Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 354 500

Количество 354 500

github логотип

GHSA-xvjp-2q6g-h878

больше 2 лет назад

In the Linux kernel, the following vulnerability has been resolved: dm-crypt: don't modify the data when using authenticated encryption It was said that authenticated encryption could produce invalid tag when the data that is being encrypted is modified [1]. So, fix this problem by copying the data into the clone bio first and then encrypt them inside the clone bio. This may reduce performance, but it is needed to prevent the user from corrupting the device by writing data with O_DIRECT and modifying them at the same time. [1] https://lore.kernel.org/all/20240207004723.GA35324@sol.localdomain/T/

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvjp-2h38-99ph

почти 2 года назад

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix out-of-bounds read in `v3d_csd_job_run()` When enabling UBSAN on Raspberry Pi 5, we get the following warning: [ 387.894977] UBSAN: array-index-out-of-bounds in drivers/gpu/drm/v3d/v3d_sched.c:320:3 [ 387.903868] index 7 is out of range for type '__u32 [7]' [ 387.909692] CPU: 0 PID: 1207 Comm: kworker/u16:2 Tainted: G WC 6.10.3-v8-16k-numa #151 [ 387.919166] Hardware name: Raspberry Pi 5 Model B Rev 1.0 (DT) [ 387.925961] Workqueue: v3d_csd drm_sched_run_job_work [gpu_sched] [ 387.932525] Call trace: [ 387.935296] dump_backtrace+0x170/0x1b8 [ 387.939403] show_stack+0x20/0x38 [ 387.942907] dump_stack_lvl+0x90/0xd0 [ 387.946785] dump_stack+0x18/0x28 [ 387.950301] __ubsan_handle_out_of_bounds+0x98/0xd0 [ 387.955383] v3d_csd_job_run+0x3a8/0x438 [v3d] [ 387.960707] drm_sched_run_job_work+0x520/0x6d0 [gpu_sched] [ 387.966862] process_one_work+0x62c/0xb48 [ 387.971296] ...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-xvjm-g277-p3fj

около 4 лет назад

SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQL commands via the det parameter.

EPSS: Низкий
github логотип

GHSA-xvjm-fvxx-q3hv

около 5 лет назад

CHECK-fail due to integer overflow

CVSS3: 2.5
EPSS: Низкий
github логотип

GHSA-xvjm-5f8w-rrvc

около 4 лет назад

A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "List Description" field under the "Edit A List" module.

EPSS: Низкий
github логотип

GHSA-xvjj-mhxv-ccr9

около 4 лет назад

Memory leak in Cisco Unity Connection 9.x allows remote attackers to cause a denial of service (memory consumption and process crash) by sending many TCP requests, aka Bug ID CSCud59736.

EPSS: Низкий
github логотип

GHSA-xvjj-hpv8-263f

около 4 лет назад

socketfilterfw in Application Firewall in Apple Mac OS X before 10.9 does not properly implement the --blockApp option, which allows remote attackers to bypass intended access restrictions via a network connection to an application for which blocking was configured.

EPSS: Низкий
github логотип

GHSA-xvjj-gv4g-2h8h

около 4 лет назад

An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 750m11ac wireless router via the HTTP request parameter in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function.

EPSS: Низкий
github логотип

GHSA-xvjh-fqcm-jpr6

2 месяца назад

Lack of output escaping leads to a XSS vector in the feed modules.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xvjg-xxqh-hg7q

9 месяцев назад

The issue was addressed with improved memory handling. This issue is fixed in Safari 26, tvOS 26, watchOS 26, iOS 26 and iPadOS 26, visionOS 26. Processing maliciously crafted web content may lead to memory corruption.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xvjg-4qjv-mmc7

около 2 лет назад

Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This stack-based buffer overflow is related to the `entry_name` request's parameter.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-xvjf-wwff-cwgg

около 4 лет назад

Cross-site scripting (XSS) vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-xvjf-ppxc-mvvq

больше 3 лет назад

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-xvjf-5mpw-35xg

около 4 лет назад

IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 150022.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvjf-3q8p-7pjv

около 4 лет назад

Cross-site scripting (XSS) vulnerability in SourceCodester E-Commerce Website v 1.0 allows remote attackers to inject arbitrary web script or HTM via the subject field to feedback_process.php.

EPSS: Низкий
github логотип

GHSA-xvjf-394g-phrr

около 4 лет назад

TeamPass Improper Privilege Management

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-xvjc-64pg-p82q

больше 2 лет назад

Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_upass' parameter of the sign-up.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvj9-g93g-8ggp

около 4 лет назад

eClass platform < ip.2.5.10.2.1 allows an attacker to execute SQL command via /admin/academic/studenview_left.php StudentID parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xvj9-4p6c-c3xm

почти 3 года назад

Dynamics Finance and Operations Cross-site Scripting Vulnerability

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-xvj8-ph7x-65gf

4 месяца назад

Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xvjp-2q6g-h878

In the Linux kernel, the following vulnerability has been resolved: dm-crypt: don't modify the data when using authenticated encryption It was said that authenticated encryption could produce invalid tag when the data that is being encrypted is modified [1]. So, fix this problem by copying the data into the clone bio first and then encrypt them inside the clone bio. This may reduce performance, but it is needed to prevent the user from corrupting the device by writing data with O_DIRECT and modifying them at the same time. [1] https://lore.kernel.org/all/20240207004723.GA35324@sol.localdomain/T/

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xvjp-2h38-99ph

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix out-of-bounds read in `v3d_csd_job_run()` When enabling UBSAN on Raspberry Pi 5, we get the following warning: [ 387.894977] UBSAN: array-index-out-of-bounds in drivers/gpu/drm/v3d/v3d_sched.c:320:3 [ 387.903868] index 7 is out of range for type '__u32 [7]' [ 387.909692] CPU: 0 PID: 1207 Comm: kworker/u16:2 Tainted: G WC 6.10.3-v8-16k-numa #151 [ 387.919166] Hardware name: Raspberry Pi 5 Model B Rev 1.0 (DT) [ 387.925961] Workqueue: v3d_csd drm_sched_run_job_work [gpu_sched] [ 387.932525] Call trace: [ 387.935296] dump_backtrace+0x170/0x1b8 [ 387.939403] show_stack+0x20/0x38 [ 387.942907] dump_stack_lvl+0x90/0xd0 [ 387.946785] dump_stack+0x18/0x28 [ 387.950301] __ubsan_handle_out_of_bounds+0x98/0xd0 [ 387.955383] v3d_csd_job_run+0x3a8/0x438 [v3d] [ 387.960707] drm_sched_run_job_work+0x520/0x6d0 [gpu_sched] [ 387.966862] process_one_work+0x62c/0xb48 [ 387.971296] ...

CVSS3: 7.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-xvjm-g277-p3fj

SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQL commands via the det parameter.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xvjm-fvxx-q3hv

CHECK-fail due to integer overflow

CVSS3: 2.5
0%
Низкий
около 5 лет назад
github логотип
GHSA-xvjm-5f8w-rrvc

A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "List Description" field under the "Edit A List" module.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xvjj-mhxv-ccr9

Memory leak in Cisco Unity Connection 9.x allows remote attackers to cause a denial of service (memory consumption and process crash) by sending many TCP requests, aka Bug ID CSCud59736.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xvjj-hpv8-263f

socketfilterfw in Application Firewall in Apple Mac OS X before 10.9 does not properly implement the --blockApp option, which allows remote attackers to bypass intended access restrictions via a network connection to an application for which blocking was configured.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xvjj-gv4g-2h8h

An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 750m11ac wireless router via the HTTP request parameter in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user function.

5%
Низкий
около 4 лет назад
github логотип
GHSA-xvjh-fqcm-jpr6

Lack of output escaping leads to a XSS vector in the feed modules.

CVSS3: 6.1
0%
Низкий
2 месяца назад
github логотип
GHSA-xvjg-xxqh-hg7q

The issue was addressed with improved memory handling. This issue is fixed in Safari 26, tvOS 26, watchOS 26, iOS 26 and iPadOS 26, visionOS 26. Processing maliciously crafted web content may lead to memory corruption.

CVSS3: 8.8
0%
Низкий
9 месяцев назад
github логотип
GHSA-xvjg-4qjv-mmc7

Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This stack-based buffer overflow is related to the `entry_name` request's parameter.

CVSS3: 7.2
1%
Низкий
около 2 лет назад
github логотип
GHSA-xvjf-wwff-cwgg

Cross-site scripting (XSS) vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xvjf-ppxc-mvvq

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvjf-5mpw-35xg

IBM Security Guardium 10 and 10.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 150022.

CVSS3: 9.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvjf-3q8p-7pjv

Cross-site scripting (XSS) vulnerability in SourceCodester E-Commerce Website v 1.0 allows remote attackers to inject arbitrary web script or HTM via the subject field to feedback_process.php.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xvjf-394g-phrr

TeamPass Improper Privilege Management

CVSS3: 4.9
1%
Низкий
около 4 лет назад
github логотип
GHSA-xvjc-64pg-p82q

Online Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txt_upass' parameter of the sign-up.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS3: 9.8
больше 2 лет назад
github логотип
GHSA-xvj9-g93g-8ggp

eClass platform < ip.2.5.10.2.1 allows an attacker to execute SQL command via /admin/academic/studenview_left.php StudentID parameter.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-xvj9-4p6c-c3xm

Dynamics Finance and Operations Cross-site Scripting Vulnerability

CVSS3: 7.6
1%
Низкий
почти 3 года назад
github логотип
GHSA-xvj8-ph7x-65gf

Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks

0%
Низкий
4 месяца назад

Уязвимостей на страницу