Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 324 081

Количество 324 081

github логотип

GHSA-xv92-wq9x-wgm4

почти 4 года назад

Unspecified vulnerability in the OpenID Identity Authentication extension in TYPO3 4.3.0 allows remote attackers to bypass authentication and gain access to a backend user account via unknown attack vectors in which both the attacker and victim have an OpenID provider that discards identities during authentication.

EPSS: Низкий
github логотип

GHSA-xv8x-pr4h-73jv

больше 4 лет назад

Memory corruption when returning a literal struct with a private call inside of it

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv8x-9rph-3fg2

почти 4 года назад

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1045, CVE-2016-1046, CVE-2016-1047, CVE-2016-1048, CVE-2016-1049, CVE-2016-1050, CVE-2016-1051, CVE-2016-1052, CVE-2016-1053, CVE-2016-1054, CVE-2016-1055, CVE-2016-1056, CVE-2016-1057, CVE-2016-1059, CVE-2016-1060, CVE-2016-1061, CVE-2016-1065, CVE-2016-1066, CVE-2016-1067, CVE-2016-1068, CVE-2016-1069, CVE-2016-1070, CVE-2016-1075, CVE-2016-1094, CVE-2016-1121, CVE-2016-1122, CVE-2016-4102, and CVE-2016-4107.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv8x-7495-j62f

почти 4 года назад

An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allows unauthenticated, remote attackers to gain administrator privileges via the Teachers Web Panel (TWP) User ID or Password field. If exploited, the attackers could perform any actions with administrator privileges (e.g., enumerate/delete all the students' personal information or modify various settings).

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv8w-mvvr-vf38

почти 4 года назад

Multiple cross-site scripting (XSS) vulnerabilities in FancyFon FAMOC before 3.17.4 allow remote attackers to inject arbitrary web script or HTML via the (1) LoginForm[username] to ui/system/login or the (2) order or (3) myorgs to index.php.

EPSS: Низкий
github логотип

GHSA-xv8v-xmj4-3j83

больше 2 лет назад

The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization. This vulnerability arises from a lack of proper cookie verification and affects all instances of SNMP Web Pro 1.1 without HTTP Digest authentication enabled, regardless of the password used for the web interface.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xv8v-5726-pq4v

почти 4 года назад

An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-xv8q-vwcv-3mcg

почти 4 года назад

The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 calls the FindMaxElementInSubArray function with incorrect template arguments, which allows remote attackers to obtain sensitive information from video memory via a crafted WebGL.drawElements call.

EPSS: Низкий
github логотип

GHSA-xv8q-fw76-648m

почти 4 года назад

An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a document to be destroyed and then later reused, resulting in a use-after-free vulnerability, which can lead to code execution under the context of the application. An attacker can convince a user to open a document to trigger this vulnerability.

CVSS3: 7.8
EPSS: Высокий
github логотип

GHSA-xv8q-8fhp-7r88

почти 4 года назад

An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocated, which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xv8q-37rr-6369

10 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

EPSS: Низкий
github логотип

GHSA-xv8m-jw66-qjxm

6 месяцев назад

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to basic contract details using unauthorised internal identifiers.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-xv8j-v7c6-7mjc

почти 4 года назад

The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retrieval in fm_IDL.xml.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xv8j-86xh-qr5w

почти 2 года назад

Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting negative values into the oneflow.zeros/ones parameter.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv8h-m568-7fx7

больше 3 лет назад

The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for packet origin parameter length. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xv8h-43h9-v3jq

больше 3 лет назад

FeehiCMS Cross Site Scripting vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xv8g-hcfj-ppcw

почти 4 года назад

It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-xv8g-fj9h-6gmv

24 дня назад

Linkdave Missing Authentication on REST and WebSocket endpoints

EPSS: Низкий
github логотип

GHSA-xv8g-4jv9-wpq8

почти 4 года назад

Directory traversal vulnerability in infusions/last_seen_users_panel/last_seen_users_panel.php in MyFusion (aka MyF) 6 Beta, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the settings[locale] parameter.

EPSS: Низкий
github логотип

GHSA-xv8f-556c-h484

около 1 месяца назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX R&F rf allows PHP Local File Inclusion.This issue affects R&F: from n/a through <= 1.5.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xv92-wq9x-wgm4

Unspecified vulnerability in the OpenID Identity Authentication extension in TYPO3 4.3.0 allows remote attackers to bypass authentication and gain access to a backend user account via unknown attack vectors in which both the attacker and victim have an OpenID provider that discards identities during authentication.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv8x-pr4h-73jv

Memory corruption when returning a literal struct with a private call inside of it

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xv8x-9rph-3fg2

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1045, CVE-2016-1046, CVE-2016-1047, CVE-2016-1048, CVE-2016-1049, CVE-2016-1050, CVE-2016-1051, CVE-2016-1052, CVE-2016-1053, CVE-2016-1054, CVE-2016-1055, CVE-2016-1056, CVE-2016-1057, CVE-2016-1059, CVE-2016-1060, CVE-2016-1061, CVE-2016-1065, CVE-2016-1066, CVE-2016-1067, CVE-2016-1068, CVE-2016-1069, CVE-2016-1070, CVE-2016-1075, CVE-2016-1094, CVE-2016-1121, CVE-2016-1122, CVE-2016-4102, and CVE-2016-4107.

CVSS3: 9.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-xv8x-7495-j62f

An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allows unauthenticated, remote attackers to gain administrator privileges via the Teachers Web Panel (TWP) User ID or Password field. If exploited, the attackers could perform any actions with administrator privileges (e.g., enumerate/delete all the students' personal information or modify various settings).

CVSS3: 9.8
6%
Низкий
почти 4 года назад
github логотип
GHSA-xv8w-mvvr-vf38

Multiple cross-site scripting (XSS) vulnerabilities in FancyFon FAMOC before 3.17.4 allow remote attackers to inject arbitrary web script or HTML via the (1) LoginForm[username] to ui/system/login or the (2) order or (3) myorgs to index.php.

0%
Низкий
почти 4 года назад
github логотип
GHSA-xv8v-xmj4-3j83

The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization. This vulnerability arises from a lack of proper cookie verification and affects all instances of SNMP Web Pro 1.1 without HTTP Digest authentication enabled, regardless of the password used for the web interface.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-xv8v-5726-pq4v

An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.

CVSS3: 6.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-xv8q-vwcv-3mcg

The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 calls the FindMaxElementInSubArray function with incorrect template arguments, which allows remote attackers to obtain sensitive information from video memory via a crafted WebGL.drawElements call.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xv8q-fw76-648m

An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a document to be destroyed and then later reused, resulting in a use-after-free vulnerability, which can lead to code execution under the context of the application. An attacker can convince a user to open a document to trigger this vulnerability.

CVSS3: 7.8
75%
Высокий
почти 4 года назад
github логотип
GHSA-xv8q-8fhp-7r88

An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocated, which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-xv8q-37rr-6369

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

10 месяцев назад
github логотип
GHSA-xv8m-jw66-qjxm

Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to basic contract details using unauthorised internal identifiers.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-xv8j-v7c6-7mjc

The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user permission for retrieval in fm_IDL.xml.

CVSS3: 6.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-xv8j-86xh-qr5w

Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting negative values into the oneflow.zeros/ones parameter.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-xv8h-m568-7fx7

The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for packet origin parameter length. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xv8h-43h9-v3jq

FeehiCMS Cross Site Scripting vulnerability

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xv8g-hcfj-ppcw

It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-xv8g-fj9h-6gmv

Linkdave Missing Authentication on REST and WebSocket endpoints

24 дня назад
github логотип
GHSA-xv8g-4jv9-wpq8

Directory traversal vulnerability in infusions/last_seen_users_panel/last_seen_users_panel.php in MyFusion (aka MyF) 6 Beta, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the settings[locale] parameter.

2%
Низкий
почти 4 года назад
github логотип
GHSA-xv8f-556c-h484

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX R&F rf allows PHP Local File Inclusion.This issue affects R&F: from n/a through <= 1.5.

CVSS3: 8.1
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу