Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 375 356

Количество 375 356

github логотип

GHSA-xvwx-4pm6-jf3g

около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject FITRIM ranges shorter than a cluster ocfs2_trim_mainbm() trims the global bitmap in cluster units, but its too-short range validation only checks sb->s_blocksize. On filesystems with a cluster size larger than the block size, a FITRIM range that is at least one block but shorter than one cluster is accepted and shifted down to len == 0. The later start + len - 1 and len -= ... arithmetic then underflows and can drive trimming past the requested range. Reject ranges shorter than s_clustersize instead. That preserves the existing -EINVAL behavior for requests that cannot discard even one allocation unit and keeps zero-cluster trims out of the group walk.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvww-xhx6-22pf

6 месяцев назад

SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xvww-cpj4-267x

больше 4 лет назад

Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read cookies by navigating to a Dojo file, related to an "open direct" issue.

EPSS: Низкий
github логотип

GHSA-xvww-87m7-74xx

больше 4 лет назад

The version V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perform unauthorized operations.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvwv-6wvx-px9x

больше 7 лет назад

Plone Open Redirect

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvwr-jcvg-47ph

почти 2 года назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder allows SQL Injection.This issue affects NEX-Forms – Ultimate Form Builder: from n/a through 8.7.8.

CVSS3: 8.5
EPSS: Низкий
github логотип

GHSA-xvwq-6652-7rm2

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in GMOD GBrowse before 1.69 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xvwp-q2w5-88cf

больше 2 лет назад

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later

CVSS3: 3.8
EPSS: Низкий
github логотип

GHSA-xvwp-h6jv-7472

почти 4 года назад

FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvwm-fhx3-vrj9

больше 4 лет назад

Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-xvwj-v9pv-cwjj

почти 2 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mashiurz.com Plain Post allows Stored XSS.This issue affects Plain Post: from n/a through 1.0.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xvwh-vh35-wwv2

4 месяца назад

A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_smart_ptr.h. Such manipulation leads to improper validation of specified type of input. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 5.2.5 is able to address this issue. The name of the patch is 66d16516e24893bebc1c8af52bf2fe9ad0735061. Upgrading the affected component is advised.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-xvwh-qhvg-2jjx

больше 4 лет назад

While processing QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY vendor command, driver does not validate the data obtained from the user space which could be invalid and thus leads to an undesired behaviour in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS605, SD 600, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvwg-32hp-p5p5

больше 4 лет назад

The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when processing a SET call, which allows local users to cause a denial of service (system hang or crash) via unspecified SET operations.

EPSS: Низкий
github логотип

GHSA-xvwf-ffg2-9c6p

больше 4 лет назад

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36576151.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvwf-58fx-rg4f

больше 1 года назад

In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvwc-mxm8-8hqg

почти 2 года назад

An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvwc-m4qj-9wr9

почти 3 года назад

Cross-Site Request Forgery (CSRF) vulnerability in dan009 WP Bing Map Pro plugin < 5.0 versions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xvw9-48jx-4p2f

больше 1 года назад

Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-xvw9-3mhm-xjqq

около 3 лет назад

Apache Airflow information disclosure vulnerability

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvwx-4pm6-jf3g

In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject FITRIM ranges shorter than a cluster ocfs2_trim_mainbm() trims the global bitmap in cluster units, but its too-short range validation only checks sb->s_blocksize. On filesystems with a cluster size larger than the block size, a FITRIM range that is at least one block but shorter than one cluster is accepted and shifted down to len == 0. The later start + len - 1 and len -= ... arithmetic then underflows and can drive trimming past the requested range. Reject ranges shorter than s_clustersize instead. That preserves the existing -EINVAL behavior for requests that cannot discard even one allocation unit and keeps zero-cluster trims out of the group walk.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xvww-xhx6-22pf

SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory

CVSS3: 8.1
0%
Низкий
6 месяцев назад
github логотип
GHSA-xvww-cpj4-267x

Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read cookies by navigating to a Dojo file, related to an "open direct" issue.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvww-87m7-74xx

The version V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perform unauthorized operations.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvwv-6wvx-px9x

Plone Open Redirect

CVSS3: 6.1
1%
Низкий
больше 7 лет назад
github логотип
GHSA-xvwr-jcvg-47ph

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder allows SQL Injection.This issue affects NEX-Forms – Ultimate Form Builder: from n/a through 8.7.8.

CVSS3: 8.5
1%
Низкий
почти 2 года назад
github логотип
GHSA-xvwq-6652-7rm2

Cross-site scripting (XSS) vulnerability in GMOD GBrowse before 1.69 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xvwp-q2w5-88cf

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later

CVSS3: 3.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-xvwp-h6jv-7472

FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess

CVSS3: 7.1
1%
Низкий
почти 4 года назад
github логотип
GHSA-xvwm-fhx3-vrj9

Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-xvwj-v9pv-cwjj

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mashiurz.com Plain Post allows Stored XSS.This issue affects Plain Post: from n/a through 1.0.3.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xvwh-vh35-wwv2

A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_smart_ptr.h. Such manipulation leads to improper validation of specified type of input. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 5.2.5 is able to address this issue. The name of the patch is 66d16516e24893bebc1c8af52bf2fe9ad0735061. Upgrading the affected component is advised.

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-xvwh-qhvg-2jjx

While processing QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY vendor command, driver does not validate the data obtained from the user space which could be invalid and thus leads to an undesired behaviour in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS605, SD 600, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xvwg-32hp-p5p5

The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when processing a SET call, which allows local users to cause a denial of service (system hang or crash) via unspecified SET operations.

0%
Низкий
больше 4 лет назад
github логотип
GHSA-xvwf-ffg2-9c6p

A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36576151.

CVSS3: 7.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xvwf-58fx-rg4f

In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvwc-mxm8-8hqg

An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

CVSS3: 9.8
1%
Низкий
почти 2 года назад
github логотип
GHSA-xvwc-m4qj-9wr9

Cross-Site Request Forgery (CSRF) vulnerability in dan009 WP Bing Map Pro plugin < 5.0 versions.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
github логотип
GHSA-xvw9-48jx-4p2f

Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 8.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-xvw9-3mhm-xjqq

Apache Airflow information disclosure vulnerability

CVSS3: 6.5
1%
Низкий
около 3 лет назад

Уязвимостей на страницу