c:351 print_report mm/kasan/report.c:462 [inline] kasan_report+0x11c/0x130 mm/kasan/report.c:572 read_descriptors+0x263/0x280 drivers/usb/core/sysfs.c:883 ... Allocated by task 758: ... __do_kmalloc_node mm/slab_common.c:966 [inline] __kmalloc+0x5e/0x190 mm/slab_common.c:97...

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-xxq9-94ff-354x

почти 2 года назад

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->num_intf_addr_present coming from userspace, which can lead to a heap overwrite.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-xxq8-w68p-wqxp

почти 4 года назад

Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xxq8-5mc3-63xg

больше 3 лет назад

IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-xxq8-555q-w627

почти 4 года назад

Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xxq7-hjr2-f27f

почти 4 года назад

Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxq5-xj37-9fx7

почти 4 года назад

It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xxq5-c27j-953j

больше 2 лет назад

Microsoft Outlook for Mac Spoofing Vulnerability

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xxq4-jv5p-cfwc

почти 4 года назад

In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xxq4-9c68-6533

больше 1 года назад

Windows Authentication Information Disclosure Vulnerability

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xxq4-3742-3h28

около 4 лет назад

Generation of Error Message Containing Sensitive Information in microweber

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xxq3-gj76-wh9v

почти 4 года назад

PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

EPSS: Низкий
github логотип

GHSA-xxq3-764r-q6rm

почти 4 года назад

AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.

EPSS: Низкий
github логотип

GHSA-xxq2-fm9w-xjv8

3 месяца назад

The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xxq2-74hw-vg6m

почти 3 года назад

Jenkins WSO2 Oauth Plugin Session Fixation vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xxq2-62cv-vmcw

почти 3 года назад

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxqf-cf9x-9rwq

lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xxqf-46rv-f5hw

There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

0%
Низкий
около 4 лет назад
github логотип
GHSA-xxqc-wcch-833f

A vulnerability has been found in JAdmin-JAVA JAdmin 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /memoAjax/save. The manipulation of the argument ID leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-xxqc-84hc-65cr

CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of the X-Forwarded-Host HTTP header.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xxqc-5rhp-jfq2

In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descriptor in hub_port_init() Syzbot reported an out-of-bounds read in sysfs.c:read_descriptors(): BUG: KASAN: slab-out-of-bounds in read_descriptors+0x263/0x280 drivers/usb/core/sysfs.c:883 Read of size 8 at addr ffff88801e78b8c8 by task udevd/5011 CPU: 0 PID: 5011 Comm: udevd Not tainted 6.4.0-rc6-syzkaller-00195-g40f71e7cd3c6 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/27/2023 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0xd9/0x150 lib/dump_stack.c:106 print_address_description.constprop.0+0x2c/0x3c0 mm/kasan/report.c:351 print_report mm/kasan/report.c:462 [inline] kasan_report+0x11c/0x130 mm/kasan/report.c:572 read_descriptors+0x263/0x280 drivers/usb/core/sysfs.c:883 ... Allocated by task 758: ... __do_kmalloc_node mm/slab_common.c:966 [inline] __kmalloc+0x5e/0x190 mm/slab_common.c:97...

CVSS3: 6.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxq9-94ff-354x

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->num_intf_addr_present coming from userspace, which can lead to a heap overwrite.

CVSS3: 6.7
0%
Низкий
почти 2 года назад
github логотип
GHSA-xxq8-w68p-wqxp

Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-xxq8-5mc3-63xg

IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449.

CVSS3: 3.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xxq8-555q-w627

Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xxq7-hjr2-f27f

Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.

CVSS3: 7.5
1%
Низкий
почти 4 года назад
github логотип
GHSA-xxq5-xj37-9fx7

It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xxq5-c27j-953j

Microsoft Outlook for Mac Spoofing Vulnerability

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xxq4-jv5p-cfwc

In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.

CVSS3: 3.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xxq4-9c68-6533

Windows Authentication Information Disclosure Vulnerability

CVSS3: 5.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-xxq4-3742-3h28

Generation of Error Message Containing Sensitive Information in microweber

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xxq3-gj76-wh9v

PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

9%
Низкий
почти 4 года назад
github логотип
GHSA-xxq3-764r-q6rm

AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xxq2-fm9w-xjv8

The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks

CVSS3: 4.9
0%
Низкий
3 месяца назад
github логотип
GHSA-xxq2-74hw-vg6m

Jenkins WSO2 Oauth Plugin Session Fixation vulnerability

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-xxq2-62cv-vmcw

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions.

CVSS3: 5.9
0%
Низкий
почти 3 года назад

Уязвимостей на страницу